System and method for efficient onboarding to wireless network of group of WLAN devices owned by user

JP2023119589A5Pending Publication Date: 2025-10-28CYPRESS SEMICONDUCTOR CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023021413
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-02-16
Filing Date
2023-02-15
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing methods for onboarding multiple WLAN-enabled devices to a wireless network require manual intervention for each device, which is time-consuming and cumbersome, especially for users with multiple devices.

Method used

A system and method for automatically forming a common onboarding group (COG) among devices, exchanging unique identifiers, cryptographic algorithms, and secret keys, and using these to seamlessly onboard subsequent devices once the first device is connected, either with AP assistance or through a private onboarding network.

Benefits of technology

Enables efficient, automated onboarding of multiple devices by minimizing user interaction, reducing the time and effort required for connecting multiple WLAN devices to a new network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide methods for seamlessly onboarding commonly owned wireless local area network enabled devices to a wireless network.SOLUTION: The method includes: exchanging an UID, encryption algorithm and key between the devices to form a common onboarding group (COG), manually provisioning authentication information to onboard a first device (e.g., a mobile phone) of the COG; automatically provisioning authentication information to onboard a second device; using the first device to register, with an access point, the UID and a connection profile encrypted using the algorithm; using the access point to respond to a probe from the second device; and using the second device to decrypt the encrypted connection profile using a secret key so as to join the network.SELECTED DRAWING: Figure 2A
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to wireless local area network (WLAN) onboarding, and more particularly, to systems and methods for provisioning a group of WLAN devices owned by a user when entering a new WLAN range.

Background Art

[0002] Wireless networks use technologies or protocols such as wireless local area network (WLAN) that enable wireless-enabled mobile devices (e.g., laptops and notebook computers, mobile phones, cameras, smartwatches, health trackers, and other wearable devices) to interact with an IP network such as the Internet through a router or access point (AP).

[0003] Configuring a mobile device to connect to an existing wireless network is known as "onboarding." Common methods for onboarding a mobile device to an existing WLAN include the traditional method of having the device owner or user manually enter the Service Set Identifier (SSID), entering a security key into the device, provisioning credentials, and allowing the device to access the WLAN. More recent methods of onboarding include Wi-Fi Protected Setup (WPS) and Wi-Fi Easy Connect. In WPS, the user must press a physical or virtual button on both the AP and the station or device to trigger a protocol for establishing a secure tunnel where credentials are exchanged. For Wi-Fi Easy Connect, the user must obtain a Uniform or Universal Resource Identifier (URI) by scanning a Quick Response (QR) code (using a camera) or by using other types of wireless communication, such as Bluetooth, Bluetooth Extended, or Near Field Communication with the device being provisioned.

[0004] While none of the above onboarding methods are difficult, users need to manually initiate the onboarding process for each device they want to add to their WLAN. However, as it has become very common for people to own and carry multiple WLAN-enabled devices, including computers, mobile phones, cameras, smartwatches, and health trackers, having to manually and repeatedly onboard each device individually has become a time-consuming and cumbersome problem.

[0005] Therefore, when entering the range of a new wireless local area network, there is a need for a system and method for onboarding a group of wireless devices owned by a user. There is a further need for a system and method for onboarding that is substantially automated and requires minimal manual input or action from the user. [Overview of the project] [Problems that the invention aims to solve]

[0006] A system, computer program, and method are provided for automatically and seamlessly onboarding all or some of the devices in a group of commonly owned WLAN devices to the WLAN once any single device in that group has been onboarded. [Means for solving the problem]

[0007] Generally, the method involves, in the first phase, the steps of exchanging unique identifiers (UIDs), encryption algorithms, and secret keys among devices to form a common onboarding group (COG); in the second phase, the steps of manually provisioning credentials to onboard the first device of the COG; and finally, in the third phase, automatically provisioning credentials to onboard the second device.

[0008] In one embodiment, authentication information for provisioning a second and subsequent device is provided through a wireless network access point (AP). Briefly, after onboarding the first device, the first device registers its UID and encrypted connection profile with the AP, and the encrypted connection profile is encrypted using an encryption algorithm and a secret key. Next, when a second or subsequent device in the COG makes a query, i.e., sends a probe request to the AP that includes the UID exchanged when forming the COG, the AP responds with a probe response that includes the UID and the encrypted connection profile. The second or subsequent device then decrypts the encrypted connection profile using the secret key and joins the wireless network.

[0009] In other embodiments, in a third phase, credentials for provisioning the second and subsequent devices are provided directly from the first device in the COG being onboarded. In this embodiment, the step of automatically provisioning credentials to at least the second device in the COG includes: the first device monitoring the wireless network for a probe request from the second device, including a UID; the first device responding to the probe request with a probe response including a connection profile encrypted with an encryption algorithm and a secret key, and a UID; and the second device decrypting the encrypted connection profile of the second device using the secret key. The second device then joins the wireless network using the provisioned credentials.

[0010] In yet another embodiment, credentials for provisioning a second and subsequent device are provided from the first device over a private onboarding network (OBN). This method begins with a first phase, in which a service set identifier (SSID) or OBN name is predetermined, and a security profile for the OBN is negotiated, including a key management algorithm, an encryption algorithm, and a secret passphrase or key (K) to secure the OBN. Values ​​for the security profile may include, for example, DK_OBN as the SSID, Wi-Fi or Wireless Protected Access 2 (WPA2) as the key management algorithm, Advanced Encryption Standard (AES) as the encryption algorithm, and a string such as ab39Ax$b as the key for the passphrase or secret key (K). Thus, the first phase of this method differs from the first phase of the method described above in that the method described above does not require negotiation about the SSID or key management algorithm.

[0011] In the second phase, the first device in the group is connected to or onboarded to the wireless network using one of the known means described above. In the third phase, the private OBN is started using the first device, and a beacon is broadcast on the OBN. The second and subsequent devices in the group scan the wireless network, including the OBN, find a beacon on the OBN to connect to the first device, and exchange messages, and respond to this beacon. The second and subsequent devices then join the wireless network using provisioned credentials.

[0012] Further features and advantages of embodiments of the present invention, as well as the structure and operation of various embodiments of the present invention, are described in detail below with reference to the accompanying drawings. It should be noted that the present invention is not limited to the specific embodiments described herein. Such embodiments are presented herein for illustrative purposes only. Additional embodiments will be apparent to those skilled in the art based on the teachings contained herein.

[0013] Hereinafter, embodiments of the present invention will be described with reference to the accompanying schematic drawings, where corresponding reference numerals indicate corresponding parts, merely as examples. Furthermore, the accompanying drawings, incorporated into this specification and forming part of the specification, illustrate embodiments of the present invention and, together with the description, illustrate the principles of the present invention and further serve to enable those skilled in the art to create and use the present invention. [Brief explanation of the drawing]

[0014] [Figure 1] This is a simplified schematic block diagram illustrating a wireless network where methods for provisioning groups of wireless devices are particularly useful. [Figure 2A] This flowchart illustrates one embodiment of a method for provisioning a group of wireless devices, in which an access point in the wireless network assists in distributing authentication information to a second and subsequent devices. [Figure 2B]Figure 2A is a schematic block diagram illustrating the method. [Figure 3] This block diagram represents an embodiment of a standard radio frame used in probe request, probe response, and action frames, to which onboarding protocol attributes can be added. [Figure 4A] This flowchart illustrates one embodiment of a method for provisioning a group of wireless devices, wherein a first device being onboarded to a wireless network provides authentication information to a second and subsequent devices. [Figure 4B] Figure 4A is a schematic block diagram illustrating the method. [Figure 5A] This flowchart illustrates one embodiment of a method for provisioning a group of wireless devices, wherein a first device being onboarded to a wireless network provides authentication information to a second and subsequent devices on a private onboarding network. [Figure 5B] Figure 5A is a schematic block diagram illustrating the method. [Figure 6] This is a simplified schematic block diagram showing a computer program located in the memory of a wireless device, which is designed to automatically onboard a second and subsequent wireless device once the first device in a group of commonly owned wireless devices has been onboarded. [Modes for carrying out the invention]

[0015] Disclosed are a system, method, and computer program for automatically and seamlessly onboarding WLAN-enabled devices in a group of commonly owned devices to a wireless network once any single device in that group has been onboarded. The system, method, and computer program of this disclosure are particularly useful for automatically onboarding multiple commonly owned mobile devices, such as mobile phones, tablets, notebook and laptop computers, cameras, smartwatches, and health trackers, to public and private wireless local area networks (WLANs).

[0016] Figure 1 is a simplified schematic block diagram showing a wireless network 100 in which a method for provisioning a group of wireless devices is particularly useful. Referring to Figure 1, the wireless network 100 generally includes an access point (AP) 102, e.g., a router, which is coupled to an Internet Protocol network 104, e.g., the Internet, through a hardline or physical connection, e.g., fiber optic cable or Ethernet cable. Typically, the wireless network 100 further includes several wireless-enabled devices that are wirelessly coupled to the router 102 through one of several wireless network protocols. In one embodiment, the wireless network 100 is a WLAN, and the wireless-enabled devices include one or more computers 106, e.g., a laptop or notebook computer, a tablet 108, a mobile phone 110, a camera 112, a smartwatch 114, a health tracker 116, and other wearable devices. In accordance with this disclosure, some or all of these wireless-enabled devices 106, 108, 110, 112, 114, and 116 may be owned or used by a single common user, and may be grouped together to form a COG, which, once any single device in the group is onboarded, will be automatically and seamlessly onboarded to a wireless network.

[0017] Referring to the flowchart in Figure 2A and the schematic block diagram in Figure 2B, one embodiment of a method for provisioning a group of wireless devices is described, in which AP 102 in a wireless network 100 assists in distributing authentication information to a second and subsequent group of commonly owned devices. Referring to Figures 2A and 2B, the method begins with a first phase (Phase 1) relating to the step (Step 202) of exchanging multiple attributes among commonly owned WLAN-enabled devices to form a COG. As shown in Figure 2B, the COG includes at least one first device (e.g., a mobile phone 110) and a second device (e.g., a computer 106), and the number of multiple attributes exchanged may include a negotiated unique ID (UID), an encryption algorithm (Enc.Algor.), and a secret key (K). Generally, forming a COG occurs once per device before entering the range of a new wireless network and requires only some connectivity for the devices to communicate. Proper connectivity between devices can include connecting via a local area network (LAN), a wireless local area network (WLAN), near-field communication (NFC) tags, Bluetooth or Bluetooth Extensions (BLE), or by optically scanning a quick response (QR) code using the camera of a device added to the COG.

[0018] Next, in the second phase (Phase 2), when entering the range of the wireless network for the first time, the user manually provisions authentication information on the COG's first device (mobile phone 110) to onboard the first device to the wireless network 100 (Step 204), and the UID and encrypted connection profile (Enc in Figure 2B) K(cred) is automatically registered with the AP of the wireless network (step 206). Generally, manual onboarding of the first device by the user only needs to be performed once when entering the range of a new wireless network and can be achieved by any existing onboarding mechanism including Wi-Fi Protected Setup (WPS), Wi-Fi Easy Connect, QR code scanning, or manual input of WLAN authentication information. The encrypted connection profile is encrypted using the encryption algorithm (Enc.Algor.) and secret key (K) negotiated previously in phase 1.

[0019] Referring again to FIGS. 2A and 2B, in the following third phase (phase 3), the second device (computer 106) sends a probe request including the UID to the AP 102 (step 208). The AP 102 responds with a probe response including the UID and the encrypted connection profile (Enc K (cred)) (step 210), and the second device decrypts the encrypted connection profile using the encryption algorithm and the secret key, and thereby participates in the wireless network 100 using the provisioned authentication information (step 212).

[0020] In some embodiments, the UID, encryption algorithm, and secret key can be added as part of a wireless frame or packet used in a probe request, probe response, or action frame. FIGS. 3A to 3E are block diagrams showing an embodiment of a standard wireless frame 300 to which onboarding protocol attributes including the UID and / or encrypted authentication information can be added.

[0021] Referring to Figure 3A, a radio frame 300 typically includes multiple elements or fields, including frame control 302, duration 304, multiple address fields 306, sequence control 308, higher throughput (HT) control 310, frame body 312, and frame check sequence (FCS 314). Referring to Figure 3B, the frame body 312 may include irrelevant information fields 316 and 318. Referring to Figure 3C, information field 318 may include multiple information elements (IE320), here shown as IE1 to Ien. Referring to Figure 3D, the information within the general information elements (IE320) is typically stored in type or tag, length, and value or TLV format. Thus, referring to Figure 3E, group onboarding protocol attributes can be stored within a single IE in a radio frame 300 used for a probe request or probe response. In the illustrated embodiment, the group onboarding information element 322 may include a vendor-specific IE 324, a variable-length field 326, a vendor-organization-specific identifier (OUI 328), a group onboarding protocol 330, and a value / payload field 332 in which one or more group onboarding protocol attributes are stored.

[0022] Figures 4A and 4B illustrate an embodiment of another method for automatically provisioning multiple wireless devices within a COG after the onboarding of a first device, without requiring assistance from an AP. Referring to Figures 4A and 4B, the method begins in a first phase (Phase 1) with the step of forming a COG by exchanging multiple attributes among commonly owned WLAN-enabled devices (Step 402), and in a second phase (Phase 2) with manually provisioning authentication information to the first device in the COG (shown as a mobile phone 110 in Figure 4B) to onboard the first device to the wireless network 100 (Step 404). These steps are substantially the same as those described in steps 202 and 204 of the AP-assisted method described above.

[0023] In the third phase (Phase 3), the first device monitors the frequency or channel of the wireless network 100 for a probe request containing a UID from the second device (shown as computer 106 in Figure 4B) (Step 406). As indicated by the dashed arrow in Figure 4B, this probe request may also be received by AP 102 because the probe request is transmitted on the same channel or frequency used by the wireless network 100 and the second device is within range of the AP.

[0024] The first device responds to the probe request with a probe response containing a connection profile and UID encrypted using the encryption algorithm (Enc.Algor.) and secret key (K) previously negotiated in Phase 1 (Step 408). Note that AP102 also responds to the probe request. However, unlike the previous method, AP102 does not include any instructions or software that would allow the AP to recognize a special request from the second device (i.e., a request that is special due to the presence of a UID in the probe request), so it responds to the probe request with a response, which typically contains the UID and Enc.Algor. K This is similar to a normal, conventional probe response that does not include (Cred) and is ignored by the second device.

[0025] Finally, the second device decrypts the encrypted connection profile using an encryption algorithm and secret key, and then uses the provisioned credentials to join the wireless network 100 (step 410).

[0026] As described above with reference to Figures 3A to 3E, the UID, encrypted connection profile, and secret key (K) exchanged in the probe request (step 406) and probe response (step 408) can be added to existing WLAN frame formats designed for this type of exchange.

[0027] Figures 5A and 5B illustrate an embodiment of yet another method for automatically provisioning multiple wireless devices within a COG after the onboarding of a first device, where the first device onboarded to the wireless network provides authentication information to second and subsequent devices on the private onboarding network. Referring to Figures 5A and 5B, the method begins in a first phase (Phase 1) with the step of exchanging or negotiating several attributes among commonly owned WLAN-enabled devices to form a COG and a Secure Private Onboarding Network (OBN) (Step 502). As in the method described above, the attributes exchanged to form the COG may include a negotiated unique ID (UID), encryption algorithm (Enc.Algor.), and secret key (K). Additional attributes exchanged to form the OBN may include a service set identifier (SSID) or OBN name and key management algorithm. The values ​​for these attributes can include, for example, DK_OBN as the SSID, Wi-Fi or Wireless Protected Access 2 (WPA2) as the key management algorithm, Advanced Encryption Standard (AES) as the encryption algorithm, and a string such as ab39Ax$b as the key for the passphrase or secret key (K). Thus, the first phase of this method differs from the first phase of the method described above in that the method described above does not require negotiation about the SSID or key management algorithm.

[0028] In the second phase (Phase 2), the COG's first device (shown as mobile phone 110 in Figure 5B) is manually provisioned with authentication information and onboarded to the wireless network 100 (Step 504). The step of manually onboarding the first device is substantially the same as that described in Steps 204 and 404 of the AP assistance method described above.

[0029] In the third phase (Phase 3), the first device initiates a Private Secure Radio Onboarding Network (OBN505) and begins broadcasting a beacon carrying the OBN network name (Step 506). Here, the OBN uses the concept of a conventional WLAN access point to enable the remaining connectivity of COG members and request authentication information, although other WLAN protocols, such as Wi-Fi Aware or Wi-Fi Direct protocols, can be used. Alternatively, the OBN505 can include non-WiFi protocols or technologies, such as Bluetooth or BLE. To conserve power for the first device, the first device may host the OBN505 for a predetermined period of time after the first device has been onboarded, for example, 15 minutes. To conserve power, the first device may turn off its radio after transmitting the OBN periodic beacon and waiting for queries from other COG members for a predetermined period of time (e.g., 10 milliseconds). Additionally, or alternatively, after all devices in the COG, including the second device, have been onboarded, the first device may be configured or operable to stop broadcasting beacons and hosting the OBN505. In other schemes, the first onboarded device may periodically (e.g., once every 30 seconds) turn on the OBN network for short periods (e.g., turn on radio communication for 1 second, transmit 10 beacons, and respond to queries during this period).

[0030] Referring again to Figures 5A and 5B, the second device scans the wireless network including OBN 505 (step 508), and upon receiving a beacon on the OBN, securely connects the first and second devices on the OBN (step 510). Next, the first device exchanges messages with the second device on the OBN, including a connection profile (step 512). Finally, the second device joins the wireless network 100 using the credentials provisioned in this way (step 514).

[0031] In other embodiments, the disclosure relates to a computer program or application comprising instructions stored in a computer-readable storage medium within a plurality of commonly owned WLAN devices, the instructions, when executed by a processor within each WLAN device, cause the WLAN devices to form a common onboarding group (COG) of devices, and when a WLAN device is a first WLAN device in the COG to be onboarded to a wireless network, to automatically provision authentication information to at least one second WLAN device in the COG to onboard this second WLAN device to the wireless network. Figure 6 shows a simplified schematic block diagram illustrating one embodiment of such a computer program 600.

[0032] Referring to Figure 6, generally, the computer program 600 includes a COG module 602, which contains instructions for exchanging unique IDs (UIDs), encryption algorithms, and secret keys among multiple commonly owned WLAN devices, forming a common onboarding group (COG) of devices. As mentioned above, forming a COG requires that connectivity between wireless devices communicate these attributes. Generally, the COG module 602 may include instructions that enable WLAN devices to connect via LAN, WLAN, Bluetooth or BLE, or via NFC tags, or by optically scanning QR codes.

[0033] In an embodiment, the computer program 600 may further include a wireless network monitoring module 604 which includes instructions that cause a first WLAN device onboarded to the wireless network to monitor signals transmitted on a channel or frequency of the wireless network for probe requests from a second or subsequent WLAN device, and to respond to probe requests with probe responses that include a connection profile encrypted with an encryption algorithm and secret key, as well as a UID. As described above, the probe request may include a UID, and the probe response may include a connection profile encrypted with a previously negotiated encryption algorithm and secret key, as well as a UID.

[0034] In other embodiments, the computer program 600 may further include an onboarding network (OBN) module 606 which can operate to cause a first WLAN device to start a private wireless OBN after onboarding and broadcast beacons over the OBN, and the computer program 600 may further include an OBN monitoring module 608 which includes instructions that can operate a second WLAN device to scan for wireless networks including an OBN, securely connect to the first WLAN device over the OBN, exchange messages with the first WLAN device over the OBN, and receive a connection profile.

[0035] The OBN module 606 may include instructions for initiating a WLAN protocol wireless network, such as a hotspot, Wi-Fi Aware, or Wi-Fi Direct protocol. Alternatively, the OBN module 606 may include instructions for initiating a non-Wi-Fi protocol or technology, such as Bluetooth or Bluetooth Low Energy.

[0036] In addition, the OBN module 606 may include instructions to conserve power for the first device used to host the OBN. As described above, a method of conserving power may include limiting the time the first device hosts the OBN to a predetermined period, for example, 15 minutes, after the first device has been onboarded or turned off radio communication, after the first device has been broadcasted a periodic beacon and waited for probe requests from COG members for a predetermined period of time. Alternatively, the OBN module 606 may include instructions to stop broadcasting beacons and hosting the OBN after all devices in the COG, including the second device, have been onboarded. Alternatively, the OBN module 606 may enable the OBN periodically for a certain short period of time.

[0037] Finally, the computer program 600 may further include an automatic onboarding module 610, which includes instructions that can be used to cause a second and subsequent WLAN device to decrypt an encrypted connection profile using a secret key and automatically onboard to the wireless network.

[0038] Alternatively or additionally, in some embodiments in which an AP 102 in the wireless network 100 assists in distributing authentication information to second and subsequent devices in the COG, a computer program may further include a registration and response module 612, which includes instructions stored in a computer-readable storage medium in the AP, and which, when executed by a processor in the AP, can operate to cause the AP to receive and register a UID and encrypted connection profile from a first WLAN device being onboarded, to respond to probe requests from second or subsequent WLAN devices with probe responses including the UID and encrypted connection profile, and to implement the AP assistance method described above with reference to Figures 2A and 2B.

[0039] Accordingly, a method is disclosed for automatically and seamlessly onboarding WLAN-enabled devices in a group of commonly owned devices to a wireless network once any single device in that group has been onboarded. Embodiments of the present invention are described above with functional and schematic block diagrams illustrating the implementation of the specified functions and their relationships. The boundaries of these functional foundational elements are arbitrarily defined in this specification for the sake of clarity. Alternative boundaries can be defined as long as the specified functions and their relationships are adequately performed.

[0040] The above-described descriptions of specific embodiments sufficiently reveal the general nature of the invention so that others can readily modify and / or adapt these specific embodiments to various uses without departing from the general concept of the invention or without excessive experimentation, by applying their knowledge of the art. Therefore, such adaptations and modifications are intended to fall within the meaning and scope of equivalence of the disclosed embodiments, based on the teachings and guidance presented herein. It should be understood that the language or terminology in this specification is for illustrative purposes only, not limiting purposes, and that the language or terminology in this specification should be interpreted by those skilled in the art in consideration of the teachings and guidance.

[0041] It should be understood that the Chapter on Embodiments for Carrying Out the Invention, rather than the Chapter on Summary and Abstract, is intended to be used to interpret the claims. The Chapter on Summary and Abstract may describe one or more exemplary embodiments of the Invention, not all of them as intended by the inventor, and is therefore not intended to limit the Invention and the accompanying claims in any way.

[0042] The scope and breadth of the present invention should not be limited by any of the exemplary embodiments described above, but should be defined solely in accordance with the following claims and their equivalents.

Claims

1. exchanging a plurality of attributes among commonly owned wireless local area network (WLAN) enabled devices to form a common onboarding group (COG) of devices, wherein the exchanging a plurality of attributes includes negotiating among all commonly owned WLAN enabled devices a unique ID (UID), an encryption algorithm, and a secret key to be used by each WLAN enabled device of the COG; onboarding a first device of the COG to a WLAN by manually provisioning authentication information on the first device, wherein the manually provisioning of authentication information includes registering, with the first device, a connection profile encrypted with the encryption algorithm and the secret key and the UID with an access point (AP) for the WLAN; automatically provisioning the credentials to at least one second device of the COG to onboard the second device to the WLAN, wherein automatically provisioning the credentials to the second device includes using the second device to send a probe request including the UIDs exchanged between the commonly owned WLAN-enabled devices of the COG prior to manually provisioning credentials to the first device of the COG; A method comprising:

2. exchanging the plurality of attributes between commonly owned WLAN enabled devices includes establishing communication between the commonly owned WLAN enabled devices electronically using a local area network (LAN), a wireless network, a near field communication (NFC) or a Bluetooth protocol, or optically using a quick response (QR) code; The method of claim 1.

3. The step of exchanging the attributes between commonly owned WLAN-enabled devices is accomplished manually by a user or automatically using User Datagram Protocol (UDP) or TCP to discover previously unowned devices and add them to the COG. The method of claim 1.

4. The step of automatically provisioning the authentication information to at least one second device of the COG includes: sending the probe request including the UID directly to the AP; responding, using the AP, to the probe request with a probe response that includes the UID and the encrypted connection profile previously registered with the AP using the second device; decrypting the encrypted connection profile in the second device using the encryption algorithm and the private key and onboarding the second device to the WLAN; Including, The method of claim 1.

5. The step of automatically provisioning the authentication information to at least one second device of the COG includes: monitoring, by the first device, the WLAN for a probe request from the second device including the UID; Responding to the probe request with a probe response to the second device using the first device, the probe response including the encrypted connection profile and the UID previously registered with the AP using the first device; decrypting the encrypted connection profile in the second device using the encryption algorithm and the private key and onboarding the second device to the WLAN; Including, The method of claim 1.

6. The step of automatically provisioning the authentication information to at least one second device of the COG includes: Initiating a private wireless onboarding network (OBN) with the first device and broadcasting a beacon on the OBN; scanning, by the second device, for a wireless network including the OBN; securely connecting the first device and the second device over the OBN; exchanging messages from the first device to the second device over the OBN, the messages including the connection profile encrypted using the encryption algorithm and the private key; decrypting the encrypted connection profile in the second device using the encryption algorithm and the private key and onboarding the second device to the WLAN; Including, The method of claim 5.

7. The OBN comprises wireless protocols including hotspot, Wi-Fi Aware or Wi-Fi Direct and is secured using WLAN security standard protocols or non-WiFi technologies including Bluetooth; The method of claim 6.

8. Initiating the OBN and broadcasting the beacon includes hosting the OBN for a predetermined time after the first device is onboarded. The method of claim 6.

9. Initiating the OBN and broadcasting the beacon includes periodically broadcasting the beacon for a predetermined time period. The method of claim 6.

10. The step of initiating the OBN and broadcasting the beacon includes: hosting the OBN for a predetermined time after the beacon is broadcast; if a response is not received from the second device after the predetermined time, aborting the step of hosting the OBN; Including, The method of claim 6.

11. starting the OBN and broadcasting the beacon includes stopping the OBN after all devices in the COG, including the second device, have been onboarded. The method of claim 6.

12. the step of manually provisioning authentication information on the first device of the COG to onboard the first device to the WLAN is performed once by a user upon entering range of the WLAN. The method of claim 1.

13. manually provisioning authentication information on the first device of the COG to onboard the first device to the WLAN is accomplished by using Wi-Fi Protected Setup, Wi-Fi Easy Connect, a quick response (QR) code, or by the user manually entering the authentication information for the WLAN; The method of claim 12.

14. 1. A system comprising a plurality of commonly owned wireless local area network (WLAN) devices, each WLAN device comprising: a processor; a computer-readable storage medium having instructions stored thereon; the instructions, when executed by the processor, cause the WLAN device to: exchanging attributes including a negotiated unique ID (UID), an encryption algorithm, and a secret key between the WLAN device and all other WLAN devices of the plurality of commonly owned WLAN devices to form a common onboarding group (COG) of devices; When the WLAN device is a first WLAN device in the COG that enters range of a WLAN, automatically provisioning authentication information, and onboarding the WLAN device to the WLAN and automatically provisioning authentication information includes registering, with the WLAN, a connection profile encrypted with the encryption algorithm and the secret key and the UID with an access point (AP) for the WLAN; When the WLAN device is not the first WLAN device in the COG to enter range of the WLAN, automatically provisioning the WLAN device in the COG with authentication information, onboarding the WLAN device to the WLAN, and automatically provisioning the WLAN device with authentication information includes: sending, using the WLAN device, a probe request including the UID; and receiving a probe response including the UID and the encrypted connection profile. system.

15. The instructions, when executed by the processor, causing the first WLAN device of the COG to come into range of the WLAN and monitor signals transmitted on the WLAN for a probe request including the UID from a second WLAN device of the COG, and responding to the probe request with the probe response including the encrypted connection profile and the UID; causing the second WLAN device to decrypt the encrypted connection profile using the private key and automatically onboard to the WLAN; further comprising the instructions: The system of claim 14.

16. The instructions, when executed by the processor, causing the first WLAN device of the COG to enter range of the WLAN and, after onboarding, initiate a private wireless onboarding network (OBN) and broadcast a beacon on the OBN; When the WLAN device is not the first WLAN device in the COG that comes into range of the WLAN, Scanning for a wireless network including the OBN; securely connecting the first WLAN device over the OBN; exchanging messages with the first WLAN device over the OBN, the messages including an encrypted connection profile and the UID; automatically provisioning authentication information into the WLAN device and onboarding the WLAN device into the WLAN; further comprising the instructions: The system of claim 14.

17. 1. A computer program stored on a computer-readable storage medium in a plurality of commonly owned wireless local area network (WLAN) devices, comprising: The computer program includes instructions that, when executed by a processor within each WLAN device, cause the WLAN device to: exchanging attributes including a negotiated unique ID (UID), an encryption algorithm, and a secret key between the WLAN device and all other WLAN devices of the plurality of commonly owned WLAN devices to form a common onboarding group (COG) of devices; When the WLAN device is a first WLAN device in the COG that enters range of a WLAN, automatically provisioning authentication information, and onboarding the WLAN device to the WLAN and automatically provisioning authentication information includes registering, with the WLAN, a connection profile encrypted with the encryption algorithm and the secret key and the UID with an access point (AP) for the WLAN; When the WLAN device is not the first WLAN device in the COG that comes within range of the WLAN, automatically provisioning the WLAN device with authentication information, onboarding the WLAN device to the WLAN, and automatically provisioning the WLAN device with authentication information includes: sending, using the WLAN, a probe request including the UID; and receiving a probe response including the encrypted connection profile and the UID. Computer program.

18. The instructions, when executed by the processor, causing the first WLAN device of the COG to enter range of the WLAN and, after onboarding, monitor signals transmitted over the WLAN for a probe request including the UID from a second WLAN device of the COG, and respond to the probe request with a probe response including the encrypted connection profile and the UID; causing the second WLAN device to decrypt the encrypted connection profile using the private key and automatically onboard to the WLAN; further comprising the instructions:

18. A computer program according to claim 17.

19. The instructions, when executed by the processor, causing the first WLAN device of the COG to enter range of the WLAN and, after onboarding, initiate a private wireless onboarding network (OBN) and broadcast a beacon on the OBN; When the WLAN device is not the first WLAN device in the COG that comes into range of the WLAN, Scanning for a wireless network including the OBN; securely connecting the first WLAN device over the OBN; exchanging messages with the first WLAN device over the OBN, the messages including an encrypted connection profile and the UID, and automatically provisioning authentication information on the WLAN device; onboarding the WLAN device to the WLAN; further comprising the instructions:

18. A computer program according to claim 17.