Trusted Device Evaluates Unknown Devices for Secure Network Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure network environments face challenges in provisioning credentials to unknown devices, especially those outside the communication domain of the credentialing system or lacking standard network connections, leading to inaccessible networks and security risks from manual provisioning.
Innovation Solution
Implementing a system where trusted third-party devices evaluate the trustworthiness of unknown devices using predefined rules, providing credentials for network access and facilitating communication with the credentialing system, enabling secure and rapid provisioning of unknown devices within secure networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual provisioning is used for unknown devices, then security control is maintained, but provisioning time increases and security risks arise from manual errors
Solution Approach 1:
The unknown device autonomously obtains credentials by presenting device attributes to the credentialing system without manual intervention. The device self-provisions by having its attributes evaluated and credentials automatically issued, eliminating the need for manual provisioning while maintaining security through automated attribute validation.
Solution Approach 2:
Device attributes serve as an intermediary mechanism between the unknown device and the credentialing system. Instead of direct manual provisioning or direct device authentication, the system evaluates intermediate attributes (device type, manufacturer, model) to automatically determine credential issuance, bridging the gap between security control and automated provisioning.
2Reliability
If pre-configuration of credentials is required, then security is maintained, but devices outside communication domain cannot access the network
Solution Approach 1:
The system performs preliminary evaluation of device attributes before credential issuance. By pre-defining trust rules based on device attributes (device type, manufacturer, model) and evaluating these attributes in advance, the system can securely provision devices that were not pre-configured, enabling adaptability while maintaining security through predefined evaluation criteria.
Solution Approach 2:
The system changes from requiring pre-configured device identities to evaluating device attributes as proxy parameters for trustworthiness. Instead of relying on pre-provisioned credentials tied to specific device identifiers, the system uses attribute-based evaluation (device type, manufacturer, model) to dynamically determine credential issuance, enabling devices outside the traditional communication domain to access the network.
3Productivity
If automated provisioning is implemented, then provisioning speed increases, but security control may be compromised
Solution Approach 1:
Device attributes act as an intermediary layer that enables automated provisioning while maintaining security control. The credentialing system evaluates intermediate attributes (device type, manufacturer, model) against predefined trust rules to automatically determine credential issuance, achieving both high provisioning speed and security through attribute-based decision-making rather than direct device authentication.
Solution Approach 2:
The system implements feedback through predefined trust rules that evaluate device attributes and automatically adjust credential issuance decisions. The credentialing system receives device attributes, evaluates them against established trust criteria, and provides feedback in the form of automated acceptance or rejection decisions, enabling secure automated provisioning through rule-based feedback mechanisms.
Data Source
AI summary
A trusted device responsible for evaluating trustworthiness of unknown devices is provided. Trust evaluation rules usable to determine whether to authorize unknown devices to access a resource are received. A request to access the resource and device evaluation attributes are received from an unknown device. The trustworthiness of the unknown device is evaluated based upon the device evaluation attributes using the trust evaluation rules. In response to determining that the unknown device is trustworthy, a credential for accessing the resource is provided to the unknown device, and the device evaluation attributes of the unknown device and an identification of the unknown device are sent to a registrar for the resource.


