METHOD FOR AUTOMATIC PAIRING OF AT LEAST ONE PAIRING DEVICE TO A NETWORK AND ASSOCIATED SYSTEM
The method addresses the complexity and security issues in device pairing by using a trusted third-party device for automatic Wi-Fi network pairing, ensuring secure and efficient device connection with minimal user interaction.
Patent Information
- Application Number
- FR2023002059
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-06
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2043-03-06
AI Technical Summary
Existing methods for pairing devices to a communication network, such as Wi-Fi networks, are cumbersome and require significant user interaction, especially when devices are far apart or lack a user interface, posing security and complexity challenges.
A method involving a trusted third-party device for automatic pairing, where devices exchange connection and identification data, with proximity verification and encryption, minimizing user intervention and ensuring secure pairing through signal strength and certificate validation.
Enables secure, automatic pairing of devices with minimal user interaction, reducing the complexity and enhancing security by leveraging proximity verification and encryption.
Smart Images

Figure 00000014_0000 
Figure 00000015_0000 
Figure 00000016_0000
Abstract
Description
Title of the invention: METHOD FOR AUTOMATIC PAIRING OF AT LEAST ONE PAIRING DEVICE TO A NETWORK AND ASSOCIATED SYSTEM technical field
[0001] The present invention relates to a method for automatically pairing at least one pairing device to a communication network via a trusted third-party device. It also relates to a system associated with said method. Prior art
[0002] Wi-Fi technology is now available in an ever-increasing number of devices, and pairing some devices can be cumbersome in practice. Devices lacking a user interface sometimes require the use of methods such as WPS pairing or the use of third-party applications to transmit connection information and enable the pairing of new devices to a secure WLAN network using, for example, the WPA2 standard.
[0003] In the case of WPS, it is necessary to press a button on each device involved in the pairing mechanism within two minutes. If the two devices are far apart, this can make pairing more complicated in practice.
[0004] In the case of using an application, this implies installing said application and using it with a large number of presses and inputs on it.
[0005] A concrete example is pairing a set-top box or repeater with a home broadband gateway. Today, the most common method is WPS, which is increasingly being abandoned for security reasons.
[0006] The object of the present invention is to resolve at least one of these drawbacks by means of a new method of automatic pairing of at least one pairing device to a communication network. Description of the invention
[0007] This objective is achieved with a method for automatically pairing at least one pairing device to a communication network via a trusted third-party device located near said pairing device, at least one master device being connected to said network, the method comprising the following steps:
[0008] - detection of network devices compatible with pairing by the device matching,
[0009] - exchange of connection and identification data between the device pairing and one of the detected compatible devices on the network, the detected compatible device on the network chosen for the exchange becoming a direct device,
[0010] - sends to the pairing device, via the direct device, a list of devices which can be considered as trusted third-party devices,
[0011] - monitoring of the devices on the list by the matching device thanks to the the power of the signal received by each of them, the one with the highest received power and exceeding a predetermined threshold being chosen as the trusted third-party device,
[0012] - monitoring of the pairing device by the direct device via the third-party device of trust thanks to the strength of the received signal, the pairing device being considered reliable for pairing if its received signal exceeds a predetermined threshold,
[0013] - sending the connection information of the master device by the direct device to reliable pairing device.
[0014] The present invention enables the secure pairing of a WLAN device to a master WLAN device, such as a broadband gateway, with minimal user intervention. A pairing device is defined as any type of device that can be connected to a master device. To pair the pairing device with the master device, the user uses a third-party WLAN device (such as a mobile phone) to authenticate the pairing device to the master device, enabling the latter to provide the necessary information for connecting to the pairing device and thus allowing pairing. The device acting as the trusted third-party device must be located near the relay device to validate that the latter can access the connection information.
[0015] The object of the invention is that the user electrically connects the pairing device and it automatically connects to the master device, such as a home gateway, for example. The invention minimizes the number of user interactions.
[0016] The invention offers a solution for associating devices such as a repeater or a TV decoder, this association always being carried out at the right time in the right place.
[0017] The invention does not require a screen or buttons and reduces the interactions required to pair the equipment. It simplifies the procedure (no need to enter login credentials; the action is simple: move a device already connected to the same network to the device you wish to connect).
[0018] The invention can be applied to any communication protocol allowing the encrypted sending of data and able to request radio measurements of their environment.
[0019] The invention can be integrated into any type of equipment with Wi-Fi and can even be standardized in order to extend the number of equipment compatible with the procedure.
[0020] In a more restrictive framework, it could facilitate the pairing of equipment from the same manufacturer.
[0021] The notion of proximity, which is verified by both devices (the one we wish to pair and the trusted one) in a symmetrical manner, secures the procedure and is protected by the encryption of the data sent.
[0022] Since this proximity is configurable, two scenarios are possible: the trusted device can be "stuck" to the device to be paired and act as an NFC device, or the device can be located less than half a meter away (for example, in the end user's pocket), with the latter being notified of the pairing via a third-party application. The step of exchanging connection and identification data between the pairing device and one of the detected compatible devices on the network can include at least one subsequent step:
[0023] - transmission of connection data by the pairing device to the direct device said matching device,
[0024] - authentication of the connection data of the pairing device received by the direct device via the master device,
[0025] - sending connection data directly from the device to the pairing device of the master device,
[0026] - authentication of the master device's connection data by the device matching.
[0027] The direct device can correspond to the master device or to a relay device.
[0028] The step of exchanging connection and identification data between the pairing device and one of the detected compatible devices on the network may also include the following step:
[0029] - sending the identification information of the pairing device to the device direct.
[0030] Data exchanges between each device can be carried out according to a type of action, the type of action corresponding to at least one of the following actions:
[0031] -information
[0032] - list
[0033] - selection
[0034] - validation
[0035] - request
[0036] - interrogation
[0037] - answer
[0038] The connection data may include at least one identification certificate.
[0039] The identification data may include a MAC address of the master device and a network name.
[0040] The MAC address of the master device corresponds to the BSSID, "Basic Service Set Identifier," and the network name corresponds to the SSID, "Service Set Identifier." The MAC address, "Media Access Control," corresponds to the physical address of a network device.
[0041] Data exchanges between each device can be carried out via at least one standardized Wi-Fi frame.
[0042] These standardized Wi-Fi frames allow data to be sent without the transmitter and receiver needing to be on the same WLAN network.
[0043] The standardized Wi-Fi frame may contain at least one piece of relative data:
[0044] - to a type of action related to sending the standardized Wi-Fi frame,
[0045] - to the data relating to the action.
[0046] The list of devices can be sent in the form of a standardized Wi-Fi frame including all the MAC addresses of the devices in the list, as well as the channel and frequency band used by each device in the list.
[0047] This data allows the matching device to analyze each of the STAs.
[0048] According to another aspect of the invention, a system is proposed comprising at least one master device connected to a network, at least one device of the system comprising a processing unit configured to implement a process according to the invention.
[0049] According to yet another aspect of the invention, a computer program product is proposed comprising instructions which, when the program is executed by a processing unit in at least one device of the network, leads the latter to implement the process according to the invention. Description of the figures and methods of implementation
[0050] Other advantages and features of the invention will become apparent from the detailed description of implementations and embodiments, which are by no means limiting, and from the following accompanying drawings:
[0051] [Fig. 1a] illustrates a first configuration of a system of devices according to the invention,
[0052] [Fig. 1b] illustrates a second system configuration of devices according to the invention,
[0053] [Fig.2] describes the step of detecting equipment and exchanging connection data of the process according to the invention.
[0054] [Fig.3] describes the step of selecting the trusted third-party device and the pairing step of the method according to the invention.
[0055] These embodiments being in no way limiting, one may in particular consider Variants of the invention comprising only a selection of features described or illustrated hereafter, isolated from other described or illustrated features (even if this selection is isolated within a sentence including these other features), if this selection of features is sufficient to confer a technical advantage or to differentiate the invention from the prior art. This selection includes at least one preferably functional feature without structural details, and / or with only a portion of the structural details if this portion alone is sufficient to confer a technical advantage or to differentiate the invention from the prior art.
[0056] We will first describe, with reference to Figures 1a and 1b, system configurations of devices belonging to the same internet network in which the method according to the invention is applied. Each device has a system that is configurable via a list of parameters. This system also has a memory for storing information necessary for the continuation of the procedure.
[0057] The SD relay device that the user wishes to pair with a PD pairing device has an access point functionality that must be active during the procedure as well as a connection point functionality that is also active in order to perform the pairing.
[0058] The topology of figures 1a and 1b comprises:
[0059] - a PD pairing device, “Pairing Device”,
[0060] - a trusted third-party TTP STA device, and
[0061] - a set of AD devices, "Authenticator Devices", which corresponds to a a set of SD relay devices and MD master devices connected to the same network designated by AD,
[0062] The AD network topology may include:
[0063] - either a master device MD, “Master Device” (see [Fig. aa]),
[0064] - either a master device MD and one or more relay devices SD, "Slave Device » that can act as a relay (see [Fig.lb]).
[0065] The device that communicates directly with the pairing device PD is designated as the Direct Device DD. The Direct Device DD can be the Master Device MD (see [Fig. 1a]) or a Relay Device SD (see [Fig. 1b]). When the Direct Device DD is a Relay Device SD, the Relay Device SD automatically forwards the received information to the Master Device MD, and the Master Device MD transmits the information to the Relay Device SD for forwarding to the pairing device PD.
[0066] With reference to [Fig.2], the step of detecting equipment and exchanging connection data of the process according to the invention is described.
[0067] The method according to the invention is initiated by the PD pairing device. Triggering can be automatic or initiated by the user using a software or hardware button. The first step of the method consists of detecting devices compatible with the invention.
[0068] Each device supporting the invention and having activated it in its system must transmit beacon or probe response frames containing information relating to the support of the procedure. This information can be transmitted through a field in the aforementioned frames called the "Vendor Information Element." The information presented is whether or not the procedure is supported, whether the device is a master (MD) or relay (SD) device of the network to which it belongs, and a unique identifier relating to that network.
[0069] The PD pairing device analyzes its radio environment by performing a scan and stores in memory all devices supporting the invention. The detected devices are sorted by the strength of the signal received by the PD pairing device, from strongest to weakest. The PD pairing device then sends its connection data, including its certificate, to all detected devices. If no devices are detected, the procedure is canceled.
[0070] Each device of the invention must first hold a certificate issued by a trusted third party with a set of public and private keys. Data exchanges between each device in the AD network take place via standardized Wi-Fi frames of the "Public Action Frame" type. The frame contains the following data:
[0071] - to the type of action related to sending the frame,
[0072] - to the data relating to the action.
[0073] The PD pairing device transmits its connection data, including its certificate and public key, to all detected devices. It therefore sends a Public Action Frame (PAF) with the action type "procedure initialization" (Request) and transmits its certificate and a sequence number as data. Since the certificate data set can exceed the size of an 802.11 MPDU frame, the transmission can be done in several parts using multiple PAFs. The sequence number allows the recipient devices to order the data so they can reconstruct the certificate.
[0074] Each device that receives a PAF frame with the action type Request relays the data received in the frame to the master device MD of its network and indicates the power level at which the frame's transmission signal was received. If a master device MD receives the frame, it does not need to relay this frame and is considered the direct device DD. If the data has been relayed by one or more relay devices SD of its network, the master device MD, when sending a response to the peering device PD, must transmit its data to the relay device SD. Having received the Request frame at the highest measured power level of all SD relay devices, this SD relay device ensures the transmission of standardized Wi-Fi PAF frames via the 802.11k protocol for the remainder of the procedure and acts as a relay to the master device MD. It is then designated as the direct device DD.
[0075] The master device (MD) of each network will first authenticate the certificate to determine if it was issued by a device considered trustworthy in order to validate the rest of the procedure. The certificate issued by the peering device (PD) must be associated with an organization known and validated by the master device (MD). If the certificate is not valid, the device that received the Request frame will not respond to the device that sent the same frame.
[0076] If the certificate is valid, the direct device DD responds to the peering device PD with a PAF frame to transmit its certificate in turn. This frame has a "Response" action type and transmits its certificate and a sequence number in its data. As with the sending of a Request frame, the size of the PAF frame may be insufficient to support the total length of the certificate; the sequence number will be used to reconstruct the certificate.
[0077] The PD pairing device, in turn, authenticates the received certificate to determine whether the master device MD of the network it wishes to pair with was issued by a device considered trusted, thus validating the rest of the procedure and enabling it to send its information. The certificate issued by the master device MD must be associated with an organization known and validated by the PD pairing device to be considered trusted. If the certificate is not valid, the PD pairing device cancels the procedure with the direct device DD that sent the Response frame. If there are no more valid compatible devices, the procedure is canceled.
[0078] An additional frame type is also present to allow the replay of the two preceding action frames in case of errors such as an incomplete certificate or key. This frame is defined by the action type "Query" and must indicate the action frame it requests (Request or Response). If, after a configurable number of Query frame transmissions, either of the two preceding steps has not been completed, the procedure is terminated respectively on the AD network device side for the Query frame of a Request frame and on the PD matching device side for the Query frame of a Response frame. The latter cancels the procedure for the requested AD network device. A configurable number of received Query frames also prevents abusive requests and ignores any Query frame exceeding this number.
[0079] With reference to [Fig.3], we describe the step of selecting the trusted third-party device and the pairing step of the method according to the invention.
[0080] From this step onward, the content of all frames sent with Public Action Frames (PAFs) is encrypted using the public key of the receiving device and signed with the private key of the sending device. If a device is unable to decrypt a frame with its private key and authenticate the sender by signature, the procedure is canceled for the sending and receiving pair. The PD pairing device can then continue the procedure with another compatible device on the network or cancel it if no more compatible devices are available.
[0081] The pairing device PD sends its identification information to the direct device DD. This information includes its BSSID and SSID. This information is saved in memory by the master device MD and will be reused later in the procedure. The pairing device PD sends its information using a frame containing the action type Info (for information), its BSSID, and its SSID.
[0082] The PD pairing device then waits for the information necessary to continue the procedure, sent for each device on the AD network that received the Info frame. A timer of configurable duration is started, after which, once finished, the PD pairing device can send another Info frame and restart the timer. The PD pairing device can repeat this operation a configurable number of times. If the information is not received, the PD pairing device cancels the procedure with the direct device DD with which it is communicating.
[0083] The direct device DD, having received an INFO frame, responds with a list of devices (STA), one of which will be selected as the trusted third-party device in the remainder of the procedure. The list of devices (STA) is provided by the master device MD.
[0084] The master device MD therefore creates a list of STA devices. To be included in the list, the STA device must meet the following conditions:
[0085] - Support the IEEE 802.11k (“Radio resource measurement”) standard,
[0086] - Support the IEEE 802.11 w standard (“Protected Management Frame”),
[0087] - To be associated via Wi-Fi with one of the devices on the AD network.
[0088] Support for IEEE 802.11k and IEEE 802.11w standards is announced at the connection of the STA device when sending an Association Request frame.
[0089] The direct device DD sends the list of STA devices to the pairing device PD in a frame with a "List" action. This frame contains in its data all the MAC addresses of the STA devices in the list, as well as the channel and frequency band used by each STA device. If several devices Positive devices on the AD network send a List frame containing the same MAC address; the PD matching device cancels the procedure with the relevant devices on the AD network.
[0090] Upon receiving the List frame, the PD pairing device monitors each of the STA devices in the list and measures the received power of the Wi-Fi signals they emit. If the measured received power of one of the STA devices in the list exceeds a predetermined threshold, the STA device is then designated as a trusted third-party STA (TTP STA). The PD pairing device stops monitoring the other STA devices and informs the direct device (DD). If no STA device is designated as a trusted third-party STA after a configurable period, the PD pairing device proceeds to the list of STA devices received in the List frame of the next device in the AD network, based on the received signal strength. If all lists have been processed, the procedure is canceled.
[0091] Once the TTP STA trusted third party is selected by the PD matching device, the latter informs the direct device DD of its choice. The PD matching device transmits the information via a frame with a "Selection" action. This frame contains information relating to the TTP STA trusted third party device, such as its MAC address, the channel on which it was detected, and the power level at which the PD matching device measured it.
[0092] The PD matching device then waits for the reception of a "Validation" frame, which will be described below. A timer of configurable duration is started, after which, once finished, the PD matching device can again send a Selection frame and re-start the timer. The PD matching device can repeat this operation a configurable number of times. If the expected frame is not received, the PD matching device cancels the procedure with the direct DD device and terminates the entire procedure.
[0093] Upon receiving the Selection frame, the master device MD checks whether the trusted third-party device TTP STA belongs to the originating list and whether the power level measured by the matching device PD is above a predetermined threshold. If these conditions are met, the master device MD validates the device in the STA list as a trusted third-party device TTP STA. The direct device DD transmits the information to the matching device PD.
[0094] The pairing device is then monitored in turn by the direct device DD via the trusted third-party device TTP STA using the strength of the signal received via an 802.11k protocol. The pairing device PD is considered reliable for pairing if its received signal exceeds a predetermined threshold.
[0095] Once the pairing device is considered reliable for pairing, the The connection information of the master device MD is sent by the direct device DD to the pairing device PD. The pairing device pairs with the network.
[0096] Typically at least one of the means of the device according to the invention described above, preferably each of the means of the device according to the invention described above, are technical means.
[0097] Typically, each of the means of the device according to the invention described above may include at least one computer, a central processing unit or computing unit, an analog electronic circuit (preferably dedicated), a digital electronic circuit (preferably dedicated), and / or a microprocessor (preferably dedicated), and / or software means.
[0098] Of course, the invention is not limited to the examples just described and many modifications can be made to these examples without departing from the scope of the invention.
[0099] Of course, the various features, forms, variants, and embodiments of the invention can be combined with one another in various ways, provided they are not incompatible or mutually exclusive. In particular, all the variants and embodiments described above are combinable.
Claims
Demands
1. A method for automatically pairing at least one pairing device (PD) to a communication network via a trusted third-party device (TTP STA) located in the vicinity of said pairing device, at least one master device (MD) being connected to said network, the method comprising the following steps: - detection of network devices (AD) compatible with pairing by the pairing device (PD), - exchange of connection and identification data between the pairing device (PD) and one of the detected compatible devices on the network (AD), the detected compatible device on the network chosen for the exchange becoming a direct device (DD), - sends to the matching device (PD) via the direct device (DD), a list of devices (STA) that can be considered as trusted third-party devices (TTP STA), - monitoring of devices on the list (STA) by the pairing device (PD) using the signal strength received by each of them, the one with the highest received power and exceeding a predetermined threshold being chosen as the trusted third-party device (TTP STA), - monitoring of the pairing device (PD) by the direct device (DD) via the trusted third-party device (TTP STA) using the strength of the received signal, the pairing device (PD) being considered reliable for pairing if its received signal exceeds a predetermined threshold, - sending the connection information of the master device (MD) by the direct device (DD) to the pairing device (PD) reliable for pairing.
2. An automatic pairing method according to claim 1, wherein the step of exchanging connection and identification data between the pairing device (PD) and one of the compatible detected devices on the network (AD) comprises at least one subsequent step: - transmission by the pairing device (PD) to the direct device (DD) of the connection data of said pairing device (PD), - authentication of the connection data of the pairing device (PD) received by the direct device (DD) by the master device (MD), - transmission by the direct device (DD) to the pairing device (PD) of the connection data of the master device (MD), - authentication of the master device's (MD) connection data by the pairing device (PD).
3. Automatic pairing method according to any one of claims 1 to 2, wherein the direct device (DD) corresponds to the master device (MD) or to a relay device (SD).
4. Automatic pairing method according to any one of claims 1 to 3, wherein the step of exchanging connection and identification data between the pairing device (PD) and one of the compatible detected devices on the network (AD), also includes the following step: - sending the identification information of the pairing device (PD) to the direct device (DD).
5. An automatic pairing method according to any one of claims 1 to 4, wherein the data exchanges between each device are carried out according to a type of action, the type of action corresponding to at least one of the following actions: - information - list - selection - validation - query - inquiry - response
6. Automatic pairing method according to any one of claims 1 to 5, wherein the connection data includes at least one identification certificate.
7. Automatic pairing method according to any one of claims 1 to 6, wherein the identification data includes a MAC address of the master device and a network name.
8. Automatic pairing method according to any one of claims 1 to 7, wherein the data exchanges between each device are carried out via at least one standardized Wi-Fi frame.
9. Automatic pairing method according to claim 8, wherein the standardized Wi-Fi frame contains at least one piece of data relating to: - a type of action linked to the sending of the standardized Wi-Fi frame, - data relating to the action.
10. Automatic pairing method according to any one of the claims instructions 1 to 9, in which the device list (STA) is sent as a standardized Wi-Fi frame including all MAC addresses of the devices (STA) in the list, as well as the channel and frequency band used by each device in the list (STA).
11. System comprising at least one master device (MD) connected to a network, at least one device of the system comprising a processing unit configured to implement a method according to any one of claims 1 to 10.
12. Product computer program comprising instructions which, when the program is executed by a processing unit in at least one network device, causes the latter to implement the method according to any one of claims 1 to 10.