Methods, devices and systems for automatically adding devices to network using wireless positioning techniques

JP2023160794A5Pending Publication Date: 2025-09-26CYPRESS SEMICONDUCTOR CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023069213
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-04-21
Filing Date
2023-04-20
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing methods for adding devices to wireless networks, such as those in the Internet of Things (IoT), often require manual configuration, lack uniformity, and pose security risks due to user input during the commissioning process.

Method used

A method involving a configuration device that stores user network information, authenticates a target device using wireless communications, and performs wireless positioning to automatically configure the device to the network without user input, utilizing protocols like Wi-Fi Channel State Information (CSI), Wi-Fi Fine Time Measurements (FTM), and Bluetooth Low Energy (BLE) Angle of Arrival/Angle of Departure (AoA/AoD) for secure and automatic device addition.

Benefits of technology

Enables easy, secure, and automatic addition of wireless devices to networks with security guarantees provided by wireless positioning, eliminating the need for manual user input and enhancing network configuration efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide methods, devices and systems for automatically adding devices to a network using wireless positioning techniques.SOLUTION: A method can include, by operation of a configuring device: storing user network information in the configuring device; receiving wireless communications from a target device; authenticating the target device; indicating a pointing direction for the configuring device; and executing a wireless positioning operation with the target device to generate positioning data. In response to the configuring device being determined to be pointing at the target device, the target device is automatically configured for the user network with the stored user network information. Corresponding methods for the configuring device, as well as devices and systems are also disclosed.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to wireless systems and, more specifically, to automatically adding devices to a wireless network.

Background Art

[0002] The addition of network connectivity to consumer and industrial devices, including the expanding Internet of Things (IoT), has led to a need to frequently add new devices to user networks. Typically, manufacturers include instructions that enable a user to manually configure (i.e., "commission") a device to the network. However, such applications lack uniformity and can be inconvenient for the user. Further, having the user enter network information can present security vulnerabilities.

[0003] To simplify the commissioning process, device provisioning protocols such as Wi-Fi Easy Connect, published by the Wi-Fi Alliance, have been proposed. Such protocols aim to reduce configuration complexity by using QR codes, NFC tags, or information downloaded from a server. However, such provisioning protocols may also require user input at the bootstrap stage, which presents security vulnerabilities and can sometimes burden the user.

[0004] It would be desirable to reach an easier way to commission a device to a wireless network.

Summary of the Invention

Means for Solving the Problems

[0005] Embodiments may include a configuration device method comprising: operating a configuration device to store user network information; receiving wireless communication from a target device to be configured; authenticating the target device using data from the wireless communication; indicating the pointing direction of the configuration device; and performing a radio positioning operation with the target device. The radio positioning operation can generate positioning data indicating the location of the target device relative to the configuration device. In response to the target device being pointed at the configuration device, the target device can be automatically configured to the user network using the stored user network information. [Brief explanation of the drawing]

[0006] [Figure 1] This is a flowchart illustrating a method for configuring a device (configurator) according to one embodiment. [Figure 2] This is a flowchart illustrating a method for configuring a device (target device) according to one embodiment. [Figure 3A] This figure shows the configuration process according to one embodiment. [Figure 3B] This figure shows the configuration process according to one embodiment. [Figure 3C] This figure shows the configuration process according to one embodiment. [Figure 3D] This figure shows the configuration process according to one embodiment. [Figure 4] This is a flowchart illustrating the transmission of wireless positioning data according to an embodiment. [Figure 5A] This is a graph comparing the wireless channel response of devices with and without a line of sight. [Figure 5B] This is a graph comparing the wireless channel response of devices with and without a line of sight. [Figure 6A] This is a flowchart of a configurator method according to another embodiment. [Figure 6B] This is a flowchart of a configurator method according to another embodiment. [Figure 7A] This is a flowchart of a method for a target device according to another embodiment. [Figure 7B] This is a flowchart of a method for a target device according to another embodiment. [Figure 7C] This is a flowchart of a method for a target device according to another embodiment. [Figure 8] This is a block diagram of a configurator according to one embodiment. [Figure 9] This is a block diagram of a configurator according to another embodiment. [Figure 10] This is a block diagram of a target device according to one embodiment. [Figure 11] This is a block diagram of a target device according to another embodiment. [Figure 12A] This figure shows a configurator according to an embodiment. [Figure 12B] This figure shows a configurator according to an embodiment. [Figure 13] This is a diagram of an antenna that may be included in the configurator according to the embodiment. [Figure 14] This is a diagram of an integrated circuit device according to one embodiment. [Figure 15] This is a diagram of a system illustrating configuration work with security assurance provided by line-of-sight (LOS) between devices, according to one embodiment. [Figure 16A] This figure shows the configuration application of the configurator according to the embodiment. [Figure 16B] This figure shows the configuration application of the configurator according to the embodiment. [Figure 16C] This figure shows the configuration application of the configurator according to the embodiment. [Figure 16D] This figure shows the configuration application of the configurator according to the embodiment. [Figure 16E] This figure shows the configuration application of the configurator according to the embodiment. [Figure 16F]A diagram showing the configuration application of the configurator according to the embodiment. [Figure 16G] A diagram showing the configuration application of the configurator according to the embodiment. [Figure 17] A diagram of the post-configuration user notification according to one embodiment. [Figure 18] A diagram of a system including an Internet of Things (IoT) device that can be automatically configured for a network using LOS guarantee by a configurator according to an embodiment.

Mode for Carrying Out the Invention

[0007] The embodiment can provide a simple and secure way to add a wireless device to an existing wireless network. Using the stored public key and / or public key infrastructure, the configuration device (i.e., the configurator) and the device to be configured (i.e., the target device) can authenticate each other. The user can direct the configurator to the target device. By using a wireless positioning protocol, the devices can determine when they are pointing at each other and, accordingly, perform an automatic configuration operation to add the target device to the wireless network. Such an automatic configuration operation does not require user input.

[0008] In some embodiments, the wireless positioning protocol can generate wireless positioning data using multiple antenna readings.

[0009] In some embodiments, the wireless positioning protocol can include any of a channel state information protocol, an elevation angle protocol, a departure angle protocol, and a precise time measurement protocol.

[0010] In some embodiments, the configurator can advertise an automated configuration service that includes a digital certificate. The target device can authenticate the configurator with a stored key and / or access the key through a secure channel established by the configurator.

[0011] Figure 1 is a flowchart of Method 100 according to one embodiment. Method 100 can be performed by a configurator device to automatically configure a target device to operate on a wireless network. Method 100 may include initiating a configuration operation 102-0. The configuration operation can be initiated by any suitable action, including, but not limited to, a user launching a configuration application, a user activating a predetermined input on the configurator device, or a user powering on the configurator device. The configurator can communicate with the target device 102-1. Such actions may include wireless communication with the target device. The target device can respond to the configurator and / or the configurator can respond to the target device. In some embodiments, such actions may include generating or responding to a broadcast (e.g., an advertisement) type transmission.

[0012] Method 100 may include the configurator instructing that the configurator should point to a target device 102-2. Such action may include providing the configurator device with a direction indicator. Such direction indicator may include, but is not limited to, a symbol on a display, one or more lights, a label, an emboss, a voice indication and / or voice or text direction, and may take any suitable form.

[0013] Method 100 can authenticate the target device 102-3. In some embodiments, such action may include decrypting a security certificate or the like received by the configurator from the target device. In some embodiments, such action may include using a key represented in a public key infrastructure, while in other embodiments, it may include using a known secure private key. If the target device cannot be authenticated (102-3 to N), the configuration work can be terminated 102-4.

[0014] If the target device is authenticated (102-3 to Y), the configurator and the target device may perform one or more radio positioning operations 102-5. Such actions may include any suitable radio positioning method or protocol that can provide directional information that can be used to determine whether the configurator device is pointing to the target device. In some embodiments, the radio positioning protocol may include, but is not limited to, Wi-Fi channel status information (CSI), Wi-Fi precise time measurement (FTM), BLE angle of arrival (AoA), or angle of departure (AoD). In some embodiments, radio positioning may also determine the distance from one device to the other. Radio positioning may result in positioning data for the configurator device. If the positioning data does not confirm that the configurator is pointing to the target device (102-6 to N) (and / or the target device is too far away), the configuration operation may be terminated 102-4.

[0015] If positioning data confirms that the configurator is pointing to the target device (102-6 to Y), the target device can be automatically configured to the user network using user network data stored in the configurator device 102-7. In some embodiments, such action may include no user input regarding network configuration and no need for the user to initiate bootstrap work (e.g., scanning a QR code or detecting / generating Near Field Communication (NFC) values).

[0016] In this way, the configurator device can automatically add new wireless devices to the network with the security assurance provided by the wireless positioning data.

[0017] Figure 2 is a flowchart of Method 204 according to one embodiment. Method 204 can be performed by a target device which is to be automatically added to the network by a configuration device. Method 204 may include communicating with a configurator device 206-0. As in Figure 1, such action may include the target device responding to the configurator or vice versa, generating or responding to a broadcast-type transmission, and in some embodiments, action 206-0 may include the target device receiving a configurator device transmission (e.g., an advertisement) which includes the configurator's digital certificate.

[0018] Method 204 may include authenticating the configurator 206-1. In some embodiments, such action may include the target device decrypting a digital certificate or the like received from the configurator. In some embodiments, such action may include using a key pre-stored on the target device (e.g., by the manufacturer of the target device) or obtaining a key from a manufacturer's server. If the configurator cannot be authenticated (206-1 to N), the configuration work may be terminated 206-2.

[0019] If the configurator is authenticated (206-1 to Y), the target device can perform radio positioning with the configurator 206-3. Such action may include any appropriate radio positioning method and equivalent described herein. If the positioning data does not confirm that the configurator is pointing to the target device (206-4 to N), the configuration process can be terminated 206-2.

[0020] If positioning data confirms that the configurator is pointing to the target device (from 206-5 to Y), the target device may allow itself to be automatically configured for the user network by the configurator device 206-05. Such automatic configuration may include any of those described herein or equivalent, and may include the automatic exchange of bootstrap data followed by a Device Configuration Protocol (DCP). Such DCP may conform to an existing standard (e.g., Wi-Fi Easy Connect) or a proprietary standard.

[0021] In this way, the security assurance provided by wireless positioning data allows for the automatic addition of wireless devices to existing networks.

[0022] According to the embodiments, wireless positioning technology can be used to detect whether one device is pointing to another. This may include determining the shortest line of sight (LOS) between the two devices. Based on such determination, the two devices enter an automated configuration method, allowing them to be added to an existing network with little to no user input. As described herein, wireless positioning technology may include, but is not limited to, Wi-Fi CSI, Wi-Fi FTM, BLE AoA, and BLE AoD. In some embodiments, such methods can enable the rapid, simple, and secure addition of Internet of Things (IoT) devices to a user network.

[0023] According to the embodiments, a user can point a configurator at a target device for configuration. The configurator may be any suitable wireless device that can be pointed at the target device, including but not limited to a smartphone, remote control, tablet device, or wearable electronic device. In some embodiments, the target device can determine whether the configurator is pointing at it and execute a configuration service discovery protocol. In such a configuration, other wireless devices nearby will not interact with the configurator because they are not the device being pointed at. In some embodiments, in addition to determining the pointing direction, the wireless protocol may determine whether the two devices are within a predetermined distance from each other (e.g., not beyond the maximum range) before allowing the automatic configuration to proceed.

[0024] One device (i.e., the target device or the configurator) can detect a service discovery request from the other device (i.e., the configurator or the target device) and then proceed with device certification, bootstrapping, authentication, and configuration protocols. If all steps are successful, the target device can connect to the network without user input. In some embodiments, the configurator and the target device may include embedded certificates in their respective wireless communications to ensure that such protocols are not performed on nearby unintended (e.g., unauthorized) devices.

[0025] Figures 3A to 3D illustrate the operation of system 308 and its corresponding devices according to an embodiment. System 308 may include a target device 310, a configurator 312, and a server 314. The target device 310 and the configurator 312 may take the form of those described herein or equivalent thereto.

[0026] Referring to Figure 3A, the configurator 312 can store information that enables the target device to be added to an existing network. Such information may include, but is not limited to, networking information (e.g., extended service set identification information, ESSID, or Wi-Fi password), user account information (e.g., account URL, username, password for accessing the device on the network), and user notification data (e.g., mobile phone number, email address).

[0027] The configurator 312 can authenticate a user to the configurator 316. Such action may include, but is not limited to, any appropriate user authentication process, including, biometrics, passwords, PINs, location (e.g., GPS), or physical identification (e.g., magnetic strips, NFC devices), and may include two-factor authentication. If the user cannot be authenticated to the configurator (316 to N), the configuration work may be terminated 318.

[0028] If the user is authenticated to the configurator (316 to Y), the configurator can be activated to perform automated configuration tasks 320. Such actions may include those described herein or equivalent. If the configurator is activated (320 to Y), the configurator may advertise or instruct that the configuration service is available 322. Such actions may include the configurator sending wireless messages, for example, periodically, according to one or more protocols. Such advertisements may include, but are not limited to, transmissions over the Wi-Fi Direct (P2P) protocol, Wi-Fi Aware (Neighbor Aware Networking, NAN), and / or BLE advertising channels. The configurator may include an embedded digital certificate in the advertisement or in such initial protocol communication. Such embedded configurator certificate may enable a target device to authenticate the configurator. In some embodiments, the configurator certificate may include manufacturer identification information (e.g., the manufacturer's name and / or URL) signed by the configurator's public key, the manufacturer's public key, and the manufacturer's private key.

[0029] When powered on in 324, the target device 310 can determine whether it is configured or not 326. If the target device is configured (326 to Y), the configuration process can be completed 318. That is, if the target device 310 is configured for one network, it does not automatically request configuration for another network. In some embodiments, the target device 310 can be returned from a configured state to an unconfigured state by a reset operation, etc. Such action may include a predetermined command (e.g., a "factory" reset) from the following. If the target device is not configured (326 to N), the target device can request configuration 328. Such action may include monitoring radio communications for one or more configuration services indicated by the configurator.

[0030] Referring to Figure 3B, the target device 310 can discover the configurator certificate included in the configurator's communications (e.g., advertisements). The target device 310 can authenticate the configurator certificate offline (e.g., using its own local database) or online (e.g., through a secure connection using the configurator). According to some embodiments, a target device that has discovered the configurator certificate can determine whether the target device stores the configurator's public key. Such action may include the target device using configurator certificate information, such as the manufacturer's name or other ID, to access the stored public key corresponding to the configurator. In some embodiments, the target device may have its own database storing the public keys of multiple manufacturers. In some embodiments, an industrial organization (e.g., a target device manufacturer) may collect public keys from trusted manufacturers (e.g., configurator manufacturers) and store them in the target device's non-volatile memory.

[0031] If the target device stores the configurator public key (330-1 to Y), the target device can attempt to verify the configurator certificate 330-2. If the target device does not store the configurator public key (330-1 to N), the target device 310 can request the configurator 312 to relay encrypted data between the target device and a server known to the target device 330-4. If the configurator 312 can provide such relay, the configurator can respond when it is ready to relay such data 330-5. The target device can use the secure encrypted relay by the configurator to request a database of trusted manufacturer data (e.g., public key, manufacturer name) 330-6. In some embodiments, the configurator can relay an end-to-end HTTPS connection (or any other suitable connection such as a tunnel-direction link setup, TDLS, etc.) between the target device and the server in response to such request.

[0032] The server can respond by sending the database to the target device via the relay 330-7. Upon receiving such a database, the target device can instruct the configurator to terminate the relay 330-8. The target device 310 can update its local database 330-9 and attempt to verify the configurator certificate. If the configurator certificate can be verified (330-2 to Y), the configurator can be verified and the configuration process can continue (e.g., proceed to Figure 3C). If the configurator certificate cannot be verified (330-2 to N), the configuration process can be terminated 318.

[0033] Referring to Figure 3C, the configurator certificate has been verified, and the target device 310 can initiate the wireless positioning protocol 332-0. The wireless positioning protocol 332-0 enables the target device to detect the position / orientation of the configurator. The wireless positioning protocol can take any suitable form and may include the transmission of radio signals between the target device and the configurator to generate positioning data and / or positioning results. According to the embodiment, wireless positioning measurements can be performed by a proprietary FTM protocol with CSI support and / or BLE AoA / AoD measurements. For devices that can operate with both Wi-Fi and BLE protocols (for example, including a “combo” chip with radio circuits that support both Bluetooth and Wi-Fi), such Wi-Fi and BLE measurements can be performed together.

[0034] In some embodiments, the target device 310 can generate a nonce value or similar value to ensure the reliability of the wireless positioning protocol. Such a nonce value can be included in the data initially sent to the configurator. Such initial data can be encrypted with the configurator's public key. Both the target device and the configurator can use the nonce value to protect the position measurement data exchanged later. In just one of many possible examples, the nonce can be used to generate a keyed hash value of the measurement data.

[0035] According to one embodiment, the target device can analyze positioning data to determine whether the configurator is pointed at the target device 332-1. Such action may vary depending on the radio positioning protocol used. In some embodiments, by examining the CSI data, it can be determined whether all receiving antennas of the target device have essentially the same AoD from all transmitting antennas of the configurator. In addition, by analyzing the spectrum of the received signals, it can be determined whether they exhibit LOS channel characteristics. Furthermore, in some embodiments, it may also be possible to verify that the configurator is pointing to the target device by using distance measurements to the configurator. If it is determined that the configurator is not pointing to the target device (from 332-1 to N), the configuration work can be terminated 318.

[0036] If the configurator is determined to be pointing to a target device (332-1 to Y), the target device can continue the service discovery protocol with the configurator. The target device 310 can send its embedded security certificate 332-2. Such security certificate may take a form appropriate to the service discovery protocol being used and may include, but is not limited to, the target device's public key, the name of the target device manufacturer, the device manufacturer's public key, and a digital signature.

[0037] Upon receiving the target device certificate, the configurator can attempt to verify the certificate. In some embodiments, such verification may include actions similar to those described for the target device in Figure 3B. Specifically, the configurator can determine whether the target device public key is stored locally (332-3). If it is not stored locally (332-3 to N), the configurator can establish a secure connection with a known server 334 and request a database of all trusted target device manufacturers 332-5. Such a secure connection may follow any suitable protocol, including HTTP or TDLS, to name just two examples. Upon receiving the database 332-6, the configurator can update its local database 332-7 and then attempt to verify the target device certificate again. If the target device certificate cannot be authenticated by the configurator (332-4 to N), the configuration process can be terminated 318. If the target device certificate can be authenticated by the configurator (332-4 to Y), the configuration process can continue.

[0038] Referring to Figure 3D, after the target device certificate has been authenticated by the configurator, the configurator 312 can execute a radio positioning protocol with the target device 310 336-0. The radio positioning protocol 336-0 can take any form described herein or equivalent and can provide location data to the configurator 312. The configurator can analyze the location data to determine whether the configurator is directed toward the target device 336-1. Such action may include determining whether the target device is within a predetermined (e.g., minimum) distance from the configurator. If the configurator determines that it is not directed toward the target device (or is too far away) (336-1 to N), the configuration work can be terminated 318.

[0039] If the configurator determines that it is directed to a target device (Y from 336-1), the configuration work proceeds to automatically configure the target device 310 for the user network. The target device and the configurator can then perform an automated bootstrap operation 336-2. Such an action may include the target device and the configurator exchanging initial information necessary to communicate and perform authentication and configuration work. In some embodiments, such an action may include the target device transmitting bootstrap data equivalent to that generated from a device configuration protocol (DCP) such as Wi-Fi Easy Connect. As just one example, the target device may provide data equivalent to that generated from a QR code, an active or passive near-field communication (NFC) device / tag, or a text string of a conventional DCP. It is understood that such automated bootstrap 336-2 is performed automatically when the target device and / or the configurator verify that the configurator is directed to the desired target device, and does not require user input.

[0040] Following automatic bootstrapping, the target device and configurator can perform automatic authentication tasks 336-3 and automatic configuration tasks 336-4. In some embodiments, such actions may follow existing DCPs, including but not limited to Wi-Fi Easy Connect. However, the use of proprietary protocols is expected. In some embodiments, automatic authentication 336-3 can utilize a public key infrastructure. Automatic configuration 336-4 may include the configurator securely providing network data that enables the target device 310 to automatically join the user network. Network data may include, but is not limited to, a network ID (e.g., BSSID), a network password, a user ID, a user password, and user contact information (e.g., email, text number). It is understood that such automatic authentication 336-3 and configuration 336-4 are performed automatically between the target device and the configurator and do not require user input.

[0041] Once the automated configuration task 336-4 is complete, the target device 310 can automatically connect to the network.

[0042] Continuing to refer to Figure 3D, the target device 310 can automatically establish a user account if it has permission to access the Internet 336-6. Such action may include adding the target device to an existing user account, or, if there is no existing user account, creating an appropriate user account. In some embodiments, the target device can contact server 314' to create or update a user's "cloud" account 336-7. The target device can notify the user that the target device has been added to the user's network 336-8. Such action may include sending an electronic message to the user using user contact information. Such notification can take any appropriate form. In some embodiments, the notification may include a URL pointing to the user's general account, a URL pointing to a specific user account, or a URL pointing to a location where the target device's control application can be accessed or downloaded. If the target device does not have access to the Internet (336-5 to N), or if a notification has been generated, the target device can operate on the user network as designed 336-9.

[0043] In this way, new devices can be added to the network without user input. The user simply points the configurator device at the target device, and that device is automatically added to the network.

[0044] According to the embodiment, the configurator and target device can execute a radio positioning protocol that can generate and transmit location data in a secure manner. Any suitable radio positioning protocol can be used, but Figure 4 shows a radio positioning protocol 440 according to one embodiment. Protocol 440 may include communication between an initiator 442 and a responder 444. The initiator 442 may be a target device (e.g., Figure 3C, 332-0) or a configurator (e.g., Figure 3D, 336-0). The initiator 442 may store the public key of the responding device (e.g., from an embedded certificate in the configurator advertisement). The initiator 442 may issue a radio positioning protocol initiation request 446-0. Such a request may be encrypted with the public key of the responder 444 and may include a nonce or other generated value. The responder may respond with an acknowledgment 448 if it is able to execute the radio positioning protocol.

[0045] After a predetermined delay, at time t1_1, the responder may issue a message containing the first set of measurements 446-1. Such a message may be protected by values ​​received from the initiator, such as the nonce received in the initial request 446-0. The data contained in the measurement message may include, but are not limited to, time values ​​(departure / arrival times), power values ​​(received power, transmit power), signal angles relative to the antenna (arrival / departure angles), and channel status information (CSI), including but not limited to amplitude and phase. Upon receiving the measurement message, the initiator 442 may respond with an acknowledgment 448. Following the first measurement message 446-1, a series of time-delayed measurement messages 446-2 / 3 may be sent. Such messages may contain measurements taken at the departure time (e.g., t1_1) and arrival time (t4_1).

[0046] As described above, measurement messages (446-1 / 2 / 3) can be protected by a value sent in the initial request 446-0, such as a nonce. In some embodiments, measurement messages (446-1 / 2 / 3) can be protected by a message integrity check (MIC) framework that uses the nonce value as a key. In some embodiments, the MIC can be generated by a predetermined function (e.g., a hash function) that works with the nonce on the address and message payload. However, alternative embodiments may include any other suitable method of ensuring message integrity. Measurement messages (446-1 / 2 / 3) can be issued in bursts over burst periods 450. Figure 4 shows a set of three measurement messages, but embodiments predict more measurements per burst.

[0047] In this way, the device relays wireless measurements that are protected by a value (e.g., a nonce) exchanged in the initial secure communication.

[0048] According to the embodiments, the target device and / or configurator may include multiple antennas for detecting the orientation of one device relative to the other. In some embodiments, the measurement data may include amplitude and / or phase values ​​across the spectrum to enable determination of the line of sight (LOS) between the two devices.

[0049] Referring to Figures 5A and 5B, if a device with multiple antennas (e.g., a target device) is pointed to by another device with multiple antennas (e.g., a configurator) and the distance is relatively short, then all receiving antennas should have the same or similar AoD from their respective transmitting antennas (although different receiving antennas may detect different AoDs from the transmitting antennas). In such cases, the channel spectra (e.g., amplitude and / or phase) can have nearly ideal "LOS" characteristics. Figure 5A shows nearly ideal LOS characteristics and includes graph 552A of amplitude versus channel spectra, as well as graph 554A of phase-relative channel spectra. It is understood that graphs 552A / 554A represent multiple waveforms corresponding to separate antennas, but appear as a single waveform because they essentially overlap with each other. In contrast, Figure 5B shows the result when there is no LOS (NLOS). Graph 552B of amplitude versus channel spectra shows waveform 556-0 of one antenna different from waveform 556-1 of another antenna. Similarly, graph 554B of the phase-relative channel spectrum shows the waveform 558-0 of one antenna, which differs from the waveform 558-1 of another antenna. By using measurement data that reflects such amplitude and / or phase difference (or lack thereof) in the target device and / or configurator, LOS or NLOS can be indicated, and it can be confirmed whether the desired target device has been detected for configuration.

[0050] Figures 5A and 5B are provided as examples, and it is understood that differences in antenna data will vary depending on the protocol and / or environment. Working according to the embodiments, specific spectral portions can be selected for evaluation. Furthermore, in some embodiments, such measurements can be performed for multiple protocols (e.g., Wi-Fi and BLE).

[0051] Referring to Figures 6A and 6B, a flowchart of another embodiment of the configurator method 660 is shown. It is understood that Figure 6A connects to Figure 6B at the points labeled B1, B2, and B3.

[0052] Referring to Figure 6A, method 660 may include launching a configuration application 662-0. Such work may include, but is not limited to, any appropriate actions on the configurator device, including selecting functions on the configurator device, such as activating specific inputs, or launching a configuration application that resides in the configurator. Such configuration application may include instructions that can be executed by one or more processors in the configurator device. Such instructions may be stored in the configurator's non-volatile or volatile memory.

[0053] 662-1 The configurator may authenticate a user. Such action may include, but is not limited to, any appropriate user authentication, including a password (including a PIN), biometrics (e.g., fingerprint, facial recognition), or a physical key (e.g., an NFC tag, magnetic strip). If the user cannot be authenticated (662-1 to N), method 600 may terminate the configuration application 662-2.

[0054] Method 660 allows for the determination of network information, as described in 662-3. Such actions may include local and / or remote access to secure network information. In some embodiments, the configurator may include a secure local store (e.g., non-volatile memory) that can store the information necessary to enable a target device to be added to the network. In addition, or instead, the configurator device may also access a remote source (e.g., a server) to securely download network information. In other embodiments, a user may input network information. Network information may include, but is not limited to, a network identifier (e.g., BSSID), identification of the network's master device (e.g., a master node in a piconet), a network password, or other security information.

[0055] Method 660 allows for the determination of user account information. Such actions may include secure or remote options; that is, user account information may be stored in the secure memory of the configurator or accessed from another device via a secure connection. User account information may include, but is not limited to, information about a user who controls a network, including user contact information (e.g., email address, user mobile phone number), URLs or other accessible internet locations associated with the user, user identification values ​​(e.g., email address, user ID), or links or other connections to user applications that can track and / or control devices included in the user network.

[0056] Method 660 allows a user to be instructed to orient the configurator toward a target device. Such action may include, but is not limited to, any appropriate instructions, including, display generation instructions (e.g., arrows), lights or other indicators indicating the pointing direction, indicators on the body of the configurator (e.g., painted / embossed arrows, decals), written instructions and / or voice instructions accompanying the configurator.

[0057] Method 660 allows a configuration service to be advertised using a digital certificate 662-7. Such action may include any suitable radio transmission that can be detected by a target device. In some embodiments, such action may include transmitting one or more predetermined messages on a given set of frequencies or range (e.g., an advertising channel) and / or a transmission (e.g., a broadcast address or a custom address) that can identify itself as providing a configuration service. The digital certificate may enable authentication of the configurator. In some embodiments, the digital certificate may identify the configurator to enable the target device to authenticate the configurator and / or the configuration service. In some embodiments, the digital certificate may work with a public key infrastructure and a certificate authority. According to embodiments, the advertisement of the configuration service may be repeated periodically.

[0058] Method 660 may include monitoring requests for secure internet relay 662-8. Such action may originate from a target device requesting internet access to obtain data for authenticating the configurator, assuming the configurator can provide such access. If such a request is made (Y from 662-8), the configurator may enable secure relay 662-9. Such action may include, but is not limited to, enabling an end-to-end HTTP or TDLS connection between the target device and another device. The relay may be terminated 662-10. In some embodiments, a secure relay provided by the configurator may be terminated by a request from the target device and / or a timeout condition. It is understood that data transmitted over such relay is secure from the configurator.

[0059] Method 660 allows monitoring of requests from a target device to initiate a radio positioning operation. Such action may include receiving the radio request in accordance with a predetermined protocol. In some embodiments, such requests may be subject to a security protocol included in an advertisement for configuration services, which includes encryption by a predetermined key and method.

[0060] If such request is not received (from 662-11 to N) (including not being received within a specified period), the configuration work may be terminated 662-2.

[0061] If a radio positioning request is received (662-11 to Y), the configurator can decode the message to determine a unique value contained in the message that can be used to ensure the security of the radio positioning dataset 662-12. In some embodiments, such unique value may be a nonce generated by the target device. In some embodiments, if a radio positioning request is received and successfully decoded, the configurator may respond with an acknowledgment (ACK).

[0062] In response to a radio positioning request, Method 660 can generate and transmit a radio positioning dataset with integrity ensured by nonce 662-13. Such action may include providing radio positioning data in accordance with any of the methods / protocols described herein, or equivalents thereof, including, but not limited to, timestamped data indicating arrival and / or departure times, spectral values ​​of multiple antennas (e.g., amplitude and / or frequency), AoD values ​​and AoA values. In some embodiments, the positioning dataset may include MICs generated using nonce as shown in Figure 4.

[0063] Method 660 may wait for an ACK from the target device after transmitting each wireless location dataset 662-14. If no ACK is received (N from 662-14), Method 660 may retransmit the location data. If an ACK is received (Y from 662-14), Method 660 may continue transmitting location datasets until the last location dataset has been transmitted and acknowledged (Y from 662-15) (N from 662-15, 662-16). Several location datasets can be established according to any suitable method, including but not limited to a method indicated by an advertisement from the configurator (e.g., 662-7), a method indicated by a request from the target device (e.g., 662-11), or a method negotiated between the configurator and the target device.

[0064] Referring to Figure 6B, method 660 may include the configurator receiving a digital certificate from the target device 662-17. Having received the digital certificate, the configurator can determine whether a public key is stored locally 662-18. Such action may include looking up the key in secure memory using manufacturer information. If the target device's key is not included in the local database (from 662-18 to N), the configurator can retrieve such public key and update its local storage 662-19. In some embodiments, such action may include contacting a known server to download the latest database.

[0065] Method 660 may include the configurator attempting to authenticate a digital certificate from the target device (662-20). If the certificate cannot be authenticated (662-20 to N), the configurator may return to advertising the configuration service (662-7).

[0066] If the target device certificate can be authenticated (662-20 to Y), the configurator may request a radio positioning operation (662-21). Such actions may include any of those described herein or equivalent. If the configurator does not receive an ACK in response to that request (662-22 to N), the configurator may continue to request a radio positioning operation (if no acknowledgment is received, it may eventually time out and terminate the configuration operation).

[0067] The configurator may, following the receipt of an acknowledgment of its request (from 662-22 to Y), wait for the reception of radio positioning datasets transmitted from the target device. Such radio positioning datasets can be generated by the target device and may take any form described herein or equivalent. Method 660 may generate an ACK to send to the target device after receiving each radio positioning dataset (662-25). Method 660 may continue to receive positioning datasets until the last positioning dataset is received and acknowledged (from 662-26 to Y) (from 662-24, -26, -27 to Y).

[0068] Once all datasets (bursts) have been received, the configurator can determine whether it is pointing to a target device 662-28. If the configurator determines that it is not pointing to a target device (N from 662-28), the configurator can terminate the configuration process 662-2. If the configurator determines that it is pointing to a target device (Y from 662-28), the configurator can perform the automated authentication process 662-29 and the automated configuration process 662-30. Such automated processes can be performed without user input. As described in this document, in some embodiments, such automated processes may be performed by Wi-Fi Easy Connect, but may also be performed by a proprietary DCP. Such automated processes (662-29 / 30) can be initiated by the automated bootstrap described in this document, or an equivalent (i.e., a bootstrap that does not require user action).

[0069] Thus, once the configurator is authenticated along with the user, the configurator can automatically send and receive wireless location data and determine whether the configurator is pointing to the target device. The transmitted wireless encrypted data can be inspected using a value (e.g., a nonce) received from the target device.

[0070] Referring to Figures 7A to 7C, another embodiment of the target device method 764 is shown in a flowchart. It is understood that Figure 7A connects to Figure 7B at the points labeled B1, B2, and B3, and Figure 7B connects to Figure 7C at the point labeled C1.

[0071] Referring to Figure 7A, method 764 may include powering on the target device 766-0. If, upon power-up, the target device is already configured for the network (766-1 to Y) and the device has not undergone a factory reset (766-2 to N), the target device is configured and the configuration process can be completed. If the target device is not yet configured (766-1 to N) or has undergone a factory reset (766-2 to Y), the target device may search for a configuration service 766-3. If no configuration service is found (766-3 to N), the configuration process can be completed.

[0072] If a configuration service is found (766-3 to Y), the target device can receive a digital certificate from the configurator (766-4). Such work may include receiving an advertisement containing the embedded digital certificate. However, an alternative embodiment may include the target device issuing a request for a configuration service. From the digital certificate, the target device can retrieve the corresponding public key in the local database. If the local public key is not stored (766-5 to N), the target device can request a secure connection to a trusted server through the configurator (766-6). If such a secure connection cannot be provided (766-7 to N), the configuration work may be terminated. If a secure connection can be provided (766-7 to Y), the target device can retrieve data from the trusted public server through the connection and update its local storage to include the latest public key (766-8). Such action may include storing such data in the target device's secure non-volatile store.

[0073] If the target device cannot authenticate the configurator with a public key (766-9 to N), the target device may terminate the configuration work 766-10. If the target device can authenticate the configurator with a public key (766-9 to Y), the target device may generate a nonce value and send such value in an encrypted request to begin the radio positioning work 766-11. Such request may take any form described herein and may include, but is not limited to, establishing the number of bursts and / or burst durations during which the target device can receive measurement datasets from the configurator.

[0074] Referring to Figure 7B, following the request to initiate a radio positioning operation, method 764 may include waiting for the reception of a radio positioning dataset 766-12. If the dataset is not received, the target device may return to requesting a radio positioning operation 766-11. In some embodiments, if a location dataset is not received within a predetermined time, the configuration operation may be terminated (e.g., a timeout may occur). After receiving a radio location dataset, method 764 sends an ACK to the configurator 766-13. Method 764 may continue to receive and acknowledge location datasets (766-14 to N, 766-15) until the last location dataset has been transmitted and acknowledged (766-14 to Y). Such a location dataset can be established according to the embodiments described herein and their equivalents, can take various forms, and includes having a MIC generated by the configurator using a nonce from the target device.

[0075] After receiving the location dataset, the target device can analyze the data to determine whether the configurator is directed to the target device.766-16 Such analysis can take the form of those described in this document or equivalent. If it is determined that the configurator is not directed to the target device (N from 766-16), the configuration process can be terminated.

[0076] If the configurator determines that it is pointing to a target device (from 766-16 to Y), the target device may initiate the bootstrap process, which may include the encrypted transmission of the target device's digital certificate 766-17. The bootstrap process may include steps necessary for the target device to communicate across the network. The bootstrap process may include, but is not limited to, the identification of channel / link layer information and / or the exchange of temporary cryptographic keys. It is understood that, unlike conventional methods, the bootstrap process does not have to involve user actions, such as scanning a barcode or detection using NFC, to name just two examples.

[0077] In some embodiments, if the target device has sent its digital certificate to the configurator but has not received a request to initiate radio positioning work (766-18 to N), the configuration can be terminated. If such a request is received (766-18 to Y), the target device can generate and transmit a location dataset (766-19). If the configurator has not received an ACK for the location data, the target device can retransmit the location data. If an ACK is received (766-20 to Y), method 764 can continue transmitting location datasets until the last location dataset has been transmitted and acknowledged (766-21 to Y) (766-21 to N, 766-22).

[0078] Referring to Figure 7C, the target device can authenticate the configurator and, after determining that the configurator is directed to the target device, perform the automated authentication process 762-29 and the automated configuration process 762-30 with the configurator. Such automated processes can be performed without user input and may take any form described herein or equivalent.

[0079] If the target device is automatically authenticated and configured, and the target device can access the internet (766-23 to Y), and does not store user account data (766-24 to N), the target device can create a user account (766-25). If a user account exists or has been created (766-24, 766-25 to Y), the target device can automatically add the target device to the user account (766-26). The target device can notify the user that the target device has been added to the user network (766-27). In some embodiments, any or all of the creation of a user account (766-25), adding to a user account (766-26), or user notification (766-27) can utilize information provided by an automated device configuration action (e.g., 762-30).

[0080] Thus, when the target device is powered on, it can search for the Auto Configuration Service. Once it finds such a service, the target device can use the Line of Service (LOS) to assure the configurator that it has selected the target device for configuration.

[0081] Referring to Figure 8, a block diagram of a configurator 812 according to one embodiment. The configurator 812 may include a controller circuit 870, a memory system 872, a wireless circuit 874, and a pointing indicator 876. The controller circuit 870 may include a processor and / or logic circuit for performing the various configurator tasks described herein. The controller circuit 870 may include, but is not limited to, one or more processors having corresponding memory, custom logic, programmable logic, or a combination thereof. In some embodiments, the controller circuit 870 may include a processor that executes instructions 872-0 stored in non-volatile memory 878, which may be a secure area or may include a secure area. The secure area may be an area accessible only according to a predetermined security procedure.

[0082] In the illustrated embodiment, the controller circuit 870 can provide a user authorization function 870-0 and a configuration application 870-1. The user authorization function 870-0 can require the user to authenticate itself with the configurator 812 or the configuration application 870-1. The user authorization function 870-0 may include any personal authorization / authentication action described herein, or equivalents thereof. Such personal authorization / authentication actions may include, but are not limited to, biometric readers (e.g., fingerprint readers, cameras), user interfaces (e.g., text / voice input), and other input / output (IO) (e.g., NFC readers, magnetic readers, QR code processors), but may utilize functions present in the configurator 812.

[0083] Configuration application 870-1 may include various automatic configuration functions and their equivalents described herein. Such functions may include, but are not limited to, radio direction checking 880-0, automatic authentication 880-1, and automatic configuration 880-2. Radio direction checking 880-0 can use radio data to determine whether configurator 812 is directed to a target device. After determining that configurator 812 is directed to a target device, automatic authentication 880-1 can authenticate the target device without requiring the input of security data at that time, which includes authentication without user input and / or action. Similarly, after determining that configurator 812 is directed to a target device, automatic configuration 880-2 can configure the target device to the network (i.e., commission the target device) without requiring the input of network or user data at that time. Automatic authentication 880-1 and / or configuration 880-2 may take any form described herein or their equivalents, including DCPs according to existing standards and / or proprietary standards.

[0084] The memory system 872 may include any suitable memory to enable the configurator to perform configuration functions. The memory system 872 may include a secure non-volatile memory 878 that can store user data 872-1 for configuring the target device. The user data 872-1 may include user and / or configuration data as described herein, or equivalent, and includes data for configuring the target device.

[0085] The wireless circuit 874 may include circuits for communicating in accordance with one or more wireless standards, including but not limited to one or more IEEE 802.11 wireless standards and / or one or more BT standards (including BLE). The wireless circuit 874 may be configured to perform one or more radio positioning protocols 874-0, which may take any form as described herein or equivalent thereto. The radio positioning protocols 874-0 can provide radio positioning data to the configuration application 870-1. From such data, the radio direction finding function 880-0 can determine whether the configurator is pointed towards the target device.

[0086] The pointing indicator 876 can instruct the user on how to point the configurator towards the target device. The pointing indicator 876 can take any form as described in this document or an equivalent thereto.

[0087] Figure 9 is a block diagram of a configurator 912 according to another embodiment. The configurator 912 may include a processor system 970, a memory system 972, a wireless circuit 974, a cellular circuit 982, an audio control circuit 984, an input / output (IO) circuit, a display / user input (UI) control circuit 986, a camera control circuit 988, a location circuit 990, an NFC circuit 992, and one or more indicators 997.

[0088] The processor system 970 may include one or more processors capable of executing instructions 972-0 stored in the memory system 972 to provide various functions described herein, as well as other functions appropriate to the type of device (such as cellular communication, execution of other applications, etc.). The executed instructions 972-0 may provide functions including, but not limited to, user authorization 970-0, automatic configuration applications 970-1, radio positioning operations 980-0, and encryption and decryption 980-5. User authorization operations 970-0 may include any of the operations described herein and their equivalents, in which the user authenticates themselves with the configurator 912 or automatic configuration application 970-1. Embodiments anticipate user authorization 970-0, which includes activating any of the various parts of the configurator 912, including, but not limited to, a display / UI control circuit 986 (e.g., a fingerprint reader, text input for passwords and / or PINs), a camera control circuit 988 (e.g., facial recognition, other biometrics), a location circuit 990 (verification of the requesting user's physical location), or an NFC circuit 992 (detection of the user's NFC key).

[0089] The automated configuration application 970-1 may include the tasks described herein, including the automated authentication / configuration tasks 980-0 / 1 (e.g., standard or proprietary DCP) described herein, but without requiring user input (e.g., no QR code, no NFC scan, no text input). In some embodiments, the automated configuration application 970-1 may also perform a configuration advertising function 980-3, which can broadcast a notice of the automated configuration capabilities of the configurator 912 described herein or an equivalent. Such a broadcast may follow any suitable radio protocol, including but not limited to any 802.11 radio standard and / or BT standard. The automated configuration application 970-1 may also perform a target device certificate verification function 980-4, which can access a secure local or remote public key to verify a digital certificate received from a target device.

[0090] The radio positioning operation 980-0 can receive a location dataset from the target device via the radio circuit 974. From such location data, the configurator 912 can determine the orientation of the configurator relative to the target device. Such operations can be performed as described in the embodiments and equivalents of this document, including but not limited to CSI, FTM, AoA, and AoD. Such data can be generated using a radio dataset produced by any suitable radio standard, including but not limited to any 802.11 radio standard and / or BT standard. The encryption / decryption operation 980-5 can encrypt transmissions to the target device and includes using a nonce 978-1 received from the target device (e.g., including MIC in the radio dataset). Encryption can also use a public key from a public-private key infrastructure, as well as a temporary key (e.g., in bootstrap operations) and a long-term key (e.g., in automated authentication and configuration operations). The decryption operation can decrypt messages from the target device using a private key (local and / or acquired), as well as temporary and long-term keys.

[0091] The memory system 972 may include non-volatile "flash" memory 978 and volatile memory (e.g., DRAM) 972-2. The flash memory 978 may include a secure storage area that can store various values ​​for performing automatic configuration based on the direction (e.g., LOS) or equivalent as described herein. The values ​​stored may include, but are not limited to, instructions 972-0 executed by the processor system 970, keys 972-2 (e.g., target device public key, temporary key, long-term key), configurator digital certificates 978-0, user data (e.g., user network ID, network password, user account information), and one or more nonce values ​​978-1 (e.g., generated by the target device and derived by decrypting target device messages).

[0092] The wireless circuit 974 may include a BT circuit 974-1 and a Wi-Fi circuit 974-2. The BT circuit 974-1 can conform to one or more BT standards. The WLAN circuit 974-2 can conform to one or more IEEE 80.211 wireless standards. In some embodiments, the wireless circuit 974 may be part of a composite integrated circuit device. The wireless circuit 974 can be connected to an antenna system 994. The antenna system 994 may include multiple antennas to enable the generation of AoA and AoD values ​​in wireless positioning operations. The cellular circuit 982 can provide communication functions according to one or more cellular standards and can be connected to a cellular antenna system 996.

[0093] The I / O circuit 985 may include any suitable I / O circuit that can enable the configurator 912 to communicate with other devices. The I / O circuit 985 may be wired or wireless. In some embodiments, the I / O circuit 985 may include one or more serial interfaces. As described in this document, in some embodiments, the configurator 912 may include a directional antenna or antenna array 967. Such antenna 967 can be used for wireless detection work. In some embodiments, such antenna 967 can be connected to the configurator 912 by the I / O circuit 985.

[0094] The location circuit 990 can determine the location of the configurator 912 and may include a GPS circuit in some embodiments. The NFC circuit 992 can provide NFC capabilities to the configurator 912. The audio control circuit 984 can provide voice functionality to the configurator 912. The display UI control circuit 986 can control the display 998 of the configurator 912, which also functions as a user input (e.g., a touchscreen). The camera control circuit 988 can control the camera system 999.

[0095] According to the embodiment, any of the various parts of the configurator 912 can provide pointing instructions that instruct the user on how to orient the configurator 912 towards a target device for automatic configuration. The pointing instructions can take any suitable form, but the embodiment anticipates any of the following: visual pointing instructions 976-0 (e.g., arrows or other symbols) generated on the display 998 by the display / UI control circuit 986, another type of visual indicator 976-1 (e.g., LEDs, lasers), a physical pointer 972-6 (e.g., a pointer formed on the body of the configurator, such as a decal or embossing), or audio or tactile instructions 976-3 (e.g., vibrations) generated by the audio control circuit 984 or other circuitry.

[0096] In some embodiments, the processor system 970, the memory system 972, and the wireless circuit 974 can be formed by a system-on-a-chip (SoC) type device.

[0097] In some embodiments, the configurator 912 may be a handheld electronic device such as a smartphone, tablet, or other similar device. Thus, the configurator device can advertise an automated configuration task, and then, upon receiving an appropriate response from a target device and directing the configurator towards the target device according to a pointing indicator, it can perform such task.

[0098] Figure 10 is a block diagram of a target device 1010 according to one embodiment. The target device 1010 may include a controller 1095, a secure non-volatile memory 1093, and a radio circuit 1091. The controller 1095 may include circuitry for performing various functions described herein and may include one or more processors having corresponding memory, custom logic, programmable logic, or a combination thereof. The controller 1095 can provide an automated authentication task 1095-0 and an automated configuration task 1095-1. Such tasks may include those described herein and their equivalents, including proprietary DCPs or existing standards. According to the embodiment, such tasks may be enabled after the target device 1010 determines, based on radio positioning, that the configurator is directed to the target device 1010.

[0099] The secure non-volatile memory 1093 can store various values ​​necessary for operating the target device. According to one embodiment, the secure non-volatile memory 1093 can store configuration data 1093-0 and manufacturer installation data 1093-1. The configuration data 1093-0 can be provided by a configurator or the like through an automated configuration operation 1095-1, enabling the target device to operate within the user network. The manufacturer installation data 1093-1 may be data contained in the target device provided by the manufacturer of the target device, and may include a database of known good configurator manufacturer values ​​(e.g., keys, IDs, internet addresses). The target device 1010 can authenticate the configurator digital certificate using the manufacturer installation data 1093-1.

[0100] The wireless circuit 1091 can provide wireless communication conforming to one or more wireless standards. The wireless circuit 1091 can enable or provide a wireless positioning function 1091-0. The wireless positioning function 1091-0 can take any form as described herein or equivalent, and can enable the target device 1010 to determine when the configurator is directed to the target device 1010 and / or can provide a location dataset to enable the configurator to determine when the configurator is directed to the target device 1010. In some embodiments, the wireless circuit 1091 can detect advertisements or similar broadcasts from the configurator that indicate the presence of an automatic network configuration function. In an alternative embodiment, the target device 1010 can request automatic configuration.

[0101] In some embodiments, the target device 1010 can be formed on a single integrated circuit board.

[0102] Thus, the target device may include a radio positioning function that allows the configurator device to automatically configure the target device for the network once it is confirmed that the configurator device is directed towards the target device.

[0103] Figure 11 shows a target device 1110 according to another embodiment. The target device 1110 may be a composite device including a WLAN section 1189, a BT section 1187, and an input / output (IO) circuit 1185. The target device 1191 may have a radio circuit 1191 formed from a portion of the WLAN section 1189 and the BT section 1187. The target device 1110 can also operate with an antenna system 1183.

[0104] The WLAN section 1189 may include a controller section 1195 that communicates with a bridge interface 1173, an IEEE 801.11 radio circuit 1191, and an I / O circuit 1185 via a backplane 1179. The controller section 1195 may include a processor subsystem 1181 and a memory subsystem 1199. The processor subsystem 1181 can execute code 1175 stored in the memory system 1199 to provide various functions to the target device 1110. Such functions may include, but are not limited to, certificate verification 1181-0, nonce generation 1181-1, encryption / decryption 1181-2, bootstrap 1181-3, automatic authentication 1195-1, automatic configuration 1195-2, and automatic user account creation / update 1181-4. Certificate verification 1181-0 can verify a digital certificate received from the configurator. Such testing may include offline testing 1181-0a and online testing 1181-0b. Offline testing 1181-0a may include authenticating the digital certificate by accessing manufacturer authentication data 1193-1 (securely stored in memory subsystem 1199) after detecting the digital certificate in the configurator transmission. Online testing 1181-0b may include accessing a remote server to obtain data for authenticating the digital certificate after detecting the digital certificate in the configurator transmission. In some embodiments, such online authentication 1181-0b may include requesting a secure relay from the configurator. In alternative embodiments, if the target device 1110 has internet access, online authentication 1181-0b may include the target device 1110 directly contacting a known good server to obtain data used to authenticate the configurator digital certificate.

[0105] The nonce generator 1181-1 can generate a nonce value that can be included in one or more transmissions to the configurator device and can guarantee the integrity of communication with the configurator. In some embodiments, such a nonce value can be used to encrypt a radio location dataset transmitted to the configurator and / or guarantee its integrity (e.g., MIC). The encryption / decryption function 1181-2 can perform the encryption and decryption functions described herein, including those using a public key infrastructure. The bootstrap 1181-3 can initiate a communication protocol with the configurator to enable the automatic configuration of the target device (e.g., to add the target device to an existing network). In some embodiments, as described herein, such action may include the target device 1110 transmitting bootstrap data equivalent to that generated from the DCP (e.g., a QR code, data provided by an NFC chip), but may not include user data input or actions.

[0106] Automatic authentication 1195-1 and automatic configuration 1195-2 can take the forms described herein, including proprietary or existing DCPs (e.g., Wi-Fi Easy Connect). In some embodiments, such automated work can be initiated after the configurator determines that it is pointing to the target device 1110 (e.g., having an LOS with the target device 1110), after the target device 1110 determines that the target device 1110 is pointing to the configurator, or both.

[0107] Automatic user account creation / update 1181-4 may include the target device 1110 determining whether a user account exists. If a user account does not exist, the target device 110 may create a user account. Such action may include the target device 1110 directly contacting an appropriate server if it has internet access or through a secure connection via the configurator. If a user account exists, the target device 1110 may add itself to such account using user account data provided by the configurator. Such action may include the target device 1110 notifying the user when it has added itself to the network and / or user account.

[0108] The memory subsystem 1199 may include memory circuitry to enable the operation of the target device 1110. The memory subsystem 1199 may include secure non-volatile memory 1193 and optionally volatile memory (not shown). The secure non-volatile memory 1193 may store code 1175 executed by the processor section 1181 to provide the various functions described, configuration data 1193-0, and manufacturer installation data 1193-1. The configuration data 1193-0 may include network configuration data provided by the configurator in an automated configuration operation and may take the form described herein and equivalent forms. The configuration data 1193-0 may enable the target device to operate within a wireless network after the target device has been automatically configured by the configurator. The manufacturer data 1193-1 may be installed when the target device 1110 is manufactured and may be accessed by the target device in an offline certificate verification operation 1181-0a to verify the configurator digital certificate. In some embodiments, such data may be a database that can be updated in online certificate verification operation 1181-0b.

[0109] The bridge interface 1173 enables communication between the WLAN section 1189 and the BT section 1187.

[0110] The IEEE 802.11 radio circuit 1191A can provide wireless communication compliant with one or more IEEE 802.11 radio standards. The radio circuit 1191A may include a MAC layer circuit 1191A-0 and a physical layer (PHY) circuit 1191A-1. In some embodiments, the MAC layer circuit 1191A-0 can consist of a neighbor-aware network (NAN) MAC layer 1183 capable of executing one or more radio positioning protocols 1183-0. The PHY circuit 1191A1 can operate with the IEEE 802.11 RF circuit 1191-A2, which can enable the transmission of one or more IEEE 802.11 compliant communications in any suitable band, including but not limited to 2.4 GHz, 5 GHz, and / or 6 GHz.

[0111] The BT section 1187 may include a BT memory section 1187-0, a BT processor section 1187-1, a bridge control circuit 1187-2, and a BT communication control circuit 1171 that communicate through bus 1187-3. The BT memory and processor sections (1187-0 / 1) may include instructions and a processor for providing BT communication functionality. The BT communication control circuit 1171 can enable communication in accordance with one or more BT standards. In some embodiments, the BT control circuit 1171 can perform radio positioning operations 1183-1, including but not limited to AoD and AoA measurements. The BT section 1187 may also include a BT RF circuit 1169 that may include one or more BT standard-compliant radio circuits, including receiving and transmitting packets in accordance with BT standards.

[0112] The I / O circuit 1185 can enable control of the target device 1110 from an external source. The I / O circuit 1185 can enable communication with the device according to any suitable scheme. In some embodiments, the I / O circuit 1185 may include, but is not limited to, serial communication circuits including, a serial digital interface (SDI), a universal serial bus (USB), a universal asynchronous receiver / transmitter (UART), I2C, or I2S.

[0113] Device 1110 can operate in conjunction with antenna system 1183 having multiple antennas that conform to one or more BT standards and one or more IEEE wireless standards.

[0114] Radio positioning data can be generated by IEEE 802.11 compliant circuit 1191A or BT circuits (1171, 1169), but in some embodiments, radio positioning data from both such sources can be used in the radio positioning operation to determine the orientation of the configurator relative to the target device 1110.

[0115] In some embodiments, the WLAN section 1189, the BT section 1187, and the IO circuit 1185 can be formed in the same integrated circuit.

[0116] In this way, the target device generates wireless location data using multiple protocols and sends this data to the configurator, allowing it to verify that the configurator is pointed towards the target device before performing the automated configuration task.

[0117] A configurator according to an embodiment can take any suitable form and includes any device that refers to a target device to be automatically configured and that can perform the automated configuration tasks described herein or equivalent. The configurator may refer to the whole or have parts (e.g., a attachable section or a wired part such as a wand) that can refer to the target device. In some embodiments, the configurator may be a handheld electronic device.

[0118] Figure 12A shows a configurator 1212A according to one embodiment. The configurator 1212A may be a “smartphone” device having an internally formed wireless circuit 1274A and a resident configuration application 1270-1A. Such configuration application 1270-1A can work together with the wireless circuit 1274A to perform the automated configuration tasks and equivalents described herein. In some embodiments, the configurator 1212A may be an implementation of the one shown in Figure 8 or Figure 9.

[0119] Figure 12B shows a configurator 1212B according to another embodiment. The configurator 1212B may be a remote control type device having a wireless circuit 1274B and a configurator application 1270-1B, such as firmware instructions, which can be executed by a processor circuit (not shown) within the configurator 1212B. In the illustrated embodiment, the configurator 1212B may include pointing instructions 1276B that indicate to the user how to point the configurator 1212B during the automated configuration operation.

[0120] It should be understood that Figures 12A and 12B represent only two of the many possible implementations of the configurator according to the embodiment.

[0121] Thus, the configurator device may be a handheld device that can be easily pointed at the target device during automated configuration.

[0122] In some embodiments, it may be desirable to provide greater directional control over the radio positioning signals used in the automated configuration work described herein. Therefore, embodiments anticipate the inclusion, or addition, of a radio signal directionation structure 1367 that can restrict the direction of the transmitted and / or received radio signals to a pointing direction 1365. The radio signal directionation structure 1367 can take any suitable form and, in some embodiments, may include a directional antenna (e.g., 1367a, 1367b) or an antenna array (e.g., 1367C). As can be understood from the description herein, the pointing direction 1365 can be determined by the antenna structure of the configurator 1312.

[0123] Thus, the configurator may include a function that can guide the reception and / or transmission of radio signals to improve the signal strength of radio positioning data with a line of sight (LOS) to the target device.

[0124] The embodiments may include devices and systems having various interconnected components, but embodiments may also include integrated devices capable of performing the configurator and / or target device functions described herein. In some embodiments, such integrated devices may, advantageously, be a compact single integrated circuit (i.e., a chip). Figure 14 shows a packaged single-chip device capable of operating as the configurator 1412 or target device 1410 and its equivalent as described herein. The single-chip device 1410 / 1412 may take the form shown in Figures 8, 9, 10, or 11.

[0125] However, it is understood that the device according to the embodiment may include any other suitable integrated circuit packaging type, as well as direct bonding of the device chip to a circuit board or substrate.

[0126] In this way, a single integrated circuit solution can be provided to the configurator and / or target device.

[0127] Figure 15 shows a system 1563 according to another embodiment. System 1563 may include several target devices 1510-0 to 1510-2 and a configurator 1512. The configurator 1512 may include an automated configuration application 1570-1 that can generate a pointing direction indicator 1576 for the user.

[0128] The work of system 1563 may include an initial communication for configuration work. Such initial communication may include an advertisement for configuration services from configurator 1512 and / or a configuration request from the target device (1510-0 to -2). Such initial communication may instruct configurator 1512 that it can configure the target device (1510-0 to -2). However, the automated configuration work cannot proceed unless it is confirmed that configurator 1512 is directed to the responding target device (1510-0 to -2).

[0129] Continuing to refer to Figure 15, while configurator 1512 is directed to target device 1510-1, configurator 1512 can automatically configure target device 1510-1 (represented by configuration action 1553). In contrast, when configurator 1512 is directed to target device 1510-1, configurator 1512 is not directed to target devices 1510-0 or 1510-2. Therefore, even if target device 1510-0 or 1510-2 detects or responds to a configuration advertisement (including verifying the digital certificate of configurator 1512), such target device 1510-0 or 1510-2 has no LOS to configurator 1512, so the configuration work is stopped or not started (represented by "no configuration" 1555).

[0130] In this way, using configurator pointing can ensure security when new devices are added to an existing network.

[0131] Figures 16A to 16G illustrate the operation of the configurator 1612 according to an embodiment. Figure 16A shows that the configurator 1612 may be a smartphone or tablet device on which the configuration application 1670-1 is installed. Figure 16B shows how the activation of the configuration application 1670-1 leads to the user authentication process 1670-0. Figure 16B shows the user authentication process 1670-0 including biometric security, but alternative embodiments may include any other authentication type, including two-factor authentication.

[0132] Figure 16C illustrates how application 1670-1 provides network information 1659-0 for a network to which a target device can be added. In the illustrated embodiment, the network information can identify the network and the devices currently connected to the network. Figure 16D shows possible configuration options for configuration application 1670-1. Such options may include configuring a new device for the network 1659-1, as well as any other appropriate actions.

[0133] Figure 16E shows a pointing instruction 1676 that may be generated by the configuration application 1670-1. The user can use such pointing instruction 1676 to point the configurator 1612 towards the target device for configuration. Referring to Figure 16F, with the configurator 1612 pointed towards the target device, the configurator and the target device can determine the LOS (and optionally distance) between the two devices using the radio positioning data described herein, or equivalent. The configurator 1612 can then perform the automated authentication task 1680-1 and the automated configuration task 1680-2, and equivalents, described herein. Such tasks can automatically configure the target device to which the configurator 1612 is pointed. Such tasks may include existing or custom DCPs; however, such actions do not necessarily require user action. Figure 16G shows how, after the configuration process is successful, the newly added target device 1610 (i.e., the pointed target device) can be included in the network information 1659-0'.

[0134] Thus, a configurator may include an application that can display the network and automatically add target devices to the network by pointing to the target devices.

[0135] Figure 17 shows a notification 1766-27 of a user device 1757 according to one embodiment. The user device 1757 can receive a notification 1766-27 from the target device after the target device has been added to the user's network. As the embodiments described herein, after the automatic configuration of the user device by pointing the configurator at the target device, the target device can send a notification to the user. Such a notification can be generated using user information provided by the configurator.

[0136] In some embodiments, the user device 1757 may be a portable electronic device, and the notification may be any suitable electronic message, including but not limited to text or email messages.

[0137] In this way, after the automated configuration process is completed with security assurance through LOS verification, the target device can send a notification to a designated location.

[0138] Figure 18 shows a system 1863 according to another embodiment. System 1863 may include a configurator 1812 and various target devices 1810-0 to -5. Target devices (1810-0 to -5) include, but are not limited to, those shown in Figures 2, 3A to 3C, 4, and 7A to 7C, and can perform the automated configuration methods described herein.

[0139] In the illustrated embodiments, the target devices (1810-0 to -5) may include, but are not limited to, medical devices 1810-0 / 1, lighting equipment 1810-2, security equipment 1896-3 / 4, or instrumentation equipment 1050-5, and may be "Internet of Things" (IoT) type devices. The configurator 1812 can advertise (or respond to configuration requests for) an automated configuration service.

[0140] Using pointing instruction 1876, configurator 1812 can be directed to target device (1810-2). If the pointed target device (1810-2) is requesting configuration, target device 1810-2 can be automatically configured with configurator 1812 and its equivalent as described in this document (for example, automatically when radio position data confirms LOS between two devices).

[0141] Thus, IoT-type devices can be automatically configured by the security assurance provided by the Line of Sight (LOS) between the configuring device and the IoT device to be configured.

[0142] Embodiments may include methods, devices, and systems that, through the operation of a configuration device, include storing user network information in the configuration device, receiving wireless communication from a target device to be configured, authenticating the target device with data from the wireless communication, indicating the pointing direction of the configuration device, and performing wireless positioning operations with the target device to generate positioning data indicating the location of the target device relative to the configuration device. When it is determined that the configuration device is pointed towards the target device, the target device can be automatically configured to the user network using the stored user network information.

[0143] Methods, devices, and systems according to embodiments may include authenticating a user to a configured device.

[0144] Methods, devices, and systems according to embodiments may include, through the operation of a configuration device, wirelessly broadcasting information that identifies an automated configuration operation provided by the configuration device.

[0145] Methods, devices, and systems according to embodiments may include, through the operation of a configuration device, establishing a secure connection between a target device and a configuration server in response to a request from the target device.

[0146] Methods, devices, and systems according to embodiments may include positioning data, which may be channel status information, elevation angle measurements, departure angle measurements, and precise time measurements.

[0147] Methods, devices, and systems according to embodiments may include, through the operation of a target device, transmitting wireless communications to a configuration device in response to a broadcast from a configuration device.

[0148] Methods, devices, and systems according to embodiments may include authenticating a configuration device by the target device before performing a radio positioning operation with the configuration device.

[0149] Methods, devices, and systems according to embodiments may include, through the actions of a target device, receiving a digital certificate from a configuration device that identifies the configuration device, and, if the key for the configuration device is not stored by the target device, requesting a secure connection to a server through the configuration device.

[0150] Methods, devices, and systems according to embodiments may include, through operations between a target device and a component device, generating and encrypting a nonce value, sending a radio positioning protocol initiation request containing the encrypted nonce value to another device, and verifying a location dataset received from the other device.

[0151] Methods, devices, and systems according to embodiments may include a radio communication circuit configured to perform at least one radio positioning protocol, a secure non-volatile memory configured to store user network data, and a controller circuit. The controller circuit may be configured to radio communicate with a target device, authenticate the target device, and perform at least one radio positioning protocol with the target device to generate location data. If the location data indicates that the device is pointing to the target device, the controller circuit can use the stored user network data to automatically configure the target device to operate on the user network.

[0152] The methods, devices, and systems according to the embodiments may include a wireless communication circuit that conforms to at least one IEEE 802.11 wireless standard.

[0153] The methods, devices, and systems according to the embodiments may include an antenna system.

[0154] Methods, devices, and systems according to embodiments may include controller circuitry configured to generate an advertisement transmission that includes a device digital certificate and instructions for automatic configuration capability.

[0155] Methods, devices, and systems according to embodiments may include a handheld device having a display and a controller circuit configured to generate a pointing direction on the display.

[0156] Methods, devices, and systems according to embodiments may include a radio communication circuit configured to perform at least one radio positioning protocol, a secure non-volatile memory configured to receive and store network configuration data for the device, and a controller circuit. The controller circuit may be configured to radio communicate with the configuration device, authenticate the configuration device, and perform at least one radio positioning protocol together with the configuration device to generate location data. If the location data indicates that the configuration device is pointing to the device, the controller circuit may use the configuration data received from the configuration device to configure the device to operate on the network.

[0157] Methods, devices, and systems according to embodiments may include secure non-volatile memory configured to store keys for various configuration devices.

[0158] The methods, devices, and systems according to the embodiments may include wireless communication circuits, secure non-volatile memory, and controller circuits formed on the same integrated circuit substrate.

[0159] It should be understood that any reference in this specification to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in relation to the embodiment is included in at least one embodiment of the present invention. Therefore, it should be emphasized and understood that two or more references to “one embodiment” or “an alternative embodiment” in different parts of this specification do not necessarily all refer to the same embodiment. Furthermore, certain features, structures, or characteristics may be appropriately combined in one or more embodiments of the present invention.

[0160] Similarly, in the above description of exemplary embodiments of the Invention, it should be understood that various features of the Invention may be summarized in a single embodiment, figure, or description thereof for the purpose of simplifying the disclosure and aiding in the understanding of one or more different aspects of the Invention. However, this method of disclosure should not be interpreted as reflecting an intention that the claims require more features than those explicitly enumerated in each claim. Rather, the aspects of the Invention lie in fewer features than all of the single embodiments disclosed above. Therefore, the claims following the detailed description are hereby explicitly incorporated into this detailed description, and each claim stands independently as a distinct embodiment of the Invention.

[0161] While the present invention has been described with reference to exemplary embodiments, this description is not intended to be constrained. Various modifications and combinations of the exemplary embodiments, as well as other embodiments of the invention, will be apparent to those skilled in the art by reference to the description. Accordingly, the appended claims are intended to encompass such modifications or embodiments.

Claims

1. By working with configuration devices, storing user network information for a user network in the configuration device; receiving a wireless communication from a target device to be configured; authenticating the target device with data from the wireless communication; indicating a pointing direction of the configuration device; performing a radio positioning operation with the target device to generate positioning data indicative of the location of the target device relative to the constituent devices; automatically configuring the target device to a user network using the stored user network information in response to determining that the configured device points to the target device; A method comprising:

2. The method further includes authenticating a user to the configuration device. The method of claim 1.

3. The method further includes wirelessly broadcasting, by operation of the configuration device, information identifying the automatic configuration operation provided by the configuration device. The method of claim 1.

4. the method further comprising establishing, by operation of the configuration device, a secure connection between the target device and a configuration server in response to a request from the target device; The method of claim 1.

5. the positioning data includes any one selected from the group consisting of channel state information, elevation angle measurements, departure angle measurements, and precise time measurements; The method of claim 1.

6. the method further includes transmitting the wireless communication to the constituent device in response to a broadcast from the constituent device by operation of the target device; The method of claim 1.

7. The method further includes authenticating the constituent device by the target device operation prior to the step of performing the radio positioning operation by the constituent device. The method of claim 1.

8. The method includes, by operation of the target device: receiving a digital certificate from the configuration device identifying the configuration device; if the key of the configuring device is not stored by the target device, requesting a secure connection through the configuring device to a server; further comprising: The method of claim 1.

9. The step of performing the radio positioning task includes: generating and encrypting a nonce value for the target device to be configured; sending a Wireless Positioning Protocol Initiation Request to the constituent device that includes the encrypted nonce value; verifying the location data sets received from the constituent devices; Including, The method of claim 1.

10. The step of performing the radio positioning operation includes: sending a wireless positioning protocol initiation request to the target device; verifying the location data set received from the target device; Including, The method of claim 1.

11. 1. A device for automatically configuring a target device, the device comprising: wireless communication circuitry configured to implement at least one wireless positioning protocol; a secure non-volatile memory configured to store user network data of the user network; A controller circuit; Including, The controller circuit communicates wirelessly with the target device, authenticating the target device; executing, by the wireless communication circuitry, the at least one wireless positioning protocol with the target device to generate location data; configured to automatically configure the target device to operate on the user network using the stored user network data when the location data indicates that the device is pointing to the target device. device.

12. the wireless communication circuitry conforms to at least one IEEE 802.11 wireless standard; The device of claim 11.

13. the device further includes an antenna system including a plurality of antennas; the location data is selected from the group consisting of Wi-Fi channel state information, Wi-Fi precise time measurements, Bluetooth Low Energy elevation angles, and Bluetooth Low Energy departure angles; The device of claim 11.

14. the controller circuit is configured to generate an advertisement transmission including a device digital certificate and an indication of auto-configuration capabilities. The device of claim 11.

15. the device includes a handheld device having a display; the controller circuitry is configured to generate a pointing direction on the display; The device of claim 11.

16. A device, the device comprising: wireless communication circuitry configured to implement at least one wireless positioning protocol; a secure non-volatile memory configured to receive and store network configuration data for the device; A controller circuit; Including, The controller circuit communicates wirelessly with the configuration device, authenticating the configuration device; executing, by the wireless communication circuitry, the at least one wireless positioning protocol with the configuration device to generate location data; configured to configure the device to operate on a network using the received and stored network configuration data when the location data indicates that the configuration device points to the device; device.

17. the secure non-volatile memory is further configured to store keys for various constituent devices; 17. The device of claim 16.

18. The controller circuit Generate and encrypt a nonce value, transmitting the encrypted nonce value to the constituent device in a request to execute the at least one wireless positioning protocol with the constituent device; further configured as follows: The device of claim 11.

19. The controller circuit receiving a radiolocation data set from the constituent device; generating a radiolocation dataset; transmitting the generated radiolocation data set to the configuration device; further configured as follows: The device of claim 11.

20. the wireless communication circuitry, the secure non-volatile memory, and the controller circuitry are formed on the same integrated circuit substrate; The device of claim 11.