Zero-Touch Sensor Provisioning via Pre-Provisioned Bootstrapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Device Provisioning Protocol (DPP) methods are cumbersome and inefficient for onboarding sensors in large enterprise networks, particularly when connecting to cloud-based systems, as they require manual configuration and lack defined mechanisms for obtaining bootstrapping information, leading to security and scalability challenges.
Innovation Solution
Implementing a method to push device bootstrapping information to network elements, enabling sensors to connect to DPP-over-Wi-Fi networks and communicate with cloud-based systems without traditional wired or cellular connections, using adaptive selection of communication mechanisms like Wi-Fi, Ethernet, or cellular, and integrating cloud-based authentication for secure authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional DPP methods are used for onboarding sensors, then security can be maintained through manual configuration, but the onboarding process becomes cumbersome and inefficient for large enterprise networks
Solution Approach 1:
The system performs preliminary actions by pre-provisioning bootstrapping information (such as DPP public keys) to network elements like access points during manufacturing or initial setup. This allows sensors to automatically obtain authentication credentials without manual configuration, resolving the contradiction between maintaining security through pre-established credentials and enabling automated onboarding at scale.
Solution Approach 2:
The sensor device performs self-service by autonomously obtaining bootstrapping information from network elements and completing its own provisioning process without requiring a separate configurator device. The sensor initiates connections, retrieves credentials, and configures itself to join the network and communicate with cloud services, eliminating manual intervention while maintaining security through the pre-provisioned credentials.
2Reliability
If manual configuration is required for DPP provisioning, then security can be ensured through controlled credential distribution, but scalability is limited for large enterprise networks
Solution Approach 1:
Network elements such as access points and cloud-based configurators serve as intermediaries that automatically distribute bootstrapping information to sensors. These intermediaries mediate between the security requirements (controlled credential distribution) and scalability needs (automated provisioning at scale) by implementing secure credential management systems that can serve multiple devices simultaneously without manual intervention for each device.
Solution Approach 2:
Bootstrapping information is preliminarily distributed to network elements before sensors need to connect. This preliminary action enables the network infrastructure to automatically authenticate and provision sensors as they arrive, achieving both security through controlled credential distribution and high productivity through automated, scalable onboarding processes.
3Reliability
If separate configurator devices are used for DPP provisioning, then security can be maintained through controlled authentication, but device complexity and deployment time increase
Solution Approach 1:
The system merges the functions of the separate configurator device into the network elements themselves (access points, cloud configurators) and the sensor device. This consolidation eliminates the need for dedicated configurator hardware, reducing overall system complexity while maintaining authentication security through the distributed credential verification process embedded in the merged system components.
Solution Approach 2:
The sensor device performs self-service provisioning by directly interacting with network elements to obtain bootstrapping information and complete authentication. This eliminates the need for separate configurator devices, reducing device complexity and deployment time while maintaining security through the self-service authentication process using pre-provisioned credentials.
4Reliability
If traditional wired or cellular connections are required for cloud communication, then connection reliability can be ensured, but deployment flexibility and scalability are reduced
Solution Approach 1:
The system implements multi-functionality by enabling sensors to communicate with cloud services through multiple connection types including Wi-Fi, Ethernet, and cellular networks. The bootstrapping information and authentication mechanisms work universally across different communication protocols, allowing deployment in diverse environments (wireless, wired, mobile) while maintaining connection reliability through adaptive protocol selection and redundant communication paths.
Data Source
AI summary
Systems and methods are provided for zero-touch provisioning of devices, such as sensors, on a network. When a device is unable/cannot access a network via Ethernet, cellular, or near field communications capabilities resident on the device, the device can alternatively be provisioned via an intermediate network device, such as an access point using, e.g., Device Provisioning Protocol or Wi-Fi EasyConnect. A cloud-based network management system may receive a device's bootstrapping information during or after manufacturing of the device. Ultimately, the device, via the intermediate network device, is able to communicate with a back-end, cloud-based network insight system from which configuration parameters for the device may be obtained.


