Trusted Device Evaluates Unknown Devices for Secure Network Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure network environments face challenges in provisioning credentials to unknown devices, especially those outside the communication domain of the credentialing system or lacking standard network connections, leading to inaccessible networks and security risks from manual provisioning.

Innovation Solution

Implementing a system where trusted third-party devices evaluate the trustworthiness of unknown devices using predefined rules, providing credentials for network access and facilitating communication with the credentialing system, enabling secure and rapid provisioning of unknown devices within secure networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning is used for unknown devices, then security control is maintained, but provisioning time increases and security risks arise from manual errors

Engineering Contradiction:
Improvesecurity controlVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The unknown device autonomously obtains credentials by presenting device attributes to the credentialing system without manual intervention. The device self-provisions by having its attributes evaluated and credentials automatically issued, eliminating the need for manual provisioning while maintaining security through automated attribute validation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Device attributes serve as an intermediary mechanism between the unknown device and the credentialing system. Instead of direct manual provisioning or direct device authentication, the system evaluates intermediate attributes (device type, manufacturer, model) to automatically determine credential issuance, bridging the gap between security control and automated provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-configuration of credentials is required, then security is maintained, but devices outside communication domain cannot access the network

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary evaluation of device attributes before credential issuance. By pre-defining trust rules based on device attributes (device type, manufacturer, model) and evaluating these attributes in advance, the system can securely provision devices that were not pre-configured, enabling adaptability while maintaining security through predefined evaluation criteria.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes from requiring pre-configured device identities to evaluating device attributes as proxy parameters for trustworthiness. Instead of relying on pre-provisioned credentials tied to specific device identifiers, the system uses attribute-based evaluation (device type, manufacturer, model) to dynamically determine credential issuance, enabling devices outside the traditional communication domain to access the network.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated provisioning is implemented, then provisioning speed increases, but security control may be compromised

Engineering Contradiction:
Improveprovisioning speedVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Device attributes act as an intermediary layer that enables automated provisioning while maintaining security control. The credentialing system evaluates intermediate attributes (device type, manufacturer, model) against predefined trust rules to automatically determine credential issuance, achieving both high provisioning speed and security through attribute-based decision-making rather than direct device authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback through predefined trust rules that evaluate device attributes and automatically adjust credential issuance decisions. The credentialing system receives device attributes, evaluates them against established trust criteria, and provides feedback in the form of automated acceptance or rejection decisions, enabling secure automated provisioning through rule-based feedback mechanisms.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11095653B2Secure provisioning of unknown devices through trusted third-party devices
Publication Date: 2021.08.17 KYNDRYL INC
  • US11095653B2 patent drawing
  • US11095653B2 patent drawing
  • US11095653B2 patent drawing

AI summary

A trusted device responsible for evaluating trustworthiness of unknown devices is provided. Trust evaluation rules usable to determine whether to authorize unknown devices to access a resource are received. A request to access the resource and device evaluation attributes are received from an unknown device. The trustworthiness of the unknown device is evaluated based upon the device evaluation attributes using the trust evaluation rules. In response to determining that the unknown device is trustworthy, a credential for accessing the resource is provided to the unknown device, and the device evaluation attributes of the unknown device and an identification of the unknown device are sent to a registrar for the resource.