Method for automatically pairing at least one pairing device to a network and associated system
Patent Information
- Application Number
- EP2024706442
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-06
- Filing Date
- 2024-02-22
- Publication Date
- 2026-01-14
AI Technical Summary
The existing methods for pairing devices to a communications network, such as WPS and third-party applications, are cumbersome and insecure, especially for devices without user interfaces, and often require complex user interactions and proximity challenges.
A method for automatic pairing of devices to a communication network using a trusted third-party device, which involves detection of compatible devices, exchange of connection data, selection of a trusted third-party device based on signal strength, and secure authentication to minimize user interactions and ensure secure pairing.
Enables secure and effortless pairing of devices to a master device, such as a broadband gateway, with minimal user actions, reducing the need for screens or buttons and enhancing security through proximity verification and encryption.
Smart Images

Figure EP2024054540_12092024_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: METHOD FOR AUTOMATICALLY PAIRING AT LEAST ONE PAIRING DEVICE TO A NETWORK AND ASSOCIATED SYSTEM
[0003] Technical field
[0004] The present invention relates to a method for automatically pairing at least one pairing device to a communication network via a trusted third-party device. It also relates to a system associated with said method.
[0005] State of the prior art
[0006] Wi-Fi technology is now available in an ever-increasing variety of devices, and pairing some devices can be cumbersome. Devices that lack a user interface sometimes require methods such as WPS pairing or third-party applications to transmit connection information and allow new devices to be paired to a secure WLAN network using, for example, the WPA2 standard.
[0007] In the case of WPS, it is necessary to press a button on each device involved in the pairing mechanism within two minutes. If the two devices are far from each other, this can make pairing more complicated in use.
[0008] In the case of using an application, this involves installing said application and using it with a large number of taps and entries on it.
[0009] A concrete example is pairing a decoder or repeater with a home broadband gateway. Today, the most common method is WPS, which is increasingly being abandoned due to security concerns.
[0010] The aim of the present invention is to resolve at least one of these drawbacks by a new method of automatic pairing of at least one pairing device to a communication network.
[0011] Presentation of the invention This objective is achieved with a method for automatically pairing at least one pairing device to a communication network via a trusted third-party device located near said pairing device, at least one master device being connected to said network, the method comprising the following steps:
[0012] - detection of network devices compatible with pairing by the pairing device,
[0013] - exchange of connection and identification data between the pairing device and one of the detected compatible devices of the network, the detected compatible device of the network chosen for the exchange becoming a direct device,
[0014] - sends to the pairing device by the direct device, a list of devices that can be considered as trusted third-party devices,
[0015] - monitoring of the devices in the list by the pairing device using the signal strength received by each of them, the one with the highest received power and exceeding a predetermined threshold being chosen as the trusted third-party device,
[0016] - monitoring of the pairing device by the direct device via the trusted third-party device using the received signal strength, the pairing device being considered reliable for pairing if its received signal exceeds a predetermined threshold,
[0017] - sending the master device's connection information by the direct device to the reliable pairing device upon pairing.
[0018] The present invention enables secure pairing of a WLAN device to a master WLAN device, such as a broadband gateway, with minimal user action. A pairing device is understood to mean any type of device that can be connected to a master device. In order to pair the pairing device to the master device, the user uses a third-party WLAN device (such as a mobile phone) to authenticate the pairing device to the master device so that the latter provides the information necessary for connection to the pairing device and allows its pairing. The device that serves as a trusted third-party device must be in proximity to the relay device in order to validate that the latter can access the connection information.
[0019] The purpose of the invention is for the user to electrically connect the pairing device and for it to automatically connect to the master device, such as a home gateway for example. The invention makes it possible to minimize the number of user interactions as much as possible.
[0020] The invention offers a solution for associating devices such as a repeater or a TV decoder, this association always being carried out at the right time in the right place.
[0021] The invention does not require a screen or buttons and allows for the reduction of interactions to pair the equipment. It facilitates the procedure (no need to enter connection identifiers, the action is simple: move a device already connected to the same network to the device you wish to connect).
[0022] The invention can be applied to any communication protocol allowing the encrypted sending of data and which can request radio measurements of their environment.
[0023] The invention can be integrated into any type of equipment with Wi-Fi and can even be standardized in order to expand the number of equipment compatible with the procedure.
[0024] In a more restrictive framework, it could facilitate the pairing of equipment from the same manufacturer.
[0025] The notion of proximity, which is verified by both devices (the one we want to pair and the trusted one) in a symmetrical manner, secures the procedure and is protected by the encryption of the data sent.
[0026] Since this proximity is configurable, two scenarios can be imagined: the trusted device can be "stuck" to the device to be paired and act as an NFC device or the device can be located less than half a meter away (for example, the end user's pocket), the latter being able to be notified by a notification via a third-party application of the pairing. The step of exchanging connection and identification data between the pairing device and one of the detected compatible devices in the network can include at least one of the following steps:
[0027] - sending by the pairing device to the direct device of the connection data of said pairing device,
[0028] - authentication of the connection data of the pairing device received by the direct device by the master device,
[0029] - sending by the direct device to the pairing device of the connection data of the master device, - authentication of the connection data of the master device by the pairing device.
[0030] The direct device can correspond to the master device or to a relay device.
[0031] The step of exchanging connection and identification data between the pairing device and one of the detected compatible devices of the network may also include the following step:
[0032] - sending the identification information of the pairing device to the direct device.
[0033] Data exchanges between each device can be carried out according to an action type, the action type corresponding to at least one of the following actions:
[0034] - information
[0035] - list
[0036] - selection
[0037] - validation
[0038] - request
[0039] - interrogation
[0040] - answer
[0041] The login data may include at least one identification certificate.
[0042] The identification data may include a MAC address of the master device and a network name.
[0043] The master device's MAC address corresponds to the BSSID, "Basic Service Set Identifier" and the network name corresponds to the SSID, "Service Set Identifier". The MAC address, "Media Access Control" corresponds to the physical address of a network device.
[0044] Data exchange between each device can be carried out via at least one standardized Wi-Fi frame.
[0045] These standardized Wi-Fi frames allow data to be sent without the transmitter and receiver needing to be on the same WLAN network.
[0046] The standardized Wi-Fi frame can contain at least one piece of data relating to: a type of action related to sending the standardized Wi-Fi frame, data relating to the action. The list of devices can be sent as a standardized Wi-Fi frame including all the MAC addresses of the devices in the list, as well as the channel and frequency band used by each device in the list.
[0047] This data allows the matching device to analyze each of the STAs.
[0048] According to another aspect of the invention, a system is proposed comprising at least one master device connected to a network, at least one device of the system comprising a processing unit configured to implement a method according to the invention.
[0049] According to yet another aspect of the invention, there is provided a computer program product comprising instructions which, when the program is executed by a processing unit in the at least one device of the network, causes the latter to implement the method according to the invention.
[0050] Description of figures and embodiments
[0051] Other advantages and particularities of the invention will appear on reading the detailed description of implementations and embodiments which are in no way limiting, and the following appended drawings:
[0052] [Fig. 1a] illustrates a first configuration of a system of devices according to the invention,
[0053] [Fig. 1b] illustrates a second configuration of a system of devices according to the invention,
[0054] [Fig. 2] describes the step of detecting equipment and exchanging connection data of the method according to the invention.
[0055] [Fig. 3] describes the step of selecting the trusted third-party device and the pairing step of the method according to the invention.
[0056] These embodiments being in no way limiting, it will be possible in particular to consider variants of the invention comprising only a selection of characteristics described or illustrated subsequently isolated from the other characteristics described or illustrated (even if this selection is isolated within a sentence comprising these other characteristics), if this selection of characteristics is sufficient to confer a technical advantage or to differentiate the invention compared to the state of the prior art. This selection comprises at least one preferably functional characteristic without structural details, and / or with only a part of the structural details if this part only is sufficient to confer a technical advantage or to differentiate the invention compared to the state of the prior art.
[0057] First, with reference to Figures 1a and 1b, we will describe configurations of systems of devices belonging to the same Internet network in which the method according to the invention is applied. Each device has a system that is configurable by means of a list of parameters. This system also has a memory for recording information necessary for the continuation of the procedure.
[0058] The SD relay device that the user wants to pair with a PD pairing device has an access point functionality that must be active during the procedure as well as a connection point functionality that is also active in order to perform the pairing.
[0059] The topology of figures 1a and 1b includes:
[0060] - a PD pairing device,
[0061] - a trusted third-party TTP STA device, and
[0062] - a set of AD devices, “Authenticator Devices”, which corresponds to a set of SD relay and MD master devices connected to the same network designated by AD,
[0063] The AD network topology can include: either a master device MD, “Master Device” (see figure 1a),
[0064] - either a master device MD and one or more relay devices SD, “Slave Device” which can act as a relay (see figure lb).
[0065] The device that communicates directly with the PD pairing device is referred to as the direct device DD, "Direct Device". The direct device DD can correspond to the master device MD (see figure 1a) or to a relay device SD (see figure 1b). When the direct device DD corresponds to a relay device SD, the relay device SD automatically transfers the received information to the master device MD and the master device MD transmits the information to the relay device SD to send it to the PD pairing device.
[0066] With reference to Figure 2, the step of detecting equipment and exchanging connection data of the method according to the invention is described.
[0067] The method according to the invention is initiated by the PD pairing device. The triggering can be done automatically or can be initiated by the user himself using a software or hardware button. The first step of the method consists of detecting devices compatible with said invention.
[0068] Each device, supporting the invention and having activated it in its system, must transmit in beacon frames or probe responses containing information relating to the support of the procedure. This information can be transmitted through a field of the frames mentioned above called "Vendor Information Element". The information presented is the support or not of the procedure, if the device is MD master or SD relay device of the network to which it belongs and a unique identifier relating to this network.
[0069] The PD pairing device analyzes its radio environment by performing a scan and stores in memory all the devices supporting said invention. The detected devices are sorted by the signal strength received by the PD pairing device, from strongest to weakest. Then, the PD pairing device sends to all the detected devices its connection data which includes its certificate. If no device has been detected the procedure is canceled.
[0070] Each device of the invention must first hold a certificate issued by a trusted third party with a set of public and private keys. Data exchanges between each device in the AD network are carried out via standardized Wi-Fi frames of the “Public Action Frame” type. The frame contains data relating to: the type of action linked to sending the frame, data relating to the action.
[0071] The PD pairing device transmits its connection data, which includes its certificate and its public key, to all detected devices. It therefore sends a "Public Action Frame" (PAF) frame with the action type "Initialization of the procedure (Request)" and transmits its certificate and a sequence number as data. Since the length of the certificate data set may exceed the size of an 802.11 MPDU frame, the transmission can be done in several parts using several PAF frames. The sequence number allows the data to be ordered in order to reconstruct the certificate by the recipient devices.
[0072] Each device that received a PAF frame with the Request action type relays the data received in the frame to the MD master device on its network and indicates at what power the frame transmission signal was received. If an MD master device receives the frame, it does not need to relay this frame and is considered the direct device DD. If the data was relayed by one or more SD relay devices on its network, the MD master device, when sending a response to the PD pairing device, must transmit its data to the SD relay device that received the Request frame at the highest measured power level of all SD relay devices. This SD relay device ensures the sending of standardized PAF Wi-Fi frames and via the 802.11k protocol for the rest of the procedure and serves as a relay to the MD master device. It is then designated as the direct device DD.
[0073] The MD master device of each network will first authenticate the certificate to determine if it was provided by a device considered trusted to validate the rest of the procedure. The certificate issued by the PD pairing device must be attached to an organization known and validated by the MD master device. If the certificate is not valid, the device that received the Request frame will not respond to the device that sent the same frame.
[0074] If the certificate is valid, the direct device DD responds to the pairing device PD with a PAF frame to transmit its certificate in turn. This frame has the action type "Response" and transmits its certificate and a sequence number in its data. As in the case of sending a Request frame, the size of the PAF frame may be insufficient to support the total length of the certificate; the sequence number will be used to reconstruct the certificate.
[0075] The PD pairing device in turn authenticates the received certificate to determine whether the master device MD of the network to which it wants to pair was provided by a device considered trusted, thus validating the rest of the procedure and being able to send its information. The certificate issued by the master device MD must be attached to a known organization validated by the PD pairing device to be considered trusted. If the certificate is not valid, the PD pairing device cancels the procedure with the direct device DD that sent the Response frame. If there are no more valid compatible devices, the procedure is canceled.
[0076] An additional frame type is also present to allow the replay of the two previous action frames in error cases such as an incomplete certificate or key. This frame is defined by the "Interrogation" action type and must indicate the action frame it requests (Request or Response). If after a configurable number of Interrogation frames sent, the completion of one of the two previous steps has not succeeded, the procedure is terminated respectively on the AD network device side for the Interrogation frame of a Request frame and on the PD pairing device side for the Interrogation frame of a Response frame, the latter cancels the procedure for the requested AD network device. A configurable number of Interrogation frames received also makes it possible to prevent abusive solicitations and to ignore any Interrogation frame exceeding this number.
[0077] With reference to Figure 3, we describe the step of selecting the trusted third-party device and the pairing step of the method according to the invention.
[0078] From this step, the content of all frames sent with PAF “Public Action Frame” type frames is encrypted using the public key of the recipient device and signed by the private key of the sending device. If a device is not able to decrypt with its private key and authenticate by signature the sender a frame, the procedure is canceled for the sender and recipient pair, the PD pairing device being able to continue the procedure with another device of the compatible network or cancel it if there are no more compatible devices available.
[0079] The pairing device PD sends its identification information to the direct device DD. This information contains its BSSID and SSID. This information is saved by the master device MD in memory and will be reused in the rest of the procedure. The pairing device PD sends its information using a frame containing the action type Info (for information), its BSSID and its SSID.
[0080] The PD pairing device then waits for the reception of the information necessary for the continuation of the procedure, sent for each device in the AD network that received the Info frame. A timer of a configurable duration is triggered after which, once completed, the PD pairing device can again send an Info frame and restart the timer. The PD pairing device can repeat the operation a configurable number of times. If the reception of the information is not successful, the PD pairing device cancels the procedure with the direct device DD with which it communicates.
[0081] The direct device DD having received an INFO frame responds with a list of devices (STA) one of which will be selected as a trusted third-party device in the rest of the procedure. The list of devices (STA) is given by the master device MD.
[0082] The MD master device therefore creates a list of STA devices. To be present in the list, the STA device meets the following conditions:
[0083] Support the IEEE 802.11k (“Radio resource measurement”) standard,
[0084] Support the IEEE 802.llw (“Protected Management Frame”) standard,
[0085] Be associated via Wi-Fi to one of the devices in the AD network.
[0086] Support for IEEE 802.11k and IEEE 802.11w standards is announced to the STA device connection when sending an Association Request frame.
[0087] The direct device DD sends the pairing device PD the list of STA devices with a frame having an action of type "List". This frame contains in its data the set of MAC addresses of the STA devices in the list, as well as the channel and frequency band used by each STA device. If several devices in the AD network send a List frame containing the same MAC address, the pairing device PD cancels the procedure with the devices in the AD network concerned.
[0088] Upon receiving the List frame, the PD pairing device monitors each of the STA devices in the list and measures the received power of the Wi-Fi signals they transmit. If the measured received power of one of the STA devices in the list exceeds a predetermined threshold, the STA device is then designated as a trusted third party (TTP STA). The PD pairing device stops monitoring the other STA devices and informs the direct device DD. If no STA device is designated as a TTP STA after a configurable time, the PD pairing device moves on to the STA device list received in the Device List frame from the next AD network based on the received signal strength. If all lists have been processed, the procedure is canceled.
[0089] Once the TTP STA trusted third party has been selected by the PD matching device, the latter informs the direct device DD of its choice. The PD matching device transmits the information using a frame with a "Selection" action. This frame contains information relating to the TTP STA trusted third party device such as its MAC address, the channel on which it was detected, as well as the power level at which the PD matching device measured it.
[0090] The PD pairing device then waits for the reception of a "Validation" frame, which will be described later. A timer of a configurable duration is triggered, after which, once completed, the PD pairing device can again send a Selection frame and restart the timer. The PD pairing device can repeat the operation a configurable number of times. If the expected frame is not received successfully, the PD pairing device cancels the procedure with the direct device DD and ends the entire procedure.
[0091] Upon receiving the Selection frame, the master device MD checks whether the TTP STA trusted third-party device belongs to the original list and whether the power level measured by the pairing device PD is greater than a predetermined threshold. If these conditions are met, the master device MD validates the device from the STA list as a TTP STA trusted third-party device. The direct device DD transmits the information to the pairing device PD.
[0092] The pairing device is then monitored in turn by the direct device DD via the trusted third-party device TTP STA using the signal strength received via an 802.11k protocol. The pairing device PD is considered reliable for pairing if its received signal exceeds a predetermined threshold.
[0093] Once the pairing device is deemed reliable for pairing, the connection information of the master device MD is sent by the direct device DD to the pairing device PD. The pairing device pairs to the network.
[0094] Typically at least one of the means of the device according to the invention previously described, preferably each of the means of the device according to the invention previously described are technical means.
[0095] Typically, each of the means of the device according to the invention previously described may comprise at least one computer, a central or calculation unit, an analog electronic circuit (preferably dedicated), a digital electronic circuit (preferably dedicated), and / or a microprocessor (preferably dedicated), and / or software means.
[0096] Of course, the invention is not limited to the examples which have just been described and numerous adjustments can be made to these examples without departing from the scope of the invention. Of course, the different characteristics, forms, variants and embodiments of the invention can be associated with each other in various combinations insofar as they are not incompatible or mutually exclusive. In particular, all the variants and embodiments described above can be combined with each other.
Claims
CLAIMS 1. Method for automatic pairing of at least one pairing device (PD) to a communication network via a trusted third party device (TTP STA) located near said pairing device, at least one master device (MD) being connected to said network, the method comprising the following steps: - detection of network devices (AD) compatible with pairing by the pairing device (PD), - exchange of connection and identification data between the pairing device (PD) and one of the detected compatible network devices (AD), the detected compatible network device chosen for the exchange becoming a direct device (DD), - sends to the pairing device (PD) by the direct device (DD), a list of devices (STA) that can be considered as a trusted third party device (TTP STA), - monitoring of the devices in the list (STA) by the pairing device (PD) using the signal strength received by each of them, the one with the highest received power and exceeding a predetermined threshold being chosen as the trusted third party device (TTP STA), - monitoring of the pairing device (PD) by the direct device (DD) via the trusted third party device (TTP STA) using the received signal strength, the pairing device (PD) being considered reliable for pairing if its received signal exceeds a predetermined threshold, - sending the connection information of the master device (MD) by the direct device (DD) to the reliable pairing device (PD) for pairing.
2. Automatic pairing method according to claim 1, wherein the step of exchanging connection and identification data between the pairing device (PD) and one of the detected compatible devices of the network (AD) comprises at least one of the following steps: - sending by the pairing device (PD) to the direct device (DD) of the connection data of said pairing device (PD), - authentication of the connection data of the pairing device (PD) received by the direct device (DD) by the master device (MD), - sending by the direct device (DD) to the pairing device (PD) of the connection data of the master device (MD), - authentication of the master device (MD) connection data by the pairing device (PD).
3. Automatic pairing method according to any one of claims 1 to 2, in which the direct device (DD) corresponds to the master device (MD) or to a relay device (SD).
4. Automatic pairing method according to any one of claims 1 to 3, wherein the step of exchanging connection and identification data between the pairing device (PD) and one of the detected compatible devices of the network (AD), also comprises the following step: - sending the identification information from the pairing device (PD) to the direct device (DD).
5. Automatic pairing method according to any one of claims 1 to 4, in which the data exchanges between each device are carried out according to a type of action, the type of action corresponding to at least one of the following actions: - information - list - selection - validation - request - interrogation - answer 6. Automatic pairing method according to any one of claims 1 to 5, wherein the connection data comprises at least one identification certificate.
7. Automatic pairing method according to any one of claims 1 to 6, wherein the identification data comprises a MAC address of the master device and a name of the network.
8. Automatic pairing method according to any one of claims 1 to 7, in which the data exchanges between each device are carried out via at least one standardized Wi-Fi frame.
9. Automatic pairing method according to claim 8, wherein the standardized Wi-Fi frame contains at least one data item relating to: a type of action linked to the sending of the standardized Wi-Fi frame, the data relating to the action.
10. Automatic pairing method according to any one of claims 1 to 9, wherein the list of devices (STA) is sent in the form of a standardized Wi-Fi frame comprising all the MAC addresses of the devices (STA) in the list, as well as the channel and the frequency band used by each device in the list (STA).
11. System comprising at least one master device (MD) connected to a network, at least one device of the system comprising a processing unit configured to implement a method according to any one of claims 1 to 10.
12. Computer program product comprising instructions which, when the program is executed by a processing unit in the at least one device of the network, causes the latter to implement the method according to any one of claims 1 to 10.