Zero-Touch IoT Device Onboarding Through Rendezvous Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT device onboarding techniques fail to securely connect new devices to a network without exposing the production network to potential denial-of-service or protocol attacks, and they do not adequately protect the network from malicious devices masquerading as new devices.

Innovation Solution

A zero-touch device onboarding technique using an intermediary to establish guest Wi-Fi credentials, allowing the device to register with a rendezvous service for onboarding server information, and then verify the device's intent using a universal unique identifier (UUID) to provide secure network credentials for connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing IoT device onboarding techniques are used, then devices can be connected to the network, but the production network is exposed to denial-of-service attacks and malicious devices

Engineering Contradiction:
Improvenetwork securityVSAvoiddenial-of-service attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a rendezvous service as an intermediary between the new device and the production network. The device first connects to the rendezvous service to verify its intent and obtain credentials, then uses those credentials to securely connect to the production network. This mediator architecture prevents direct exposure of the production network to unverified devices, thereby blocking denial-of-service attacks while maintaining reliable device onboarding.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If existing onboarding techniques are used, then devices can join the network, but malicious devices can masquerade as new devices

Engineering Contradiction:
Improvedevice onboarding efficiencyVSAvoiddevice impersonation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification of device intent through the rendezvous service before allowing connection to the production network. The device must present its identity and receive authentication from the rendezvous service in advance. This preliminary action ensures that only legitimate devices can proceed to join the network, preventing impersonation attacks while maintaining efficient onboarding throughput.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure verification is implemented, then network security is improved, but the onboarding process complexity increases

Engineering Contradiction:
Improvedevice authentication securityVSAvoidonboarding process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The rendezvous service acts as a specialized intermediary that handles the complex authentication and verification logic, shielding the production network from complexity while ensuring secure device onboarding. The service manages credential issuance, device verification, and security policies centrally, allowing the overall system to achieve high security without each component needing to implement complex security logic independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12464355B2Secure device onboarding techniques
Publication Date: 2025.11.04 INTEL CORP
  • US12464355B2 patent drawing
  • US12464355B2 patent drawing
  • US12464355B2 patent drawing

AI summary

Various systems and methods for establishing network connectivity and onboarding for Internet of Things (IoT) devices and trusted platforms, including in Open Connectivity Foundation (OCF) specification device deployments, are discussed. In an example, a zero touch owner transfer method includes operations of: receiving a first request from a new device for network access to begin an onboarding procedure with a network platform; transmitting credentials of a first network to the new device, the first network used to access a rendezvous server and obtain onboarding information associated with the network platform; receiving a second request from the new device for network access to continue the onboarding procedure; and transmitting credentials of a second network to the new device, as the new device uses the second network to access the onboarding server of the network platform and perform or complete the onboarding procedure with the network platform.