VLAN Segmentation for Secure IoT Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems and IoT devices face challenges in seamless credential provisioning, requiring manual input of network credentials and separate updates, especially when multiple devices from different manufacturers are involved.

Innovation Solution

A system utilizing a virtual local area network (VLAN) with isolated network partitions for IoT devices, where a gateway device activates a provisioning mode upon user input, preprograms credentials, and securely transfers them to new devices through a separate partition, facilitating automatic connection to the main network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual credential input and separate updates are required for each device, then security control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network is segmented into two separate VLANs: a provisioning VLAN for device onboarding and a production VLAN for normal operation. This segmentation allows automated credential distribution in the provisioning VLAN while maintaining security control through isolated network zones, resolving the contradiction between ease of operation and security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A gateway device acts as an intermediary between the provisioning VLAN and production VLAN. The gateway receives credentials, manages the provisioning process, and securely distributes them to devices through the provisioning VLAN before moving devices to the production VLAN. This intermediary enables automated operation while maintaining security through controlled credential distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate updates are required for each wireless device when credentialing information changes, then security control is improved, but productivity deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Credential updates are pushed proactively from the gateway to all connected devices in the provisioning VLAN before devices need to access the production network. This preliminary action ensures all devices have current credentials without requiring individual updates, maintaining security control while improving productivity through automated bulk updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway continuously maintains credential synchronization with all devices in the provisioning VLAN, ensuring that credential updates are automatically propagated to all devices without interruption. This continuous action eliminates the need for separate manual updates to each device, improving productivity while maintaining security control.

Inventive Principle:
Principle #20Continuity of useful action

3Device complexity

If a single network partition is used for both provisioning and production, then device complexity is reduced, but reliability deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidreliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The network is divided into two separate VLANs (provisioning and production) to isolate different operational phases. This segmentation prevents credential leakage and unauthorized access by ensuring that devices can only communicate in their designated VLAN, thereby improving reliability without significantly increasing device complexity as the segmentation is managed centrally by the gateway.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each VLAN is assigned specific quality characteristics: the provisioning VLAN is configured for automated credential distribution with specific security policies, while the production VLAN is configured for normal network operations. This local quality assignment ensures that each network partition has optimized security and operational properties, improving overall system reliability while keeping individual device complexity low.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3804265B1End user inclusion and access of devices
Publication Date: 2025.06.25 CARRIER CORP
  • EP3804265B1 patent drawingFigure 1
  • EP3804265B1 patent drawingFigure 2
  • EP3804265B1 patent drawingFigure 3

AI summary

A method for credential provisioning. Aspects include receiving, by a gateway device, a request for provisioning for a wireless device, wherein the gateway device operates a virtual local area network (VLAN), the VLAN comprising a first network partition and a second network partition. Activing the second network partition responsive to the request. The credentialing data associated with the wireless device is received through the second network partition. A connection to the wireless device is established through the second network partition based at least in part on the credential data and secured credentialing data associated with the first network partition is transmitted to the wireless device.