Mesh network commissioning
The described method for secure mesh network commissioning using J-PAKE and DTLS-ClientHello messages addresses inefficiencies and insecurities in existing techniques, enhancing user experience and security through efficient and accurate device authentication and provisioning.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- GOOGLE LLC
- Filing Date
- 2025-04-01
- Publication Date
- 2026-06-02
AI Technical Summary
Existing mesh network commissioning techniques are inefficient, inaccurate, and insecure, particularly in large-scale networks, due to limited user interfaces, resource constraints, and the need for external certificate authorities, leading to cumbersome device authentication and credential provisioning.
A method for secure mesh network commissioning using a joiner router to authenticate devices with Password Authenticated Key Exchange (J-PAKE) and DTLS-ClientHello messages, and a border router to manage network credentials and commissioning sessions, ensuring secure communication and efficient device provisioning.
Enhances user experience and security by simplifying device authentication and credential provisioning, improving scalability and accuracy in large-scale mesh networks, while eliminating the need for external certificate authorities.
Smart Images

Figure 0007869367000004 
Figure 0007869367000005 
Figure 0007869367000006
Abstract
Description
Technical Field
[0001] Cross - Reference to Related Applications This application claims priority under 35 U.S.C. § 119(e) to U.S. Provisional Patent Application Serial No. 62 / 016,450, filed on Jun. 24, 2014. This application also claims priority to U.S. Provisional Patent Application Serial No. 62 / 063,135, filed on Oct. 13, 2014. This application also claims priority to U.S. Provisional Patent Application Serial No. 62 / 115,601, filed on Feb. 12, 2015. This application also claims priority to U.S. Provisional Patent Application Serial No. 62 / 141,853, filed on Apr. 2, 2015.
Background Art
[0002] Background Using wireless mesh networking to connect devices to each other and to cloud - based services is becoming increasingly popular for sensing environmental conditions, controlling devices, and providing information and alerts to users. However, many devices on the mesh network are designed to operate on battery power for long periods of time, which limits the available computing, user interface, and wireless resources in the device. In addition, to ensure the security of the mesh network, the identities of the devices that participate in and operate on the mesh network are authenticated, and communications within the mesh network are encrypted based on the credentials commissioned to the devices. However, as the pervasiveness and scale of the mesh network increase, the commissioning techniques limit the quality of the user experience for commissioning, the accuracy of joining the device to the correct mesh network during commissioning, securely injecting the credentials into the device, and provisioning device - and application - specific information to the device.
Summary of the Invention
Means for Solving the Problems
[0003] overview This overview is provided to introduce a simplified concept of mesh network commissioning. This simplified concept is further explained in the detailed description below. This overview is not intended to identify the essential characteristics of the claimed subject matter, nor is it intended to be used in defining the scope of the claimed subject matter.
[0004] Mesh network commissioning, which generally involves joining a node to a mesh network, is described. In embodiments, a joiner router may receive a beacon request from a participating device and then send a beacon from the joiner router to the participating device, the beacon providing an indication that the mesh network is available for joining. The transmitted beacon also allows the participating device to establish a local link between the participating device and the joiner router. The joiner router receives a message from a participating device requesting to join the mesh network. The message received from the participating device may include a device identifier that can be used to authenticate the participating device, and the participating device may also use Password Authenticated Key Exchange by Juggling (J-PAKE) or The authentication is performed using any other suitable cipher suite, and the authentication is effective in establishing a secure communication session between the commissioning device and the participating devices. The joiner router forwards the received message to the commissioning device of the mesh network, and it is transmitted along the communication path between the joiner router and the commissioning device. This may include forwarding received messages through one or more routers in the mesh network. In an implementation example, one of the routers may be a border router connecting the mesh network to an external network, and the commissioning device is attached to the external network. The joiner router then receives authentication from the commissioning device for the participating device to join the mesh network, and the joiner router sends network information to the participating device, which enables the participating device to join the mesh network.
[0005] Mesh network commissioning, which generally involves joining a node to a mesh network, is described. In an embodiment, a joiner router may receive a beacon request from a participating device and then send a beacon from the joiner router to the participating device, the beacon providing an indication that the mesh network is available for joining. The transmitted beacon also allows the participating device to establish a local link between the participating device and the joiner router. The joiner router relays a DTLS-ClientHello message from a participating device requesting to join the mesh network in a DTLS relay receive notification message, which is sent to the commissioning device of the mesh network. The joiner router receives a DTLS relay send notification message from the commissioning device and sends the contents of the DTLS relay send notification message to the participating device, the contents of which are useful for enabling the participating device to join the mesh network and for establishing a secure communication session between the commissioning device and the participating device. The joiner router receives an indication from the commissioning device that participating devices should be commissioned to receive network credentials for the mesh network, and receives a Key Encryption Key (KEK) shared between the commissioning device and the participating devices. The joiner router then encrypts the message at the Media Access Control (MAC) layer and uses the KEK to authenticate and securely communicate the network credentials, sending the network credentials and other essential network parameters from the joiner router to the participating devices. The secure communication session is then available for provisioning the participating devices.
[0006] Mesh network commissioning, in general terms, is described in relation to establishing a commissioning session. In an embodiment, a border router receives an application from a commissioning device to become a commissioner for devices participating in the mesh network. The border router advertises the availability of the mesh network for the commissioning device. In response to receiving the advertisement, the commissioner receives the application in response to the commissioning device receiving the advertisement. The border router transmits the received application to the leader device of the mesh network and receives a response from the leader device to the application, the response indicating acceptance or rejection of the application. The border router transmits the indication of acceptance or rejection of the application to the commissioning device. Acceptance of the application by the leader device authorizes the commissioning device to become a commissioner for the mesh network and a secure commissioning session is established. Accepting the application also allows the leader device to update its internal state, track active commissioners for the mesh network, enable participation across the entire mesh network, communicate with a set of devices authorized to join the mesh network, and propagate commissioning datasets within the mesh network.
[0007] In another aspect of mesh network commissioning, border routers also provide the border routers with enhanced (e.g., cryptographically hashed) commissioning credentials to establish a secure commissioning communication session. Including the registration of the commissioning device's identity, the enhanced commissioning credentials are derived from the commissioning credential passphrase entered by the user into the commissioning device. The border router contains an encrypted copy of the commissioning credentials that can be used to authenticate the commissioning device to the mesh network, and this encrypted copy of the commissioning credentials is previously derived from the commissioning credentials. The commissioning credentials are injected into the mesh network leader device that derived the encrypted copy of the commissioning credentials, and the leader device securely communicates the encrypted copy of the commissioning credentials to the border router.
[0008] Mesh network commissioning, in general terms, is described in relation to establishing a commissioning session. In an embodiment, a leader device of a mesh network receives an application to accept a commissioning device as a commissioner for commissioning participating devices to join the mesh network. The leader device can determine whether to accept or reject the received application and send a response to the commissioning device with an indication of whether the received application is accepted or rejected. The decision from the commissioning device regarding whether to accept or reject the received application may include ensuring that there is one active commissioner for the mesh network. In response to the decision to accept the received application, the leader device can update its internal state tracking the active commissioner for the mesh network.
[0009] In other aspects of mesh network commissioning, a leader device can receive commands from commissioning devices to initiate join mode for the mesh network and propagate commissioning datasets within the mesh network. Enhanced commissioning credentials can be derived from commissioning credentials injected into the leader device during commissioning. The leader device can send an encrypted copy of the commissioning credentials to the border router, enabling the border router to authenticate the commissioning device to the mesh network.
[0010] Mesh network commissioning, which generally involves managing multiple commissioning sessions, is described. In embodiments, a commissioning device establishes a secure commissioning communication session between the commissioning device and border routers in the mesh network to securely establish a network communication session for one or more participating devices to join the mesh network. The secure commissioning communication session is used by the commissioning device to send an application to the leader device of the mesh network to request acceptance of the commissioning device as an active commissioner for the mesh network, and to receive an indication of acceptance of the application from the leader device. The commissioning device can initiate join for the mesh network and receive requests from participating devices to join the mesh network. To initiate join for the mesh network, the commissioning device can initiate a join mode that causes routers in the mesh network to advertise that the mesh network is accepting join requests.
[0011] In another aspect of mesh network commissioning, the commissioning device can also send management messages to the leader device to enable the mesh network to join, and the management messages enable the leader device to use the mesh network. This enables updating of network data. Management messages may include steering data indicating participating devices that are permitted to join the mesh network. Network data is then propagated to router devices in the mesh network, and the network data includes an indication that the mesh network is available for joining. Participating devices establish a secure joiner communication session with the commissioning device. The commissioning device authenticates the participating devices using a Pre-Shared Key for the Device (PSKd) for the participating devices, and the participating devices A chair is added to a mesh network. A secure joiner communication session can be established by the commissioning device determining, from a copy of the device identifier received from the user as input to the commissioning device, that the encrypted device identifier received from the participating device matches the encrypted device identifier derived by the commissioning device, and by using the encrypted device identifier as a shared secret to secure the joiner communication session.
[0012] Requests from participating devices to join the mesh network are receivable via the joiner router, and the commissioning device sends an indication to the joiner router that the participating device should be commissioned to receive network credentials for the mesh network and a Key Encryption Key (KEK) shared between the commissioning device and the participating device. This transmission to the participating device via the joiner router is effective in enabling the joiner router to securely transmit network credentials to the participating device using the received KEK and commission the participating device to the mesh network. Requests received from participating devices may include the participating device's encrypted device identifier, which is derived from the participating device's device identifier using Juggling Password Authenticated Key Exchange (J-PAKE).
[0013] Mesh network commissioning, generally relating to provisioning participating devices, is described. In embodiments, a commissioning device can establish a commissioning communication session between the commissioning device and the border routers of the mesh network, and can also establish joiner communication sessions between participating devices and the commissioning device. The commissioning device then transmits commissioning information to the participating devices, which is available to the participating devices for joining the mesh network. The commissioning device receives an indication of the location of the commissioner application from the participating devices, uses the received indication to find the commissioner application, and runs the commissioner application to provision the participating devices.
[0014] Mesh network commissioning, generally relating to searching and steering, is described. In embodiments, a commissioning device for a mesh network may request steering data for the mesh network, which is an indication of a device identifier associated with a device authorized to join the mesh network. The commissioning device can then propagate the steering data from the commissioning device for the mesh network to one or more routers in the mesh network, which indicates that the commissioner is active on the mesh network. The propagation of the steering data by the commissioning device is useful in enabling one or more routers to send the steering data in a beacon message, which enables the device associated with the device identifier to identify that the device is authorized to join the mesh network. In the implementation example, the steering data is the device identifier, which is an IEEE 64-bit Extended Unique Identifier (EUI-64). This is a 16-bit Cyclic Redundancy Check (CRC16). The commissioning device can obtain steering data for the mesh network by obtaining steering data for additional device identifiers associated with additional devices that are permitted to join the mesh network. The commissioning device propagating steering data is useful in allowing devices to distinguish the mesh network from other networks, the other networks being IEEE 802.15.4 networks.
[0015] Mesh network commissioning relating to search and steering in general is described. In embodiments, a commissioning device for a mesh network may obtain steering data for the mesh network, which includes a representation of a device identifier associated with a device permitted to join the mesh network, and the representation is represented as a set of values in a Bloom filter that represents the device identifier. The commissioning device can then propagate the steering data from the commissioning device for the mesh network to one or more routers in the mesh network. Propagating the steering data allows the routers to send the steering data in beacon messages, and the steering data allows the device associated with the device identifier to identify that the device is permitted to join the mesh network by comparing a set of values in a Bloom filter with a second set of values obtained by the device.
[0016] In other aspects of mesh network commissioning, the commissioning device obtains steering data by applying a first hash function to the device identifier to generate a first hash value, and a second hash function to the device identifier to generate a second hash value. The device identifier may be an IEEE 64-bit Extended Unique Identifier (EUI-64), which is the least significant 24 bits of the EUI-64. In the implementation example, the first and second hash functions are cyclic redundancy checks (CRCs), with the first hash function being CRC16-CCITT and the second hash function being CRC16-ANSI. The commissioning device then performs a modulo operation on the first hash value to determine the first bit field position in the Bloom filter, and a modulo operation on the second hash value to determine the second bit field position in the Bloom filter. The divisor for the modulo operation may be the length of the bit array of the Bloom filter. The commissioning device can set the value at the first bit field position of the Bloom filter to 1, and the value at the second bit field position of the Bloom filter to 1. The commissioning device can set all bit field values in the steering data to 1 to indicate that the mesh network is available for any device to join. Alternatively, the commissioning device can set the bit field values in the steering data to 0 to prevent the device from joining the mesh network.
[0017] Mesh network commissioning, which generally relates to dividing nodes in a mesh network, is described. In an embodiment, a node device in the mesh network receives a commissioning dataset and compares the timestamp in the received commissioning dataset with the stored timestamp in the commissioning dataset stored in the node. From the comparison, the node device determines that the stored timestamp is more recent than the received timestamp and can accordingly send a message to the mesh network's leader device, the message containing the stored commissioning dataset. The leader device accepts the stored commissioning dataset as the most recent commissioning dataset for the mesh network and the stored commissioning dataset This is propagated through the mesh network. Alternatively, a node device can determine that the received timestamp is more recent than the stored timestamp, and in response to this determination, update the stored commissioning dataset to match the received commissioning dataset.
[0018] In other aspects of mesh network commissioning, the received commissioning dataset includes the received timestamp, commissioning credentials, the network name of the mesh network, and security policies indicating which security-related actions are permitted in the mesh network. The received timestamp includes a time value and an indication that the time value is traceable to Coordinated Universal Time (UTC). In the implementation example, the node and leader devices were previously commissioned to the mesh network, and the previous commissioning stored the same commissioning dataset in the node and leader devices. The stored commissioning dataset in the node device may be updated after a split in the mesh network that stops communication between the node and leader devices on the mesh network. The split separates the mesh network, with a first partition containing the leader devices and a second partition containing the node devices. Node devices can receive commissioning datasets after the merger of the first and second sections of the mesh network, and the merger re-establishes the communication path between node devices and leader devices on the mesh network.
[0019] Brief explanation of the drawing An embodiment of mesh network commissioning will be described with reference to the following drawings. The same numbers will be used throughout the drawings to refer to similar features and components. [Brief explanation of the drawing]
[0020] [Figure 1] This figure shows an exemplary mesh network system in which various embodiments of mesh network commissioning can be realized. [Figure 2] This figure shows an exemplary environment in which various embodiments of mesh network commissioning can be realized. [Figure 3A] A diagram showing a simplified version of an exemplary mesh network environment having devices implemented according to an embodiment of mesh network commissioning. [Figure 3B] A diagram showing a simplified version of an exemplary mesh network environment having devices implemented according to an embodiment of mesh network commissioning. [Figure 3C] A diagram showing a simplified version of an exemplary mesh network environment having devices implemented according to an embodiment of mesh network commissioning. [Figure 3D] A diagram showing a simplified version of an exemplary mesh network environment having devices implemented according to an embodiment of mesh network commissioning. [Figure 4] A diagram showing an example of data transactions between devices in a mesh network environment according to an embodiment of mesh network commissioning. [Figure 5] A diagram showing an example of a commissioning environment having an established commissioner session and an established joiner session according to an embodiment of mesh network commissioning. [Figure 6] A diagram showing an example of data transactions between devices in a mesh network environment for establishing a commissioner session according to an embodiment of mesh network commissioning. [Figure 7] A diagram showing an example of data transactions between devices in a mesh network environment for establishing a joiner session according to an embodiment of mesh network commissioning. [Figure 8] A diagram showing an example of steering data generated using a Bloom filter to encode device identifiers for participating devices according to an embodiment of mesh network commissioning. [Figure 9] A diagram showing an example of partitioning a mesh network according to an embodiment of mesh network commissioning. [Figure 10] This figure shows an exemplary method of mesh network commissioning, generally relating to joining nodes to a mesh network, following embodiments of the techniques described herein. [Figure 11] This figure shows another exemplary method of mesh network commissioning, generally relating to joining nodes to a mesh network, following an embodiment of the technique described herein. [Figure 12] This figure shows an exemplary method of mesh network commissioning, generally relating to establishing a commissioning session in a mesh network, following an embodiment of the method described herein. [Figure 13] This figure shows another exemplary method of mesh network commissioning, generally relating to establishing a commissioning session in a mesh network, following an embodiment of the method described herein. [Figure 14] This figure shows an exemplary method of mesh network commissioning, generally relating to managing multiple commissioning sessions in a mesh network, according to embodiments of the techniques described herein. [Figure 15] This figure shows an exemplary method of mesh network commissioning, generally relating to provisioning participating devices in a mesh network, according to embodiments of the techniques described herein. [Figure 16] This figure shows an exemplary method of mesh network commissioning, generally relating to searching and steering in a mesh network, according to embodiments of the techniques described herein. [Figure 17] This figure shows another exemplary method of mesh network commissioning, generally relating to searching and steering in a mesh network, according to embodiments of the techniques described herein. [Figure 18]This figure shows an exemplary method of mesh network commissioning, generally relating to the division of nodes in a mesh network, according to embodiments of the techniques described herein. [Figure 19] This figure shows an exemplary environment in which a mesh network can be realized according to an embodiment of the method described herein. [Figure 20] This figure shows an exemplary mesh network device that can be implemented in a mesh network environment according to an embodiment of the method described herein. [Figure 21] This figure shows an exemplary system having exemplary devices capable of realizing an embodiment of mesh network commissioning. [Modes for carrying out the invention]
[0021] Detailed explanation A wireless mesh network is a communications network that has wireless nodes connected in a mesh topology, providing reliable and redundant communication paths for traffic within the mesh network. A wireless mesh network uses multiple wireless links, or hops, to forward traffic between devices within the mesh network. This provides coverage over a larger area than that covered by a single wireless link.
[0022] Wireless mesh networks can be based on proprietary technology or standards-based technology. For example, wireless mesh networks are based on the IEEE 802.15.4 standard. It may also define the features and services of the Physical (PHY) layer and Media Access Control (MAC) layer for use by applications in the upper layers of a mesh networking stack. Upper-layer applications use the services defined by these standards to achieve application-level secure communication (e.g., encryption and authentication) across the mesh network.
[0023] While standards-based technologies for mesh networks provide services for secure communication, these technologies do not offer a complete solution for secure commissioning of mesh networks. Standards-based solutions may assume that devices are commissioned out of band within the secure mesh network and left to be designed by application developers. For example, an out-of-band commissioning solution might involve injecting network credentials through a wired connection before participating devices attempt a wireless-based connection to the mesh network. Alternatively, once the mesh network is established, network credentials are transmitted over an insecure wireless link.
[0024] Securely commissioning participating devices through a mesh network eliminates the need for specialized commissioning tools, additional interfaces on participating devices for credential injection, and the risk of transmitting credentials over insecure communication links. Various embodiments provide mesh network commissioning techniques to improve the commissioning of devices participating in a mesh network.
[0025] Authentication methods used in internet-connected networks may rely on the use of certificates issued by certificate authorities. These certificates can be validated to authenticate the identity of other devices on the network. Unlike devices on the internet, devices in a mesh network do not need to access internet-connected, certificate-based authentication to authenticate themselves for commissioning. A mesh network commissioning method is described that provides secure authentication of commissioning and participating devices to a mesh network without requiring an external certificate authority.
[0026] Standards for mesh networks provide services to secure communication within the mesh network, such as defining network keys (network master keys) and MAC layer encryption methods for communication between devices in the mesh network. However, inserting credentials such as network keys into devices participating in the mesh network is outside the scope of the PHY and MAC services defined by the standards. Out-of-band techniques are often used to load credentials into participating devices before they attempt to connect to the mesh network. Mesh network commissioning techniques, which securely communicate network credentials to participating devices through the mesh network during commissioning, are described.
[0027] Many devices designed for mesh networks have limited or no user interface capabilities. Because of these limited user interfaces on mesh network devices, entering information such as passphrases, device identifiers, and / or device addresses for participating devices becomes cumbersome and error-prone for users. A mesh network commissioning technique is described that improves user efficiency and data entry accuracy during the commissioning of devices participating in a mesh network.
[0028] As systems using mesh networking become increasingly ubiquitous, it may be necessary to add many participating devices during mesh network commissioning. The limited resources and user interfaces of many mesh network devices result in long and costly commissioning, especially when a large number of participating devices must be commissioned or recommissioned. Mesh network commissioning techniques that improve the scalability of commissioning participating devices into a mesh network are described.
[0029] Wireless mesh networks may use licensed or unlicensed (also known as license-exempt or license-free) radio spectrum. Standards such as IEEE 802.15.4 specify the use of unlicensed radio spectrum, including channel frequency, channel bandwidth, data rate, modulation, and access methods, enabling multiple mesh networks to operate within the unlicensed spectrum band. Mesh network commissioning techniques are described to ensure that participating devices are securely assigned to the correct mesh network in an environment where multiple mesh networks share the same radio spectrum and / or basic industry-standard networking protocols.
[0030] In addition to inserting network credentials into participating devices during commissioning, additional provisioning may be required for participating devices to update or configure them for use in a mesh network. This provisioning may require secure communication of information, such as linking participating devices to user accounts for cloud services. A mesh network commissioning technique for securely provisioning participating devices during commissioning is described.
[0031] The features and concepts of the described systems and methods for mesh network commissioning can be realized in any number of different environments, systems, devices, and / or various configurations, but embodiments of mesh network commissioning are described in the context of the following exemplary devices, systems, and configurations.
[0032] Figure 1 shows an exemplary mesh network system 100 in which various embodiments of mesh network commissioning can be realized. The mesh network 100 is a wireless mesh network including a router 102, a router-eligible end device 104, and an end device 106. Router 102, router-eligible end device 104, and end device 106 each include a mesh network interface for communication through the mesh network. Router 102 sends and receives packet data through the mesh network interface. Router 102 also routes traffic throughout the mesh network 100. Router 102 and router-eligible end device 104 can assume various roles and combinations of roles for commissioning within the mesh network 100, as described below.
[0033] Router-eligible end device 104 is located at a leaf node in the mesh network topology and does not actively route traffic to other nodes in the mesh network 100. When router-eligible device 104 is connected to an additional device, router-eligible device 104 can become router 102. End device 106 is a device that can communicate using the mesh network 100 but does not have the ability to route traffic beyond simply forwarding it to its parent router 102 in the mesh network 100.
[0034] Router 102, router-eligible end device 104, and end device 106 include network credentials used to authenticate their identity as members of the mesh network 100. Router 102, router-eligible end device 104, and end device 106 also use network credentials to encrypt communications within the mesh network.
[0035] Figure 2 shows an exemplary environment 200 in which various embodiments of a mesh networking commissioning method can be implemented. Environment 200 includes a mesh network 100 in which several routers 102 perform specific roles within the mesh network 100. Devices within the mesh network 100, as indicated by dashed lines, communicate securely through the mesh network 100 using network credentials. Devices shown outside the mesh network 100 do not have a copy of the network credentials for the mesh network 100 and cannot use mesh network layer security to communicate securely.
[0036] A border router 202 (also known as a gateway and / or edge router) is one of the routers 102. The border router 202 includes a second interface for communication with an external network outside of the mesh network 100. The border router 202 connects to an access point 204 through the external network. For example, the access point 204 may be an Ethernet® router, a Wi-Fi® access point, or any other suitable device for bridging different types of networks. The access point 204 connects to a communication network 206, such as the Internet. A cloud service 208 connected via the communication network 206 provides services related to devices within the mesh network 100 and / or services that use those devices. For example, but not limited to, the cloud service 208 provides applications that include connecting end-user devices such as smartphones and tablets to devices in the mesh network 100, processing and presenting data obtained in the mesh network 100 to end users, linking one or more devices in the mesh network 100 to a user account in the cloud service 208, provisioning and updating devices in the mesh network 100, and so on.
[0037] A user who chooses to commission a new device to join the mesh network 100 can use a commissioning device 210, which connects to the border router 202 via the external network technology of the access point 204 in order to commission the new device. The commissioning device 210 may be any computing device such as a smartphone, tablet, or notebook computer, having a suitable user interface and communication capabilities to act as a commissioner for joining devices to the mesh network 100. To become a commissioner for the mesh network 100, the commissioning device 210 applies to become a commissioner, as described in detail below.
[0038] The participating device 212 is any router-eligible end device 104 or end device 106 that the user has chosen to join the mesh network 100. Before commissioning, the participating device 212 has not received network credentials for the mesh network 100 and cannot be authenticated to the mesh network 100 or communicate securely through the mesh network 100. During commissioning, the participating device 212 acts as a joiner (i.e., a participating device), as described in detail below.
[0039] During the commissioning of participating devices 212 to join the mesh network 100, one of the routers 102 acts as a joiner router 214. The role of joiner router 214 can be performed by any router 102 on one of the participating devices 212's wireless links. The joiner router 214 provides the participating devices 212 with a local-only wireless link for the joiner session, as described in detail below.
[0040] One of the routers 102 acts as the leader 216 for the mesh network 100. The leader 216 manages router identifier assignment and is the primary arbiter of network configuration information for the mesh network 100. The leader 216 also controls, at any given time, which commissioning device 210 is accepted as the sole active commissioner for the mesh network 100.
[0041] Environment 200, as shown in Figure 2, illustrates that the device performs only one of the various roles described above. Figures 3A–3D, shown and described below, illustrate other distributions of commissioning roles for mesh network commissioning techniques, not as an extension but as examples.
[0042] Figure 3A shows a simplified version of exemplary environment 200 300, with only devices having a specific role in commissioning shown for clarity. In this example, each device in Figure 3A performs a single commissioning role in an embodiment of mesh network commissioning. Figure 3A also shows the communication links used during the commissioning process. A secure mesh communication link 302 is used between devices participating in the mesh network 100. To commission participating device 212 to the mesh network 100, an insecure local-only wireless link 304 is established to connect participating device 212 to joiner router 214. The external network 306 has communication links on the external network, such as the illustrated point-to-point link 308 between border router 202 and commissioning device 210.
[0043] Figure 3B also shows a simplified version 320 of the exemplary environment 200, showing a border / joiner router 322 which is a border router 202 that additionally performs the role of a joiner router 214. Figure 3C also shows a simplified version 340 of the exemplary environment 200, showing a commissioner / border router 342 which is a border router 202 that additionally performs the role of a commissioning device 210. In this example, the commissioner / border router 342 includes a mesh network interface. The commissioner / border router 342 may also be called an on-mesh commissioner because the commissioner / border router 342 is connected to the mesh network 100.
[0044] Figure 3D also shows a simplified version of the exemplary environment 200, 360, and depicts a commissioner / border router / joiner router 362, which is a border router 202 that additionally performs the roles of joiner router 214 and commissioning device 210. Figures 3A-3D show examples of possible combinations of mesh network commissioning roles, in which any router-eligible end device 104 can perform multiple roles (except for the role of participating device 212).
[0045] Figure 4 illustrates the commissioning process 400 by showing transactions between devices in the mesh network 100, which perform various mesh network commissioning roles. Commissioning devices 210, for example, mobile phones The commissioning process 400 begins when the communication, via advertisement 402 from border router 202, discovers that mesh network 100 is available for the commissioner. The commissioning device 210 then uses the Pre-Shared Key for the Commissioner (PSKc) to communicate with border router 202 and A secure socket connection is established. This secure connection establishes a commissioning session (404). Since there can only be one active commissioner at a time, commissioning device 210 submits an application to border router 202 (406), which is then forwarded by border router 202 to leader 216 as an application (408), thereby applying to leader 216 to become the active commissioning device 210 for mesh network 100.
[0046] When leader 216 accepts commissioning device 210 as an active commissioner, leader sends request response 410 to border router 202, which then forwards request response 412 to commissioning device. Leader 216 also indicates to devices on mesh network 100 that an active commissioner is present by propagating updated network data (414) through mesh network 100.
[0047] Once activated as a commissioner, the commissioning device 210 enables participation for the mesh network 100. Optionally, the commissioning device 210 provides steering data indicating the device identifiers of participating devices 212 that are expected to join the mesh network 100. The commissioning device 210 may also query and set network parameters such as the network name and security configuration.
[0048] The participating device 212 sends a request to the joiner router 214 to establish a joiner session (416), which then relays the request from the participating device 212 to the border router 202 (418). Note that the relay request 418 may be forwarded between the joiner router 214 and the border router 202 by any number of routers 102 in the mesh network. The border router 202 forwards the request to establish a joiner session to the commissioning device 210 (420). The commissioning device 210 sends a response to the request for a joiner session to the border router 202 (422), which then relays the response to the joiner router 214 (424). At 426, the joiner router 214 completes the establishment of the joiner session. The establishment of the joiner session in Figure 4 is shown in a simplified form for clarity, and additional relayed DTLS messages may be exchanged as part of the DTLS handshake to establish the joiner session.
[0049] As shown in sections 416-426, the participating device 212 and the commissioning device 210 use Datagram Transport Layer Security (DTLS) with a device pre-shared key (PSKd) for the participating device 212. Alternatively, a handshake is performed using Transport Layer Security (TLS). The handshake is performed over the mesh network 100, as described in detail below. The commissioning device 210 derives the PSKd from the participating device credentials received out of band on the mesh network 100, typically entered through the commissioning device 210's user interface, such as by scanning a QR code (registered trademark) or barcode. Once the handshake is complete, the shared secret generated from the PSKd is used to establish a joiner session and pass network credentials for the mesh network 100 from the joiner router 214 to the participating device 212. Optionally, in addition to passing network credentials for mesh network 100, commissioner and joiner sessions may be used to provision joiners, as shown in 428.
[0050] Figure 5 shows a commissioning environment 500 with established commissioner sessions and established joiner sessions. Commissioner session 502 is a secure communication tunnel from commissioning device 210 to border router 202. Joiner session 504 is a secure communication tunnel from commissioning device 210 to participating device 212. For clarity, other mesh communication links and external network communication links are omitted.
[0051] First device pairing To allow a device to join the mesh network 100, the first device is commissioned to establish commissioning credentials for the commissioning device to join the mesh network 100 and network credentials for the secure operation of the mesh network 100. The commissioning device 210 connects to the first device, which may be any router-eligible end device 104. The first device is commissioned out of band on the mesh network 100. To connect the first device to the commissioning device 210, USB, ad-hoc Wi-Fi, Bluetooth®, point-to-point IEEE 802.15 Any suitable connection such as .4 may be used.
[0052] Once the commissioning device 210 connects to the first device, the commissioning device programs the PSKc and network name for the mesh network 100 into the first device. The PSKc is used to authenticate the commissioning device 210 to the mesh network 100 and establish a commissioning session, as described in detail below. The network name is human-readable, similar to the Service Set Identifier (SSID) in a Wi-Fi network. Once the first device is commissioned, it becomes the leader 216 of the mesh network 100. The first device forms the mesh network 100 and determines a unique Personal Area Network Identifier (PAN ID) and a unique Extended PAN ID (XPANID) for the mesh network 100, as well as a network key for the mesh network 100.
[0053] The PSKc is derived from the commissioning credentials, which is a human-scale passphrase entered into the commissioning device 210 by the user managing the mesh network 100. The commissioning credentials are strengthened (for example, by cryptographically hashing multiple times) to derive the PSKc stored by the reader 216 and the commissioning device 210. Any suitable cryptographic hashing method may be used to derive the PSKc.
[0054] To enhance the security of PSKc, cryptographic techniques may be applied to increase the entropy of the commissioning credentials in the derived PSKc compared to an equivalent human-scale commissioning credential passphrase entered by the user. By using key stretching, the derived key can be securely stored on an embedded node that may be physically compromised, while the user's passphrase remains uncompromised. This is useful because users often reuse passphrases for multiple websites and accounts. Any preferred cryptographic technique, such as applying a cryptographic hash multiple times, can be used to stretch the key. For example, to apply the Advanced Encryption Standard-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128), a password-based key derivation function 2 (PBKD) is used. F2) can be used. For example, PSKc can be derived as shown in Equation 1:
[0055]
number
[0056] In the formula, PRF is a kind of pseudorandom function to be used by PBKDF2, P is the commissioning credentials, S is the salt for the cryptographic function (e.g., a string such as the network name and the network type concatenated together), c is the number of iterations of the PRF, and dkLen is the desired length of the derived key (PSKc).
[0057] Establishment of Commissioning Sessions Figure 6 illustrates the process 600 for establishing a commissioner session by showing the transactions between the commissioning device 210, the border router 202, and the leader 216. The mesh network 100 may have a limited number of active commissioning devices 210, but there may be multiple potential commissioning devices 210 that can act as commissioners. The leader 216 is responsible for ensuring that there is only one finite set of active commissioners for the mesh network 100. As an example, rather than an limitation, the finite set of active commissioners may be limited to a single active commissioner. In order to become an active commissioner, the commissioning device 210 applies to the leader 216 to become a commissioner for the mesh network.
[0058] In 602, the border router 202 advertises on its external network interface that the mesh network 100 is available for the commissioning device 210. The border router 202 may also make an advertisement in response to a multicast request (i.e., a scan or query) within the Service Discovery Protocol. For example, advertisement 602 may be for Multicast Domain Name Service (mDNS). This may be done using any suitable service discovery method, such as ). Specifically, for a wireless network, the border router 202 advertises the commissioning service using DNS service discovery (DNS-SD) via a Uniform Resource Locator (URL). The lookup server will then respond with the network names of all accessible different wireless networks, mesh network 100, and commissioning ports.
[0059] The commissioning device 210 responds to the advertisement from the border router 202 by requesting a secure connection for a commissioning session between the commissioning device 210 and the border router 202 (604). The commissioning session may be established in any preferred manner, for example, by using DTLS or TLS and PSKc to establish the commissioning session. As an example, but not limited to, the commissioning device 210 and the border router 202 exchange DTLS messages 606-616 to identify the commissioning device and authenticate it to the mesh network 100, and to establish a secure connection for the commissioner session.
[0060] A commissioning session may use any suitable network port, such as a User Datagram Protocol (UDP) port or a Transmission Control Protocol (TCP) port, as both the source and destination ports of the commissioning session. For example, a commissioning session may use a commissioning port discovered during network discovery. Each border router 202 may assign a commissioning port or use a default commissioning port.
[0061] To become the active commissioner for mesh network 100, commissioning device 210 applies to leader 216 to request to become a commissioner (618). Using the commissioning session, commissioning device 210 sends an application to border router 202 to become the active commissioner for mesh network 100 (620). Border router 202 forwards the application to leader 216 (622). For example, after commissioning device 210 has been authenticated and identified, border router 202 unicasts commissioner application request message 620 (e.g., COMM_PET.req) to leader 216. The commissioner application request is forwarded by the border router 202 to the leader 216 as request 622 (for example, as LEAD_PET.req) requesting that the commissioning device 210 be accepted as the active commissioning device 210 for the mesh network 100. For example, the commissioner application request message, including the commissioner identification string, is securely transmitted through the mesh network 100.
[0062] The leader 216 determines whether an active commissioner exists for the mesh network 100. If an active commissioner exists, the leader rejects the application from the commissioning device 210. If there is no active commissioner for the mesh network 100, the leader 216 accepts the application from the commissioning device 210. The leader 216 updates its copy of the commissioning dataset to reflect the existence of an active commissioner and the identity of the commissioning device 210. The leader 216 sets the join permission flag for the mesh network 100 to true. The leader 216 then propagates the network data and the updated commissioning dataset to the mesh network 100 (624), indicating that the mesh network 100 is available to join.
[0063] For example, leader 216 will respond to the commissioner application request message by accepting or rejecting commissioning device 210 as an active commissioner for mesh network 100. If accepting, leader 216 will update its copy of network data with the new commissioner information, set the join permission flag to true, and also enable any multicast protocol for low-power and lossy networks (MPL). The updated network data and commissioning datasets will be propagated through the mesh network 100 using a suitable protocol or by multicasting MLE-UPDATE messages.
[0064] The potential joiner router 214 (i.e., router 102 and router-eligible end device 104) stores the updated network information and commissioning dataset propagated by leader 216. The updated network information and commissioning dataset enables direct communication with commissioning device 210 for use when commissioning any participating device 212. The `ng` dataset includes a Border Router Locator (RLOC) that allows any device to send messages to the currently active Border Router 202, which is acting as a proxy for the active commissioner.
[0065] After determining whether to accept or reject the application from commissioning device 210, leader 216 responds to border router 202 with an indication of that decision (626). Border router 202 sends a response from leader 216 to commissioning device 210, including an indication of the decision to accept or reject the application (628). For example, leader 216 sends a leader application response message (e.g., LEAD_PET.rsp) to border router 202 indicating leader 216's decision on whether to accept or reject commissioning device 210 as an active commissioner for mesh network 100. In response to receiving a leader request response message from leader 216, border router 202 will send a commissioner request response message (e.g., COMM_PET.rsp) to commissioning device 210 indicating leader 216's decision on whether to accept or reject commissioning device 210 as an active commissioner for mesh network 100.
[0066] Alternatively, as shown in 630, after accepting the commissioning device 210's application to become an active commissioner, the leader 216 sets the join permission flag to true, but waits to receive an administrative data request setting message 632 (e.g., MGMT_SET.req) from the commissioning device 210, which includes an indication that the leader 216 is authorized to propagate the updated network data to the mesh network 100. The leader 216 responds to the commissioning device with an administrative data response setting message 634 (e.g., MGMT_SET.rsp) acknowledging receipt of the request to propagate the updated network data. The leader 216 propagates the network data and the updated commissioning dataset to the mesh network 100 (636), which indicates that the mesh network 100 is available to join.
[0067] Before commissioning device 210 sends a management data request setting message to allow leader 216 to propagate updated network information, commissioning device 210 may manage the mesh network 100, such as configuring devices or changing network settings, without making the mesh network 100 joinable. The commissioning dataset includes a commissioner session identifier, a commissioning dataset timestamp, and a PSKc. If commissioning device 210 is the active commissioner on the mesh network 100, the commissioning dataset also includes the location of the border router 202. If the mesh network 100 is joinable, the commissioning dataset also includes steering data indicating which join devices 212 are allowed to join the mesh network 100. If the mesh network 100 is joinable, router 102 in the mesh network 100 includes a join permission flag and steering data in the beacon transmitted by router 102.
[0068] The commissioning device 210 enables the commissioning device 210 to operate as a native commissioner on the mesh network 100. It may include a mesh network interface. If a unique commissioner bit is set in the beacon and the commissioning device 210 includes a mesh network interface, the commissioning device 210 may apply to the leader 216 to become the active commissioner for the mesh network 100.
[0069] Once accepted as an active commissioner, the commissioning device 210 may manage the network using management data request / set and management data response / get messages to retrieve and set the network parameters of the mesh network 100. Network parameters include the PSKc for the mesh network 100, network name, network key, network key sequence number, network PAN ID, network extended PAN ID, network unique local address (ULA), and / or radio channel. Additional management capabilities are possible, such as the ability to expel previously joined devices from the mesh network 100. Management data request / set and management data response / get messages are relayed to the leader 216 via the border router 202 through the commissioning session. Because messages for retrieving and setting network parameter commands affect the state of the entire global network, the messages are forwarded to and stored by the leader 216. Any device can directly address the leader 216 with requests to retrieve network information, thus avoiding multi-hop addressing.
[0070] Establishment of the Joiner Session To securely commission a new device to the mesh network 100, a joiner session is established between the commissioning device 210 and the participating device 212. The joiner session is a communication tunnel between the commissioning device 210 and the participating device 212 through the mesh network 100. The participating device credentials are a human-scale passphrase used to authenticate that the participating device 212 is eligible to join the mesh network 100. The participating device credentials are communicated between the participating device 212 and the commissioning device 210 by any preferred out-of-band mechanism. For example, the participating device credentials may be communicated by scanning a QR code or barcode located on the participating device 212 with a camera included in the commissioning device 210, or by entering the serial number of the participating device 212 into the user interface of the commissioning device 210.
[0071] Figure 7 illustrates the process 700 for establishing a joiner session by showing the transactions between the commissioning device 210, the border router 202, the joiner router 214, and the participating device 212. In some embodiments, the establishment of a joiner session begins when the participating device 212 scans for radio channels, such as channels defined in the IEEE 802.15.4 specification, to find potential mesh networks 100 to join. The participating device 212 issues a beacon request (702) to each mesh network 100 found during the channel scan, to which all mesh networks 100 will respond.
[0072] For example, participating device 212 performs an active scan by sending 802.15.4MAC-BEACON. requests on all channels. In response to receiving a beacon request, joiner router 214 sends a beacon response containing steering data to help participating device 212 discover the correct mesh network 100 to join (704). Joiner router 214 sends an 802.15.4MAC-BEACON. response with steering data in the payload of the 802.15.4MAC-BEACON. response. Details on generating, sending, and using steering data are described in more detail below. Once participating device 212 has found the mesh network 100 to join, participating device 212 sends a local-only radio, which is an insecure point-to-point communication link, to joiner router 214. Establish a link.
[0073] For example, participating device 212 establishes a local-only radio link to joiner router 214 by configuring MAC layer network parameters (e.g., channel, PAN ID, etc.) collected from beacons received from a channel scan (706). To establish a local-only radio link, participating device 212 sends packets to a joiner port (e.g., a UDP port) (e.g., port number 5684 ":coaps") on an insecure interface of joiner router 214. The joiner port is also communicated in beacons. If no joiner port is found, a default port is used by participating device 212.
[0074] The participating device 212 sends a request to join the mesh network 100 to the joiner router 214. Upon receiving the request to join the mesh network 100, the joiner router 214 sends a request to the commissioning device 210 for authorization to join. The joiner router 214 forwards all traffic sent by the participating device 212 on the insecure joiner port. The joiner router 214 does not process or understand the contents of the DTLS handshake as understood by the commissioning device 210. In some embodiments, the joiner router 214 may store in its memory the location of the commissioning device 210, or the location of a border router 202 which is a proxy for the commissioning device 210, and may look up the location of the commissioning device 210 from another device (e.g., leader 216, or border router 202), or some other location (e.g., remote service). The PSKd is used to authenticate the participating device 212 to the mesh network 100 and to secure the joiner session between the commissioning device 210 and the participating device 212. The PSKd is derived from the participating device credentials.
[0075] In some embodiments, the joiner session may be established using DTLS, as well as authentication protocols such as Juggling Password Authenticated Key Exchange (J-PAKE), Secure Remote Password (SRP) protocol, and / or any other suitable password authenticated key exchange protocol. For example, an elliptic curve variation of J-PAKE using the NIST P-256 elliptic curve (EC-JPAKE) may be used for authentication and key matching. Using J-PAKE with PSKd proves that the user commissioning the joiner device 212 physically owns the joiner device 212 and that the commissioning device 210 connects to the correct joiner device 212 through the joiner session.
[0076] The joiner router 214 forwards the request to join the mesh network 100, received from the participating device 212 through the joiner session, to the commissioning device 210. Once the commissioning device 210 authenticates the request to join the mesh network 100, the network key is securely forwarded to the participating device 212 using the joiner session.
[0077] For example, participating device 212 may send a joiner identification message to joiner router 214 to provide a human-readable name for participating device 212. Joiner router 214 encapsulates the information in the joiner identification message within a relay message and forwards the relay message to border router 202 using a commissioner prefix, anycast address, or border router locator. Upon receiving the relay message, border router 202 reads the source address (in this case) The address of joiner router 214 is attached to the list of the next relay addresses at the end of the relay message, and the relay message is forwarded through the joiner session.
[0078] For example, participating device 212 sends a handshake message to joiner router 214 using DTLS and UDP (708). Joiner router 214 relays the DTLS handshake message to border router 202 for delivery to commissioning device 210 (710). Joiner router 214 does not know the content of the relayed DTLS handshake message. Joiner router 214 filters incoming DTLS handshake messages received from participating device 212 over an insecure local-only wireless link based on the matching joiner UDP port described above. Joiner router 214 relays all messages received on the identified joiner UDP port. Joiner router 214 prevents denial-of-service (DOS) attacks against the mesh network 100. Therefore, the transfer of insecure messages may be limited in speed.
[0079] As a further example, participating device 212 first identifies itself to commissioning device 210 by sending a DTLS-ClientHello message to joiner router 214. This initial DTLS-ClientHello is intended to allow commissioning device 210 to assign participating device 212 a DTLS cookie for use during the remainder of the commissioning exchange. Joiner router 214 encapsulates the DTLS-ClientHello UDP payload within a DTLS relay reception notification message (e.g., RLY_RX.ntf) and adds the source address of the encapsulated packet, in this case the 64-bit link-local address of participating device 212, as the relay hop. The DTLS cookie is sent to participating device 212, which then sends it back to commissioning device 210 to assure participating device 212 that it is authentic.
[0080] The joiner router 214 also adds its address as a relay point to the DTLS relay reception notification message. The joiner router 214 sends the DTLS relay reception notification message to the border router 202. When the border router 202 receives the DTLS relay reception notification message, it forwards the DTLS relay reception notification message to the commissioning device 210 through the commissioning session (712).
[0081] Based on the joiner identification message received from participating device 212, commissioning device 210 uses the joiner identification message to initiate a DTLS-HelloVerify message based on PSKd. At 714, the DTLS-HelloVerify message and a DTLS relay transmission notification message (e.g., RLY_TX.ntf) are sent to border router 202. At 716, border router 202 relays the DTLS-HelloVerify message and the DTLS relay transmission notification message to joiner router 214. At 718, joiner router 214 sends the DTLS-HelloVerify message to participating device 212.
[0082] Alternatively, the commissioning device 210 may have information about multiple participating devices 212 to be commissioned. When the commissioning device 210 receives a DTLS-ClientHello message from a specific one of the multiple participating devices 212, it looks up the IEEE 64-bit Extended Unique Identifier (EUI-64) address of the participating device 212 that sent the DTLS-ClientHello message. The commissioning device 210 looks up the PSKd in the information about multiple participating devices 212 to be commissioned in order to continue the DTLS handshake for the specific participating device 212. The commissioning device 210 then The DTLS-ServerHello, DTLS-ServerKeyEx, and DTLS-ServerHelloDone messages are relayed back to the participating device 212 via the joiner router 214. Once this DTLS handshake is complete, the joiner session is established.
[0083] Once the commissioning device 210 authenticates the participating device 212, the commissioning device 210 delegates the network credentials for the mesh network 100 to the participating device 212. For example, the commissioning device 210 requests the network credentials from the border router 202 and sends the network credentials to the participating device 212 in a joiner delegation message transmitted through the joiner session via a DTLS relay transmission notification message through the commissioning session. Alternatively, the commissioning device 210 uses a Key Exchange key as a shared secret between the commissioning device 210 and the participating device 212. The network credentials for mesh network 100 are delegated to participating device 212 using Key:KEK. KEK is sent to joiner router 214 for participating device 212 and used to encrypt the network credentials for transmission over a local-only wireless link.
[0084] Provisioning of participating devices When participating device 212 joins the mesh network 100, participating device 212 may also require provisioning. Provisioning may include updating the firmware on participating device 212, configuring participating device 212, providing local configurations related to other devices on the mesh network 100, linking participating device 212 to a user account on the cloud service 208, linking participating device 212 to a cloud-based application server, etc. Although still established, commissioner and joiner sessions are used to provide a secure connection for provisioning participating device 212 before it uses network credentials to join the mesh network 100.
[0085] The participating device 212 transmits a location representation of the commissioner application to be executed by the commissioning device 210 in order to provision the participating device 212. The location representation may be used by the commissioning device 210 to find the commissioner application in its memory, or it may be used by the commissioning device 210 to retrieve the commissioner application from the cloud service 208. The representation may be in any preferred form, such as a uniform resource locator (URL). Once the provisioning of the participating device 212 is complete, the participating device 212 terminates the joiner session and the local-only wireless link. The participating device 212 uses network credentials to join the mesh network 100.
[0086] Steering data Wireless mesh networks may share the same radio spectrum. Standards such as IEEE 802.15.4 specify multiple channels, which allows multiple networks to operate within the same band of radio spectrum. In addition, if there are many devices to be commissioned to mesh network 100, it is desirable to efficiently communicate multiple device identifiers for many participating devices 212 using steering data in beacons to help participating devices 212 find the correct mesh network 100 to join. In an environment where multiple mesh networks share the same radio spectrum and / or basic industry standard networking protocols, A mesh network commissioning method is described for securely joining multiple participating devices 212 into the correct mesh network 100.
[0087] Once the commissioning device 210 obtains the PSKd and EUI-64MAC addresses for the desired participating device 212, the commissioning device 210 constructs steering data that will signal to the desired participating device 212 which mesh network 100 it should join. The steering data will include some way of distinguishing the mesh network 100 from other 802.15.4-based networks, a way of communicating whether there is an active commissioner on the mesh network 100, and a way of identifying which participating device 212 is currently permitted to join the mesh network 100.
[0088] Steering data is obtained by the commissioning device 210 and indicates the device identifiers of one or more participating devices 212 that are permitted to join the mesh network 100. The commissioning device 210 propagates the steering data to the router 102 in the mesh network 100. The router 102 then includes the steering data in a beacon for the mesh network 100 and transmits the beacon to provide the steering data to potential participating devices 212. The beacon is transmitted with an indication that the mesh network 100 is available and whether the potential participating device 212 is permitted to join the mesh network 100. For example, the commissioning device 210 obtains the PSKd and EUI-64MAC address for the desired participating device 212, as described above. From this EUI-64, the commissioning device 210 constructs the steering data to signal the desired participating device 212 that it is permitted to join the mesh network 100.
[0089] In a further example, the steering data may include a list of 16-bit cyclic redundancy check (CRC16) encoded EUI-64 addresses of participating devices 212 that are permitted to join the mesh network 100. CRC16 provides a compact representation of EUI-64 addresses with a low probability of collision between two different EUI-64 addresses in the CRC16 encoded addresses. The use of CRC16 reduces the size of the beacon payload required for the device identifier of the participating device 212, thereby enabling the appropriate participating device 212 to efficiently find the correct mesh network 100 to join while efficiently utilizing the resources of the mesh network 100.
[0090] If multiple mesh networks 100 have active commissioners, the participating device 212 searches for the correct mesh network 100 by collecting beacons from active scans. The participating device 212 discards beacons that have been collected from non-mesh networks, beacons with the wrong protocol, beacons with the wrong version, beacons with the wrong XPANID, beacons with the wrong network name, and / or beacons whose participation is disabled. The participating device 212 prioritizes collected beacons that perfectly match the device identifier of the participating device 212 in the steering data of the collected beacons, and then prioritizes the matching collected beacons in order of best signal strength. The participating device 212 attempts to join preferred networks one at a time (as described above) until it successfully joins a mesh network 100. If a participating device exhausts the network's priority list without successfully joining the mesh network 100, the participating device 212 may immediately or after a delay perform an active scan to restart the search for the mesh network 100.
[0091] The steering data indicates whether any participating device 212 may or should not attempt to join the mesh network 100. In addition, all bits in the steering data may be set to a value of 0 to indicate that the mesh network 100 is not available for joining. Alternatively, all bits in the steering data may be set to a value of 1 to indicate that the mesh network 100 is available for joining by any participating device 212.
[0092] Some commissioning devices 210 may lack the resources to extract the EUI-64 and participating device credentials by easily scanning a QR code. In this case, the least significant 24 bits of the EUI-64 are used as the device identifier for participating device 212 when retrieving steering data. The S bit in the beacon indicates whether a short or long device identifier is used for participating device 212 to retrieve steering data. If the EUI-64 is used as the device identifier to retrieve steering data, the S bit is set to 0. If the least significant 24 bits of the EUI-64 are used as the device identifier to retrieve steering data, the S bit is set to 1.
[0093] Figure 8 shows an example of steering data 800 generated using a Bloom filter, which is used to encode device identifiers for participating device 212 into steering data. The Bloom filter provides efficient encoding of device identifiers with a low probability of collisions between encoded values of different device identifiers. Each device identifier 802 to be included in the steering data is encoded by a first hash function 804 to generate a first hash value and by a second hash function 806 to generate a second hash value. For example, the first hash function 804 is CRC16-CCITT and the second hash function 806 is CRC16-ANSI. The device identifier 802 is the EUI-64 of participating device 212. Alternatively, the least significant 24 bits of the EUI-64 are used as the device identifier 802.
[0094] A modulo operation 808 is performed on the first and second hash values. The divisor for the modulo operation is the length of the Bloom filter's bit array 810 (bit positions in bit array 810 are indicated by 812, and bit values by 814). Before determining the steering data, each bit in the bit array is initialized to the value 0. The result of each modulo operation determines the position in the bit array. The values at the two determined positions in the bit array are set to the value 1, and the two determined bit fields provide a mapping to the device identifier.
[0095] For example, performing the modulo operation 808 on the result of the first hash function 804 for a virtual device identifier 802 yields a value of 3 for device identifier 802. Performing the modulo operation 808 on the result of the second hash function 806 yields a value of 6 for device identifier 802. To show the Bloom-filtered value of the virtual device identifier 802, the values at bit positions 3 and 6 are set to a value of 1.
[0096] Participating device 212 also calculates the Bloom filter bit positions that represent the device identifier of participating device 212. Participating device 212 determines whether both of the calculated bit positions contain a value of 1 in the steering data in the collected beacon. A positive determination indicates to participating device 212 that it is permitted to participate in the mesh network 100. To indicate that any participating device 212 is permitted to participate in the mesh network 100, all bit values in the Bloom filter bit array may be set to a value of 1. Setting all bits in the toarray to a value of 0 indicates that there is no active commissioner for the mesh network 100 and that the mesh network 100 is not available for joining. The bloom filter provides a compact representation using anonymity for device identifiers, while enabling efficient discovery of the correct mesh network 100 that the appropriate participating device 212 should join, with a low probability of false positives indicating that a particular participating device 212 is allowed to join the mesh network 100 when it is not.
[0097] The parameters for the Bloom filter are k, the number of hash functions used to hash the device identifier; m, the number of bits in the Bloom filter's bit array; and n, the number of participating devices 212 to represent in the steering data. As an example, and not an limitation, we show that parameter k is set to 2, and two hash functions are used: CRC16-CCITT with polynomial 0x1021 and CRC16-ANSI with polynomial 0x8005. Other values for k, hash function, and polynomial are possible.
[0098] The collision probability p for a Bloom filter can be calculated as follows:
[0099]
number
[0100] The commissioning device 212 may set the length m of the bit array as needed to obtain a reasonably low collision probability in the steering data. The use of a bloom filter allows the steering data to be scaled to support the participation of a large number of participating devices 212 into the mesh network 100 while maintaining a low collision probability. The following table shows various values of n and collision probability p when m = 127 (i.e., 16 bytes).
[0101] [Table 1]
[0102] To allow a large number of participating devices 212 (for example, 1000), the commissioning device 210 may decompose a large group into smaller groups such that each smaller group has a lower collision probability (misjudgment) in the steering data.
[0103] Managing commissioning data across mesh network partitions Figure 9 shows the mesh network 100 in the event of a split or division. For example, a power outage in one of the routers 102 may cause a split in the mesh network 100, preventing one section or fragment of the mesh network 100 from communicating with another section. Alternatively, radio interference may cause a split in the mesh network 100 by disrupting communication in a portion of it. If the mesh network 100 splits into two network fragments 902 and 904, network fragment 904 will select a leader for fragment 904. It may also accept a different commissioner for fragment 904 than the one for fragment 902. One or both fragments may update their network credentials during the split.
[0104] The mesh network 100 can be neatly and reliably divided into two distinct segments, which are still fully functional networks even if connectivity between the two segments is interrupted. These segments can continue any incomplete communications contained within the uninterrupted segments, which can usually be continued with key rotation. Two mesh network segments that were previously part of a single mesh network 100 can autonomously merge once connectivity between the two segments is restored.
[0105] If the commissioning credentials in network fragment 902 are changed during the split, this change in commissioning credentials will propagate to devices in network fragment 904 when connectivity is restored between network fragments 902 and 904. In other words, in some embodiments, the commissioning credentials are updated to the most recently adopted credentials. However, if both network fragments 902 and 904 authorize separate commissioners and receive separate new commissioning credentials during the split, determining the most recent credentials may become more difficult.
[0106] The resolution of commissioning credentials between any two previously fragmented but now merged mesh network fragments propagates the most recently modified commissioning dataset to the devices in mesh network 100. If there is a change in fragment 902, the user assumes that they have modified the commissioning credentials across the entire mesh network 100, but due to the split, the changes are only effective in fragment 902. At some point, fragments 902 and 904 merge. After fragmentation, although the credentials in fragment 902 were modified, the original credentials in fragment 904 remained unchanged, so the merged fragments assume that new credentials were established in fragment 902 during fragmentation. If there is a change in the commissioning credentials in fragment 904 during the split, the changes made to fragment 904 are propagated to the devices in fragment 902 after the merger.
[0107] If two users change their commissioning credentials in their respective two fragments 902 and 904 during a split, each user will believe they are changing their commissioning credentials across the entire mesh network 100. However, because the mesh network 100 is fragmented, both users can establish themselves as network commissioners and change their commissioning credentials in their respective network fragments. At some point, fragments 902 and 904 merge, but it may not be known which leader from the two fragments is dominant as the leader for the merged mesh network. The dominant leader has a copy of the most recently changed commissioning credentials. - may not have it. Since the commissioning credentials were changed independently in the two fragments, the fragment with the most recently updated commissioning credentials takes precedence.
[0108] To determine which of the two network credentials is most recent, the commissioning dataset includes timestamp information and the commissioning credentials, resolving differences between commissioning credentials when mesh networks merge. The timestamp information allows a node in mesh network 100 to determine the most recent update to the commissioning credentials in any fragment, and to synchronize the commissioning dataset in devices in mesh network 100 with the most recently updated commissioning credentials.
[0109] The timestamp information includes the timestamp and an indication of whether the timestamp is traceable to Coordinated Universal Time (UTC) or relative to the time within the mesh network 100. For example, if the commissioning device 210 uses a network time protocol such as Network Time Protocol (NTP) Access to time provided via cellular networks, timing information from Global Positioning System (GPS) receivers, etc. If the device is a smartphone or computer, the timestamp is traceable to UTC. As an example, but not limited to, if a timestamp is traceable to UTC, then the timestamp is traceable to, for example, two years after the start of UNIX® time. -15 It is expressed in seconds, traceable to a known epoch. If the timestamp is UTC traceable, the display, such as the U bit, is set to indicate that the timestamp is traceable to UTC.
[0110] If the commissioning device 210 is an embedded system such as a proprietary commissioner that does not have access to UTC-traceable time, the timestamp includes a relative time value. The relative time value is obtained by using a previous value of the timestamp, such as one provided by the reader 216, and adding an increment of clock ticks to the previous timestamp to generate a timestamp for the updated commissioning dataset. As an example, but not limited to, the time tick may be a 15-bit representation of a time tick of less than one second derived from the proprietary commissioner's 32kHz clock. If the timestamp is relative time, a marker such as the U bit is set to a value of 0 to indicate that the timestamp is represented as relative time. The increment of the timestamp for relative time allows changes to the commissioning data to be detected. When partitions merge, if one of the commissioning timestamps is traceable to UTC and the second timestamp is relative time, the commissioning data with the UTC-traceable timestamp will be given higher priority.
[0111] If the timestamps are identical between commissioning credentials updated separately during a split, alternative means may be used to break the link between the timestamps. In some embodiments, lexicographical comparison (e.g., memcmp) may be performed to determine which credentials are more recent. In some embodiments, if there is a link between timestamps, a network fragment may be preferred so that the change to the commissioning credentials in one network fragment is adopted. For example, if network fragments 902 and 904 each receive a commissioning credential change containing the same timestamp, the network fragment having the border router 202 may be preferred so that the change in network fragment 902 is adopted if the timestamp values in the commissioning datasets of the two fragments are identical. It can be considered as one piece.
[0112] Exemplary methods 1000–1800 are described with reference to Figures 10–18, respectively, according to one or more embodiments of mesh network commissioning. In general, any of the components, modules, methods, and operations described herein can be implemented using software, firmware, hardware (e.g., fixed logic circuits), manual processing, or any combination thereof. Some operations of the exemplary methods may also be described in the general context of executable instructions stored on computer-readable storage memory local to and / or remote to the computer processing system, and implementation examples may include software applications, programs, functions, etc. Alternatively, or in addition thereto, any of the functionalities described herein may utilize a field-programmable gate array (FPGA), specifically... Application-specific integrated circuits (ASICs) Application-specific Standard Product (ASSP), System-on-Chip System-on-a-chip system (SoC), complex programmable logic device This includes, but is not limited to, devices such as Complex Programmable Logic Devices (CPLDs). This can be done, at least partially, by one or more hardware logic components.
[0113] Figure 10 shows an exemplary method of mesh network commissioning, generally relating to joining nodes to a mesh network. The order in which the method blocks are described is not intended to be interpreted as restrictive, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0114] In block 1002, a beacon request is received from a participating device, and in block 1004, a beacon is sent from the joiner router to the participating device, the beacon indicating that the mesh network is available for joining. For example, in mesh network 100, joiner router 214 receives a beacon request from participating device 212 and then sends a beacon to the participating device, the beacon indicating that the mesh network 100 is available for joining. The transmitted beacon is effective in enabling participating device 212 to establish a local link between the participating device and the joiner router.
[0115] In block 1006, a message is received from a participating device requesting to join the mesh network. For example, in mesh network 100, joiner router 214 receives a message from participating device 212 requesting to join the mesh network. The message received from participating device 212 may include an encrypted device identifier that can be used to authenticate the participating device. The participating device is authenticated using Juggling Password Authenticated Key Exchange (J-PAKE), and the authentication is effective in establishing a secure communication session between the commissioning device 210 of mesh network 100 and the participating device.
[0116] In block 1008, the received message is forwarded to the commissioning device of the mesh network. For example, the joiner router 214 forwards the received message from the participating device 212 to the commissioning device 210 of the mesh network 100. In this implementation, the message may be received and forwarded using Datagram Transport Layer Security (DTLS) or User Datagram Protocol (UDP). In addition, the joiner router 214 that forwards the received message to the commissioning device 210 has a connection with the commissioning device 214. The communication path between the commissioning device 210 and the network may include forwarding received messages through one or more routers of the mesh network 100. In this implementation, one of the routers may be a border router 202 that connects the mesh network 100 to an external network, and the commissioning device is connected to the external network.
[0117] In block 1010, authentication is received for the participating device to join the mesh network, and in block 1012, network information is sent to the participating device, which is valid to enable the participating device to join the mesh network 100. For example, the joiner router 214 receives authentication from the commissioning device 210 for the participating device 212 to join the mesh network 100, and the joiner router 214 sends network information to the participating device, which is valid to enable the participating device 212 to join the mesh network.
[0118] Figure 11 shows an exemplary method 1100 of mesh network commissioning, generally relating to joining nodes to a mesh network. The order in which the method blocks are described is not intended to be interpreted as restrictive, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0119] In block 1102, a beacon request is received from a participating device, and in block 1104, a beacon is sent from the joiner router to the participating device, the beacon indicating that the mesh network is available for participation. For example, in mesh network 100, joiner router 214 receives a beacon request from participating device 212 and then sends a beacon to the participating device, the beacon indicating that the mesh network 100 is available for participation. The beacon includes the network name of mesh network 100 and steering data indicating one or more participating devices 212 that are permitted to join the mesh network. The transmitted beacon is valid to enable participating devices to establish a local link between themselves and the joiner router.
[0120] In block 1106, a DTLS-ClientHello message is received from a participating device requesting to join the mesh network, and in block 1108, the received DTLS-ClientHello message is encapsulated within a DTLS relay reception notification message. For example, a joiner router receives a DTLS-ClientHello message from participating device 212 requesting to join mesh network 100, and encapsulates the received DTLS-ClientHello message within a DTLS relay reception notification message. The DTLS-ClientHello message is receivable from participating device 212 using the User Datagram Protocol (UDP), and the DTLS relay reception notification message includes the address of participating device 212, the address of joiner router 214, and the received DTLS-ClientHello message.
[0121] In block 1110, the DTLS relay reception notification message is sent to the commissioning device of the mesh network. For example, the joiner router sends the DTLS relay reception notification message to the commissioning device 210 of the mesh network 100. In this implementation, the joiner router may apply a rate limit to the transmission of DTLS relay reception notification messages sent from participating devices to the commissioning device 210.
[0122] In block 1112, a DTLS relay transmission notification message is received from the commissioning device, and in block 1114, the contents of the DTLS relay transmission notification message are sent to the participating device, which enables the participating device to join the mesh network. For example, a joiner router receives a DTLS relay transmission notification message from commissioning device 210, sends the contents of the DTLS relay transmission notification message to participating device 212, which enables the participating device to join the mesh network 100, and which is effective in establishing a secure communication session between commissioning device 210 and the participating device. The DTLS relay transmission notification message includes the address of participating device 212, the address of joiner router 214, and a DTLS-HelloVerify message.
[0123] In block 1116, the commissioning device receives a message indicating that the participating device should be commissioned to receive network credentials for the mesh network, and in block 1118, the Key Encryption Key (KEK) shared between the commissioning device and the participating device is received. For example, the joiner router 214 receives a message from the commissioning device 210 indicating that the participating device 212 should be commissioned to receive network credentials for the mesh network 100, and also receives the Key Encryption Key (KEK) shared between the commissioning device 210 and the participating device.
[0124] In block 1120, the network credentials are sent to participating devices using KEK to secure the communication of network credentials. For example, the joiner router sends network credentials, including the network master key, to participating device 212 using KEK to secure the communication of network credentials, and the secure communication session is available for provisioning the participating devices.
[0125] Figure 12 shows an exemplary method 1200 of mesh network commissioning, generally relating to establishing a commissioning session in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0126] In block 1202, the availability of the mesh network for the commissioning device is advertised, and in block 1204, an application to become a commissioner for the mesh network is received from the commissioning device. For example, border router 202 of mesh network 100 advertises the availability of the mesh network for the commissioning device and receives an application to become a commissioner for the mesh network from commissioning device 210. The application may be received from commissioning device 210 in response to advertising the availability of the mesh network. Commissioning device 210 may also request a secure connection to border router 202, which is established using Datagram Transport Layer Security (DTLS). In addition, commissioning device 210 and border router 202 can communicate through other networks besides the mesh network, such as a Wi-Fi network or an Ethernet® network.
[0127] In block 1206, the received application is sent to the leader device of the mesh network, and in block 1208, a response to the application is received from the leader device, and the response indicates acceptance or rejection of the application. For example, border router 202 is a commission The receiving device 210 sends the received application to the leader device 216 of the mesh network 100, and then receives a response to the application from the leader device 216, which indicates acceptance or rejection of the application. The advertisement may be made using the Multicast Domain Name System (mDNS) service discovery protocol.
[0128] In block 1210, an indication of acceptance or rejection of the application is sent to the commissioning device. For example, the border router 202 sends an indication of acceptance or rejection of the application to the commissioning device 210, and acceptance of the application by the leader device 216 authorizes the commissioning device 210 to become the commissioner for the mesh network. Acceptance of the application establishes a secure commissioning session and also allows the leader device 216 to update its internal state tracking active commissioners for the mesh network, set the join permission flag for the mesh network to true, and propagate the commissioning dataset within the mesh network.
[0129] In block 1212, the identity of the commissioning device is registered with the border router in order to establish a secure commissioning communication session. For example, border router 202 registers the identity of commissioning device 210 with border router 202 in order to establish a secure commissioning communication session. Registering the identity of commissioning device 210 involves providing the border router 202 with encrypted commissioning credentials, which are derived from the commissioning credentials entered into commissioning device 210 by the user. The border router 202 contains an encrypted copy of the commissioning credentials that can be used to authenticate the commissioning device 210 to the mesh network 100. The encrypted copy of the commissioning credentials was previously derived from the commissioning credentials, which were injected into the leader device 216 of the mesh network 100 that derived the encrypted copy of the commissioning credentials. The leader device 216 then securely communicated the encrypted copy of the commissioning credentials to the border router.
[0130] Figure 13 shows an exemplary method 1300 of mesh network commissioning, generally relating to establishing a commissioning session in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0131] In block 1302, an application is received for a commissioning device to accept as a commissioner to commission participating devices to join the mesh network. For example, the leader device 216 of mesh network 100 receives an application for a commissioning device 210 to accept as a commissioner to commission participating device 212 to join the mesh network. The application is received from the border router 202 connected to the leader device 216 through the mesh network, and the commissioning device 210 is connected to the border router 202 through another network, such as a Wi-Fi network or an Ethernet® network. The application is also received using a secure communication session between the border router 202 and the commissioning device 210, and the secure communication session is established using Datagram Transport Layer Security (DTLS). The leader device 216 is a network interface for the mesh network. The commissioning device 210, including the face, can receive applications through the mesh network 100, and the commissioning device 210 applies to become a commissioner by setting the unique commissioner bit to true in the network beacon. The commissioning device 210 can communicate its application to the leader device through the Constrained Application Protocol (CoAP) port using the IEEE 802.15.4 interface.
[0132] In block 1304, a decision is made regarding whether to accept or reject the received application, and in block 1306, a response is sent to the commissioning device along with an indication of whether to accept or reject the received application. For example, the leader device 216 decides whether to accept or reject the received application and then sends a response to the commissioning device 210 along with an indication of whether to accept or reject the received application. The leader device 216 decides whether to accept or reject the received application based on the assurance that there is one active commissioner for the mesh network 100.
[0133] In block 1308, in response to the decision to accept the received application, the internal state tracking the active commissioner for the mesh network is updated. For example, the leader device 216 updates the internal state tracking the active commissioner for the mesh network.
[0134] In block 1310, a command is received from the commissioning device to initiate join mode for the mesh network, and in block 1312, the commissioning dataset is propagated within the mesh network. For example, leader device 216 receives a command from commissioning device 210 to initiate join mode for mesh network 100 and propagates the commissioning dataset within the mesh network. The commissioning dataset includes a commissioner session identifier, a commissioner timestamp, encrypted commissioner credentials, and a security policy indicating which security-related actions are permitted within the mesh network. If the commissioner is active on mesh network 100, the commissioning dataset further includes the location of border router 202. Once join mode is enabled within the mesh network, the commissioning dataset further includes steering data indicating which of the participating devices 212 are permitted to join the mesh network.
[0135] In block 1314, encrypted commissioning credentials are derived from the commissioning credentials injected into the reader device 216 during the commissioning of the reader device. For example, the reader device 216 derives encrypted commissioning credentials from the commissioning credentials injected into the reader device during the commissioning of the reader device. The derivation of the encrypted commissioning credentials is performed by applying a key derivation function, which performs multiple hashing operations using a cipher-based message authentication code (CMAC). In the implementation example, the commissioning credentials are a human-scale passphrase, and the derivation of encrypted commissioning credentials is useful for extending the length of the commissioning credentials.
[0136] In block 1316, a copy of the encrypted commissioning credentials is sent to the border router, enabling the border router to authenticate the commissioning device to the mesh network. For example, the leader device 216 receives the encrypted code A copy of the missioning credentials is sent to the border router 202, enabling the border router 202 to authenticate the commissioning device 210 to the mesh network.
[0137] Figure 14 shows an exemplary method 1400 of mesh network commissioning, generally relating to managing multiple commissioning sessions in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0138] In block 1402, a secure commissioning communication session is established between the commissioning device and the border router of the mesh network. For example, commissioning device 210 establishes a secure commissioning communication session between the commissioning device of mesh network 100 and the border router 202 in order to securely establish a network communication session for one or more participating devices 212 to join the mesh network. Commissioning device 210 establishes a secure commissioning communication session by sending a request from the commissioning device to the leader device 216 of mesh network 100 to request acceptance of commissioning device 210 as an active commissioner for the mesh network, and the commissioning device receives an indication of acceptance of the request from the leader device.
[0139] In block 1404, join for a mesh network is initiated. For example, a commissioning device initiates join for a mesh network by starting a join mode that causes one or more routers in the mesh network to advertise that the mesh network is accepting join requests. Commissioning device 210 can also initiate join for mesh network 100 by sending an administrative message to leader device 216 to make the mesh network joinable, the administrative message allowing leader device 216 to update network data for the mesh network. The network data is propagated to one or more router devices in the mesh network, and the network data includes an indication that mesh network 100 is available for join. The network data can be broadcast by the router devices via beacons, and the administrative message includes steering data indicating one or more join devices 212, and commissioning device 210 is configured to allow one or more join devices 212 to join the mesh network.
[0140] In block 1406, a request to join the mesh network is received from one of the participating devices. For example, commissioning device 210 receives a request to join mesh network 100 from one of the participating devices 212, and the request may be received via a joiner router. Commissioning device 210 can send an indication to joiner router 214 that participating device 212 should be commissioned to receive network credentials for mesh network 100 and a Key Encryption Key (KEK) shared between commissioning device 210 and the participating device. The indication sent to joiner router 214 enables the joiner router to use the received KEK to securely send the network credentials to participating device 212 and commission the participating device to the mesh network. The request received from participating device 212 may include the encrypted device identifier of the participating device, which is derived from the device identifier of the participating device using Juggling Password Authenticated Key Exchange (J-PAKE).
[0141] In block 1408, a secure joiner communication session is established between the commissioning device and the participating device. For example, commissioning device 210 establishes a secure joiner communication session between the commissioning device and participating device 212. Commissioning device 210 can establish a secure joiner communication session by determining from a copy of the device identifier received from the user as input to the commissioning device that the encrypted device identifier received from participating device 212 matches the encrypted device identifier derived by commissioning device 210, and commissioning device 210 uses the encrypted device identifier as a shared secret to secure the joiner communication session.
[0142] In block 1410, participating devices are authenticated using encrypted device identifiers, and in block 1412, participating devices join the mesh network. For example, commissioning device 210 authenticates participating device 212 using encrypted device identifiers and allows participating device 212 to join the mesh network.
[0143] Figure 15 shows an exemplary method 1500 of mesh network commissioning, generally relating to provisioning participating devices in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0144] In block 1502, a commissioning communication session is established between the commissioning device of the mesh network and the border router. For example, commissioning device 210 of mesh network 100 establishes a commissioning communication session between itself and border router 202. In block 1504, a joiner communication session is established between a participating device and the commissioning device. For example, commissioning device 210 of mesh network 100 establishes a joiner communication session between itself and participating device 212.
[0145] In block 1506, commissioning information is sent to participating devices, and this information is available to the participating devices for joining the mesh network. For example, commissioning device 210 of mesh network 100 sends commissioning information to participating device 212 that can be used by participating device 212 to join the mesh network.
[0146] In block 1508, the location of the commissioner application is received from the participating device, and in block 1510, the commissioner application is searched using the received location. For example, commissioning device 210 receives the location of the commissioner application from the participating device, and the received location may be a uniform resource locator (URL), and the commissioning application searches for the commissioner application from a cloud service via the internet. Commissioning device 210 can also use the received URL to determine whether the commissioner application is stored in the commissioning device's memory.
[0147] In block 1512, the commissioner application is executed to provision participating devices. For example, commissioning device 210 uses the commissioner application to provision participating devices. Provisioning device 212 includes updating the software on the participating device, linking the participating device to a user account on the cloud service, and / or configuring the participating device, which is a local configuration related to other devices in the mesh network. In block 1514, the commissioning of the participating device is completed, enabling the participating device to join the mesh network. For example, commissioning device 210 of mesh network 100 completes commissioning, enabling participating device 212 to join the mesh network.
[0148] Figure 16 shows an exemplary method 1600 of mesh network commissioning, generally relating to searching and steering in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0149] In block 1602, steering data for the mesh network is obtained, which includes a representation of the device identifier associated with the devices permitted to join the mesh network. For example, commissioning device 210 of mesh network 100 obtains steering data for the mesh network, which includes a representation of the device identifier associated with the devices permitted to join the mesh network. In this implementation, the steering data is a 16-bit cyclic redundancy check (CRC16) of the device identifier, which is an IEEE 64-bit extended unique identifier (EUI-64). Commissioning device 210 may also obtain steering data for mesh network 100 by obtaining steering data for additional device identifiers associated with additional devices permitted to join the mesh network.
[0150] In block 1604, steering data is propagated from the commissioning device for the mesh network to the routers in the mesh network. For example, commissioning device 210 of mesh network 100 propagates steering data to the routers in the mesh network, and the steering data indicates that the commissioner is active on the mesh network. Propagating the steering data is useful because it allows router 102 to send the steering data in a beacon message, and the steering data is useful because it allows devices associated with a device identifier to identify that the device is authorized to join the mesh network. Commissioning device 210 propagating the steering data is useful because it allows devices to distinguish the mesh network from other networks, the other networks being IEEE 802.15.4 networks.
[0151] Figure 17 shows an exemplary method 1700 of mesh network commissioning, generally relating to searching and steering in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0152] In block 1702, steering data for the mesh network is obtained, which includes a representation of the device identifier associated with devices permitted to participate in the mesh network, and the representation is shown as a set of values in a Bloom filter that represent the device identifier. For example, commissioning device 210 of mesh network 100 obtains steering data for the mesh network. The steering data includes a representation of the device identifier as a set of values in a Bloom filter. In the implementation, the commissioning device 210 obtains the steering data by applying a first hash function to the device identifier to generate a first hash value, and a second hash function to the device identifier to generate a second hash value. The device identifier may be an IEEE 64-bit Extended Unique Identifier (EUI-64), and the device identifier is the least significant 24 bits of the EUI-64. In the implementation, the first and second hash functions are cyclic redundancy checks (CRCs), where the first hash function is CRC16-CCITT and the second hash function is CRC16-ANSI.
[0153] The commissioning device 210 then performs a modulo operation on the first hash value to determine the first bit field position in the Bloom filter, and a modulo operation on the second hash value to determine the second bit field position in the Bloom filter. The divisor for the modulo operation can be the length of the bit array of the Bloom filter. The commissioning device 210 can set the value at the first bit field position of the Bloom filter to 1, and the value at the second bit field position of the Bloom filter to 1. The commissioning device 210 can set all bit field values in the steering data to 1 to indicate that the mesh network is open to any device. Alternatively, the commissioning device 210 can set the bit field values in the steering data to 0 to prevent participation in the mesh network.
[0154] In block 1704, steering data is propagated from the commissioning device for the mesh network to the routers in the mesh network. For example, commissioning device 210 of mesh network 100 propagates steering data to the routers in the mesh network, and the steering data indicates that the commissioner is active on the mesh network. Propagating the steering data allows router 102 to send the steering data in a beacon message, and the steering data allows a device associated with a device identifier to identify that the device is permitted to join the mesh network by comparing a set of values in a Bloom filter with a second set of values obtained by the device.
[0155] Figure 18 shows an exemplary method 1800 of mesh network commissioning, generally relating to the division of nodes in a mesh network. The order in which the method blocks are described is not intended to be interpreted as limiting, and any number of described method blocks can be combined in any order to implement a method or an alternative method.
[0156] In block 1802, a commissioning dataset is received by a node device in the mesh network. For example, a node device (e.g., router 102 or end device 106) in a node of mesh network 100 receives a commissioning dataset that includes a received timestamp, commissioning credentials, the network name of the mesh network, and a security policy indicating which security-related actions are permitted in the mesh network. The received timestamp includes a time value and an indication that the time value is traceable to Coordinated Universal Time (UTC).
[0157] In block 1804, the received timestamp contained in the received commissioning dataset is compared with the stored timestamp contained in the commissioning dataset stored on the node device. For example, mesh network 100 In this scenario, the node device compares the received timestamp contained in the received commissioning dataset with the stored timestamp contained in the commissioning dataset stored in the node device. In this implementation, the node device and leader device were previously commissioned to the mesh network, and the previous commissioning stored the same commissioning dataset in the node device and leader device. The stored commissioning dataset in the node device may be updated after a split in the mesh network, which disrupts communication between the node device and leader device on the mesh network. The split separates the mesh network, with a first partition containing the leader device and a second partition containing the node device. The node device can receive the commissioning dataset after the first and second partitions of the mesh network merge, which re-establishes the communication path between the node device and leader device on the mesh network.
[0158] In block 1806, a determination is made as to whether the stored timestamps in the commissioning dataset stored on the node device are more recent than the timestamps in the received commissioning dataset. For example, based on the comparison (in block 1806), the node device determines whether the stored timestamps in the commissioning dataset stored on the node device are more recent than the timestamps in the received commissioning dataset.
[0159] If the stored timestamp is more recent than the received timestamp (i.e., "yes" in 1806), then in 1808, a message is sent to the mesh network's leader device, containing the stored commissioning dataset. For example, a node device in a mesh network sends a message containing the stored commissioning dataset to the leader device of mesh network 100. The sent message allows the leader device to accept the stored commissioning dataset as the most recent commissioning dataset for the mesh network and propagate the stored commissioning dataset to the mesh network. Alternatively, if the received timestamp is more recent than the stored timestamp (i.e., "no" in 1806), then in 1810, the stored commissioning dataset is updated to match the received commissioning dataset. For example, a node device in a mesh network updates the stored commissioning dataset to match the received commissioning dataset.
[0160] Figure 19 shows an exemplary environment 1900 in which an embodiment of a mesh network 100 (as described with reference to Figure 1) and mesh network commissioning can be realized. Generally, the environment 1900 includes the mesh network 100 realized as part of a smart home or other type of structure having any number of mesh network devices configured for communication in the mesh network. For example, the mesh network devices may include a thermostat 1902, a hazard detector 1904 (for example, smoke and / or carbon monoxide), a camera 1906 (for example, indoor and outdoor), a lighting unit 1908 (for example, indoor and outdoor), and any other type of mesh network device 1910 realized inside and / or outside the structure 1912 (for example, in a smart home environment). In this example, the mesh network devices also include not only any of the devices realized as a router 102, an end device 106, and / or a participating device 212, but also any of the aforementioned devices such as a commissioning device 210, a border router 202, a joiner router 214, etc. It may include any of the following.
[0161] In Environment 1900, any number of mesh network devices can be implemented for wireless interconnection to communicate and interact with one another wirelessly. Mesh network devices are modular, intelligent, multi-sensing, network-connected devices that can seamlessly integrate with one another and / or with a central server or cloud computing system to provide one of a variety of useful smart home purposes and implementation examples. An example of a mesh network device that can be implemented as one of the devices described herein is shown and described with reference to Figure 20.
[0162] In a realization example, the thermostat 1902 may include a Nest® learning thermostat that detects ambient climate characteristics (e.g., temperature and / or humidity) in a smart home environment and controls the HVAC system. The learning thermostat 1902 and other smart devices “learn” by incorporating occupant settings to the devices. For example, the thermostat learns preferred temperature setpoints for morning and evening, the times when the occupants of the structure are asleep or awake, and the times when the occupants are usually out or at home.
[0163] Hazard detectors 1904 can be implemented to detect the presence of hazardous substances or substances indicating hazardous substances (e.g., smoke, fire, or carbon monoxide). In the example of wireless interconnection, a hazard detector 1904 may detect the presence of smoke indicating fire in a structure, in which case the hazard detector that first detects the smoke can transmit a low-power wake-up signal to all connected mesh network devices. Other hazard detectors 1904 can then receive the transmitted wake-up signal and activate a high-power state for hazard detection to receive a warning message via wireless communication. Additionally, a lighting unit 1908 can receive the transmitted wake-up signal and activate in the area of the detected hazard to illuminate and identify the problem area. In another example, the lighting unit 1908 may activate with one lighting color to indicate a problem area or region in the structure, such as a detected fire or intrusion, and with another lighting color to indicate a safe area and / or an escape route from the structure.
[0164] In various configurations, the mesh network device 1910 may include a front door interface device that works in conjunction with a network-connected door lock system to detect and react to the approach or departure of a person to or from a location, such as an exterior door of a structure 1912. The front door interface device can interact with other mesh network devices based on whether someone has approached or entered the smart home environment. The front door interface device can control doorbell functionality and notify of the approach or departure of a person via audible or visual means, and can also control settings for the security system, such as activating or deactivating the security system when residents enter or exit. The mesh network device 1910 may also include other sensors and detectors to detect ambient lighting conditions, detect room occupancy (e.g., with an occupancy sensor), and control the output state and / or dimming state of one or more lights. In some cases, sensors and / or detectors may also control the output state or speed of fans, such as ceiling fans. Sensors and / or detectors may also detect occupancy in a room or enclosed space and control the supply of power to outlets or devices, such as when the room or structure is unoccupied.
[0165] The mesh network device 1910 also connects and / or controls connected appliances and / or systems such as refrigerators, stoves and ovens, washing machines, dryers, air conditioners, pool heaters, irrigation systems, security systems, as well as televisions, entertainment systems, etc. It may also include other electronic and computing devices such as computers, intercom systems, garage door openers, ceiling fans, and control panels. When plugged in, the equipment, device, or system can notify itself to the mesh network as described above and can be automatically integrated with mesh network controllers and devices in smart homes, etc. The mesh network device 1910 may also include devices that are physically located outside the structure but within wireless communication range, such as devices that control swimming pool heaters or irrigation systems.
[0166] As described above, the mesh network 100 includes a border router 202 that interfaces with an external network outside the mesh network 100 for communication. The border router 202 connects to an access point 204, which connects to a communication network 206, such as the internet. A cloud service 208 connected via the communication network 206 provides services related to and / or using devices within the mesh network 100. For example, the cloud service 208 may include applications for connecting end-user devices such as smartphones and tablets to devices in the mesh network, processing and presenting data obtained in the mesh network 100 to end users, linking one or more devices in the mesh network 100 to a user account in the cloud service 208, and provisioning and updating devices in the mesh network 100. For example, in a smart home environment, a user can control a thermostat 1902 and other mesh network devices using a network-connected computer or portable device such as a mobile phone or tablet device. Also, mesh network devices can communicate information to any central server or cloud computing system via the border router 202 and access point 204. Data communication may be performed using one of several custom or standard wireless protocols (e.g., Wi-Fi, ZigBee® for low power, 6LoWPAN, etc.) and / or using one of several custom or standard wired protocols (e.g., CAT6 Ethernet®, HomePlug®, etc.).
[0167] Any of the mesh network devices in the mesh network 100 can function as a low-power and communication node to create the mesh network 100 in a smart home environment. Individual low-power nodes in the network can periodically send messages about what they are sensing, and other low-power nodes in the environment can repeat messages in addition to sending their own messages, thereby communicating messages from node to node (i.e., device to device) across the entire mesh network. Mesh network devices can be implemented to conserve power, especially in the case of battery-powered devices, by utilizing low-power communication protocols to receive messages, convert the messages to other communication protocols, and send the converted messages to other nodes and / or a central server or cloud computing system. For example, a occupancy and / or ambient light sensor can not only measure ambient light but also detect occupants in a room and activate a light source if the ambient light sensor detects that the room is dark and if the occupancy sensor detects that someone is in the room. The sensor may also include a low-power wireless communication chip (e.g., a Zigbee chip) that periodically sends messages about occupancy in the room and the amount of light in the room, including instantaneous messages that occur simultaneously with the occupancy sensor detecting the presence of a person in the room. As described above, these messages may be transmitted wirelessly from node to node (i.e., device to device) within a smart home environment using a mesh network, and also over the internet to a central server or cloud computing system.
[0168] In other configurations, various devices within the mesh network can function as "trigger lines" for alarm systems in a smart home environment. For example, if an intruder evades detection by alarm sensors located at windows, doors, and other entry points to the structure or environment, the alarm can still be triggered by receiving messages such as occupancy, movement, heat, or sound from one or more low-power mesh nodes in the mesh network. In another implementation example, the mesh network could be used to automatically turn lighting units 1908 on or off as a person moves from room to room within the structure. For example, a mesh network device could detect a person's movement through the structure and communicate a corresponding message through the nodes in the mesh network. Other mesh network devices receiving the message can then activate and / or deactivate accordingly, using a message indicating which room is occupied. As mentioned above, the mesh network can also be used to provide exit lighting in emergencies, such as by illuminating the appropriate lighting unit 1908 leading to a safe exit. The lighting unit 1908 may also illuminate to indicate the direction along the exit path to which a person should move to safely exit the structure.
[0169] Various mesh network devices may also be implemented to communicate with wearable computing devices that can be used to identify and locate occupants of a structure, and to adjust temperature, lighting, sound systems, etc. accordingly. In other implementations, RFID sensing (e.g., a person wearing an RFID bracelet, necklace, or key hob), synthetic vision techniques (e.g., a video camera and a facial recognition processor), voice techniques (e.g., voice, acoustic pattern, and vibration pattern recognition), ultrasonic sensing / imaging techniques, and infrared or near-field communication (NFC) techniques (e.g., a person wearing an infrared or NFC-enabled smartphone) may be used, along with rule-based inference engines or artificial intelligence techniques, to derive useful conclusions from the sensed information regarding the location of occupants in a structure or environment.
[0170] In other realization examples, the personal comfort area network, personal health area network, personal safety area network, and / or other such person-facing functionality of a service robot can be enhanced by logical integration with other mesh network devices and sensors in the environment, following rule-based reasoning or artificial intelligence techniques to achieve better performance of these functionalities. In the example related to personal health areas, the system can detect whether a pet kept in the house is moving towards the current location of the resident (for example, using one of the mesh network devices and sensors), along with rule-based reasoning and artificial intelligence techniques. Similarly, a hazard detector service robot, notified that temperature and humidity levels are rising in the kitchen, can temporarily raise hazard detection thresholds, such as a smoke detection threshold, based on the reasoning that any small increase in ambient smoke levels is likely due to cooking work and not due to truly dangerous conditions. Any service robot configured for any type of monitoring, detection, and / or servicing can be realized as a mesh node device on a mesh network, following a wireless interconnection protocol for communicating over the mesh network.
[0171] The mesh network device 1910 may also include a smart alarm clock for each individual resident of the structure in the smart home environment. For example, a resident can customize and set the alarm device for wake-up times, such as the next day or the following week. Artificial intelligence can be used to examine the resident's response to the alarm when it sounds and to infer about preferred sleep patterns over time. Individual residents can then be tracked in the mesh network based on their unique signature. Unique signatures are determined based on data obtained from sensors located in mesh network devices, including ultrasonic sensors and passive IR sensors. Resident unique signatures can be based on combinations of patterns such as movement, voice, height, and size, and facial recognition techniques can also be used.
[0172] In an example of wireless interconnection, an individual's wake-up time can be associated with a thermostat 1902 to efficiently control the HVAC system to preheat or cool the structure to desired sleep and wake-up temperature settings. Preferred settings can be learned over time, for example, by capturing the temperature set in the thermostat before a person goes to sleep and when they wake up. The collected data may also include biometric indicators of the person, such as breathing patterns, heart rate, and movement, from which inferences are made based on a combination of this data and data indicating when the person actually woke up. Other mesh network devices can use this data to provide other smart home purposes, such as adjusting the thermostat 1902 to preheat or cool the environment to desired settings, and turning lights 1908 on or off.
[0173] In practical applications, mesh network devices can also be used for sensing sound, vibration, and / or motion to detect water flow in a smart home environment and to make inferences about water usage based on water usage and consumption algorithms and mapping. This can be used to obtain signatures or fingerprints of each water source in the home, also known as "sound fingerprinting water usage." Similarly, mesh network devices can be used to detect faint sounds, vibrations, and / or movements of undesirable pests such as rats and other rodents, as well as termites, cockroaches, and other insects. The system can then notify residents of suspected pests in the environment with warning messages or other means to help facilitate early detection and prevention.
[0174] Figure 20 shows an exemplary mesh network device 2000 that may be implemented as one of the mesh network devices in a mesh network according to one or more embodiments of mesh network commissioning as described herein. The device 2000 may be integrated with electronic circuits, a microprocessor, memory, input / output (I / O) logic control, communication interfaces and components, as well as other hardware, firmware, and / or software for implementing the device in a mesh network. The mesh network device 2000 may also be implemented using a variety of components, such as any number of different components and any combination thereof, as further described with reference to the exemplary device shown in Figure 21.
[0175] In this example, the mesh network device 2000 includes a low-power microprocessor 2002 and a high-power microprocessor 2004 (e.g., a microcontroller or digital signal processor) that process executable instructions. The device also includes input / output (I / O) logic control 2006 (e.g., for including electronic circuits). The microprocessor may include integrated circuits, programmable logic devices, logic device components formed using one or more semiconductors, and other realizations in silicon and / or hardware, such as a processor and memory system implemented as a system-on-a-chip (SoC). Alternatively, or in addition to these, the device may be implemented using one or a combination of software, hardware, firmware, or fixed logic circuits that can be implemented using processing and control circuits. The low-power microprocessor 2002 and the high-power microprocessor 2004 can also support one or more different device functionalities of the device. For example, the high-power micro The high-power microprocessor 2004 may perform computationally intensive operations, while the low-power microprocessor 2002 may manage less complex processes, such as detecting hazards or temperature from one or more sensors 2008. The low-power microprocessor 2002 may also start or initialize the high-power microprocessor 2004 for computationally intensive processes.
[0176] One or more sensors 2008 can detect acceleration, temperature, humidity, water, power supply, proximity, external motion, device motion, audio signals, ultrasonic signals, optical signals, fire, smoke, carbon monoxide, global positioning satellite (GPS) signals, radio frequency (RF), It can be implemented to detect various properties such as other electromagnetic signals or electromagnetic fields. For this reason, the sensor 2008 may include one or a combination thereof of temperature sensors, humidity sensors, hazard-related sensors, other environmental sensors, accelerometers, microphones, cameras and lesser optical sensors (e.g., charge-coupled elements or video cameras), active or passive radiation sensors, GPS receivers, and radio frequency identification detectors. In an implementation example, the mesh network device 2000 may include one or more primary sensors and one or more secondary sensors, where the primary sensors sense data central to the device's core operation (e.g., sensing temperature in a thermostat, or sensing smoke in a smoke detector), while the secondary sensors sense other types of data (e.g., motion, light, or sound), which may be used for energy efficiency or smart operation purposes.
[0177] The mesh network device 2000 includes a memory device controller 2010 and a memory device 2012, such as any type of non-volatile memory and / or other suitable electronic data storage device. The mesh network device 2000 may also include various firmware and / or software, such as an operating system 2014 maintained by memory as computer executable instructions and executed by a microprocessor. The device software may also include a commissioning application 2106 that implements an embodiment of mesh network commissioning. The mesh network device 2000 also includes a device interface 2018 for interface connection with other devices or peripheral components and an integrated data bus 2020 that connects the various components of the mesh network device for data communication between components. The data bus in the mesh network device may also be implemented as one or a combination of different bus structures and / or bus architectures.
[0178] Device Interface 2018 may receive input from and / or provide information to the user (for example, as a user interface), and the received input may be used to define settings. Device Interface 2018 may also include mechanical or virtual components that respond to user input. For example, the user may mechanically move a sliding or rotatable component, or movement along a touchpad may be detected, and such movement may correspond to adjustment of the device settings. Physical and virtual movable user interface components may allow the user to define settings along a portion of an apparent continuum. Device Interface 2018 may also receive input from any number of peripheral devices, such as buttons, keypads, switches, microphones, and imaging devices (e.g., camera devices).
[0179] The mesh network device 2000 includes a mesh network interface for communication with other mesh network devices in the mesh network, and an external network interface for network communication via the internet, etc. The mesh network device 2000 may include a network interface 2022. The mesh network device 2000 also includes a wireless system 2024 for wireless communication with other mesh network devices via the mesh network interface, and for multiple different wireless communication systems. The wireless system 2024 may include Wi-Fi, Bluetooth®, This may include mobile broadband and / or point-to-point IEEE 802.15.4. Each of the different wireless systems may include wireless devices, antennas, and chipsets implemented for a specific wireless communication technology. The mesh network device 2000 also includes a power supply 2026, such as a battery, and / or for connecting the device to the line voltage. An AC power supply may also be used to charge the device's battery.
[0180] Figure 21 shows an exemplary system 2100 including an exemplary device 2102, which may be implemented as one of the mesh network devices that implement an embodiment of mesh network commissioning as described with reference to Figures 1-20 above. The exemplary device 2102 may be any type of computing device, client device, mobile phone, tablet, communication device, entertainment device, gaming device, media playback device, and / or other type of device. Alternatively, the exemplary device 2102 may be implemented as any other type of mesh network device configured for communication on a mesh network, such as a thermostat, hazard detector, camera, lighting unit, commissioning device, router, border router, joiner router, participating device, end device, reader, access point, and / or other mesh network device.
[0181] Device 2102 includes a communication device 2104 that enables wired and / or wireless communication of device data 2106, such as data communicated between devices in a mesh network, data being received, data scheduled for mass transmission, data packets of data, and data synchronized between devices. Device data may include any type of communication data and voice data, video data, and / or image data generated by applications running on the device. The communication device 2104 may also include transceivers for cellular communication and / or network data communication.
[0182] Device 2102 also includes an input / output (I / O) interface 2108, such as a data network interface that provides connection and / or communication links between the device, data networks (e.g., mesh network, external network, etc.), and other devices. The I / O interface can be used to connect the device to any type of component, peripheral, and / or accessory. The I / O interface also includes a data input port through which inputs such as any type of data, media content, and / or user input to the device can be received, and any type of communication data, as well as audio data, video data, and / or image data, can be received from any content and / or data source.
[0183] Device 2102 includes a processing system 2110 which can be at least partially realized in hardware, such as having any type of microprocessor, controller, etc., that processes executable instructions. The processing system may include integrated circuits, programmable logic devices, logic device components formed using one or more semiconductors, and other realizations in silicon and / or hardware, such as a processor and memory system realized as a system-on-a-chip (SoC). Alternatively, or in addition thereto, the device may include one or more of the software, hardware, firmware, or fixed logic circuits that can be realized using the processing and control circuits. This can be implemented using a combination of the above. Device 2102 may further include any type of system bus or other data and command transfer system that connects various components within the device. The system bus may include one or a combination of any different bus structures and architectures, as well as control lines and data lines.
[0184] Device 2102 also includes computer-readable storage memory 2112, such as a data storage device that is accessible by computing devices and provides persistent storage of data and executable instructions (e.g., software applications, modules, programs, functions, etc.). The computer-readable storage memory described herein excludes propagating signals. Examples of computer-readable storage memory include volatile and non-volatile memory, fixed and removable media devices, and any suitable memory device or electronic data storage that maintains data for access by computing devices. Computer-readable storage memory may include various implementations of random access memory (RAM), read-only memory (ROM), flash memory, and other types of storage memory in various memory device configurations.
[0185] The computer-readable storage memory 2112 provides storage for device data 2106 and various device applications 2114, such as an operating system maintained as a software application in the computer-readable storage memory and executed by the processing system 2110. The device applications may also include device managers, such as any form of control applications, software applications, signal processing and control modules, code specific to a particular device, or hardware abstraction layers for a particular device. In this example, the device applications also include a commissioning application 2116 that implements an embodiment of mesh network commissioning, for example, when the exemplary device 2102 is implemented as one of the mesh network devices described herein.
[0186] Device 2102 also includes an audio and / or video system 2118 that generates audio data for audio device 2120 and / or display data for display device 2122. The audio and / or display devices include any devices that process, display, and / or otherwise represent audio data, video data, display data and / or image data, such as image content of a digital photograph. In the embodiment, the audio and / or display devices are integrated components of the exemplary device 2102. Alternatively, the audio and / or display devices are external peripheral components of the exemplary device. In embodiments, at least some of the techniques described for mesh network commissioning may be implemented in a distributed system, for example, on platform 2126 through a “cloud” 2124. The cloud 2124 includes and / or represents platform 2126 for services 2128 and / or resources 2130.
[0187] Platform 2126 abstracts the basic functionality of hardware, such as server devices (for example, included in Service 2128) and / or software resources (for example, included as Resource 2130), and connects the exemplary device 2102 to other devices, servers, etc. Resource 2130 may also include applications and / or data that are available while computer processing is performed from the exemplary device 2102 to a remote server. In addition, Service 2128 and / or Resource 2130 are connected to the Internet, cellular network, or Wi-Fi network. Subscriber network services may be facilitated through networks, etc. Platform 2126 may also function to abstract and scale resources to service requests for resources 2130 realized through the platform, such as in an interconnected device embodiment where functionality is distributed throughout the system 2100. For example, functionality may be partially realized in an exemplary device 2102 and through Platform 2126, which abstracts the functionality of the cloud 2124.
[0188] While embodiments of mesh network commissioning have been described using language specific to features and / or methods, the scope of the appended claims is not necessarily limited to the specific features or methods described. Rather, certain features and methods are disclosed as exemplary realizations of mesh network commissioning, and other equivalent features and methods are intended to fall within the scope of the appended claims. Furthermore, various different embodiments have been described, and it should be understood that each described embodiment is achievable independently or in relation to one or more other described embodiments.
[0189] A method for securely joining a device to a mesh network includes the steps of: a joiner router receiving a message from a participating device requesting to join the mesh network; forwarding the received message to the mesh network's commissioning device; receiving authentication from the commissioning device for the participating device to join the mesh network; and sending network information to the participating device, which is valid to enable the participating device to join the mesh network.
[0190] In lieu of, or in addition to, the above-described method, further includes the steps of receiving a beacon request from a participating device and sending a beacon from the joiner router to the participating device, wherein the beacon provides an indication that the mesh network is available for participation; the step of sending the beacon is effective in enabling the participating device to establish a local link between the participating device and the joiner router; the steps of receiving the message and forwarding the received message are performed using Datagram Transport Layer Security (DTLS); the steps of receiving the message and forwarding the received message are performed using User Datagram Protocol (UDP); the message received from the participating device The sage includes an encrypted device identifier that can be used to authenticate participating devices, the participating devices are authenticated using Juggling Password Authenticated Key Exchange (J-PAKE), and the authentication is valid to establish a secure communication session between the commissioning device and the participating devices; the step of forwarding the received message to the commissioning device includes the step of forwarding the received message through one or more routers of the mesh network in the communication path between the joiner router and the commissioning device; and one of the one or more routers is a border router that connects the mesh network to an external network, and the commissioning device is attached to the external network; or one or more of these include one or a combination thereof.
[0191] A mesh network device implemented as a joiner router, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application receiving messages from participating devices requesting to join the mesh network via the mesh network interface, and the received messages are transmitted to the mesh network The network is configured to forward the information to the twork's commissioning device, which then receives authentication from the commissioning device for the participating device to join the mesh network, and initiates the transmission of network information to the participating device, which is valid to enable the participating device to join the mesh network.
[0192] In place of, or in addition to, the aforementioned mesh network devices, the commissioning application is configured to receive beacon requests from participating devices via the mesh network interface, and to initiate the transmission of beacons from the joiner router to the participating devices, the beacons providing an indication that the mesh network is available for participation; the beacons are effective in enabling participating devices to establish a local link between the participating devices and the joiner router; the commissioning application is configured to receive and forward messages using Datagram Transport Layer Security (DTLS); the commissioning application is configured to receive and forward messages using User Datagram Protocol (UDP); The following are included, or a combination thereof: the system is configured to forward sage; messages received from participating devices include encrypted device identifiers that can be used to authenticate the participating devices, and participating devices are authenticated using Juggling Password Authenticated Key Exchange (J-PAKE), and authentication is valid to establish a secure communication session between the commissioning device and the participating devices; the commissioning application is configured to forward received messages through one or more routers of the mesh network in the communication path between the joiner router and the commissioning device; and one of the one or more routers is a border router that connects the mesh network to an external network, and the commissioning device is attached to the external network.
[0193] A mesh network system includes a joiner router and a participating device configured to request to join the mesh network, the joiner router receiving a message from the participating device requesting to join the mesh network, forwarding the received message to the mesh network's commissioning device, receiving authentication from the commissioning device for the participating device to join the mesh network, and sending network information to the participating device, which is valid to enable the participating device to join the mesh network.
[0194] In lieu of, or in addition to, the mesh network system described above, the joiner router is configured to receive beacon requests from participating devices and send beacons to the participating devices, the beacons providing an indication that the mesh network is available for participation, and the beacons are effective in enabling participating devices to establish a local link between the participating device and the joiner router; messages received from participating devices include an encrypted device identifier that can be used to authenticate the participating device, the participating device is authenticated using Juggling Password Authenticated Key Exchange (J-PAKE), and the authentication is effective in establishing a secure communication session between the commissioning device and the participating device; and the joiner router is configured to forward received messages to the commissioning device through one or more routers of the mesh network in the communication path between the joiner router and the commissioning device, one of which is a border router connecting the mesh network to an external network, one or more of these.
[0195] A method for securely joining a device to a mesh network includes the steps of: a joiner router receiving a DTLS-ClientHello message from a participating device requesting to join the mesh network; encapsulating the received DTLS-ClientHello message in a DTLS relay receive notification message; sending the DTLS relay receive notification message to the commissioning device of the mesh network; receiving a DTLS relay send notification message from the commissioning device; and sending the contents of the DTLS relay send notification message to the participating device, the contents of which are valid to enable the participating device to join the mesh network. The method further includes the steps of: receiving an indication from the commissioning device that the participating device should be commissioned to receive network credentials for the mesh network; receiving a key encryption key (KEK) shared between the commissioning device and the participating device from the commissioning device; and, in response to receiving the indication, sending the network credentials from the joiner router to the participating device using the KEK to secure the communication of the network credentials.
[0196] In lieu of, or in addition to, the above-described method, the method further includes the steps of receiving a beacon request from a participating device and sending a beacon from the joiner router to the participating device; the beacon includes a network name and steering data indicating one or more participating devices authorized to join the mesh network; the step of receiving a DTLS-ClientHello message from the participating device utilizes the User Datagram Protocol (UDP); the DTLS relay receive notification message includes the address of the participating device, the address of the joiner router, and the received DTLS-ClientHello message; the DTLS relay send notification message includes the address of the participating device, the address of the joiner router, and the DTLS-HelloVerify message; the step of sending the contents of the DTLS relay send notification message to the participating device is effective in establishing a secure communication session between the commissioning device and the participating device; the secure communication session is available for provisioning the participating device; and the method further includes the step of applying a rate limit to the transmission of DTLS relay receive notification messages sent from the participating device to the commissioning device.
[0197] A mesh network device implemented as a joiner router, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application is configured to receive DTLS-ClientHello messages from participating devices requesting to join the mesh network via the mesh network interface, encapsulate the received DTLS-ClientHello messages in a DTLS relay receive notification message, initiate the transmission of the DTLS relay receive notification message to the commissioning device of the mesh network, receive a DTLS relay send notification message from the commissioning device, initiate the transmission of the contents of the DTLS relay send notification message to the participating device, the contents of which are valid to enable the participating device to join the mesh network, the commissioning application further receives an indication from the commissioning device that the participating device should be commissioned to receive network credentials for the mesh network, receive a key encryption key (KEK) shared between the commissioning device and the participating device from the commissioning device, and in response to the indication, transmit the network credentials To secure the communication, KEK is used to initiate the transmission of network credentials from the joiner router to the participating devices.
[0198] The commissioning application is configured to receive DTLS-ClientHello messages from participating devices via a mesh network interface, either in place of or in addition to the mesh network devices described above, and to initiate the transmission of beacons from the joiner router to the participating devices; the commissioning application is configured to receive DTLS-ClientHello messages from participating devices using the User Datagram Protocol (UDP); the DTLS relay receive notification message includes the address of the participating device, the address of the joiner router, and the received DTLS-ClientHello message; and the DTLS relay send notification message includes the address of the participating device, the address of the joiner router, and the DTLS-HelloVerify message; the contents of the DTLS relay send notification message sent to the participating device are valid for establishing a secure communication session between the commissioning device and the participating device; and the secure communication session is available for provisioning the participating device.
[0199] The mesh network system includes a joiner router and a participant device configured to request to join the mesh network, the joiner router receiving a DTLS-ClientHello message from the participant device requesting to join the mesh network, encapsulating the received DTLS-ClientHello message in a DTLS relay receive notification message, sending the DTLS relay receive notification message to the mesh network's commissioning device, receiving a DTLS relay send notification message from the commissioning device, and sending the contents of the DTLS relay send notification message to the participant device, the contents of which are valid to enable the participant device to join the mesh network, the joiner router further receiving an indication from the commissioning device that the participant device should be commissioned to receive network credentials for the mesh network, receiving a key encryption key (KEK) shared between the commissioning device and the participant device from the commissioning device, and in response to the indication, the joiner router is configured to send the network credentials from the joiner device using the KEK to secure the communication of the network credentials.
[0200] In place of, or in addition to, the above-described mesh network system, the system includes one or a combination of the following: receiving beacon requests from participating devices and sending beacons from the joiner router to participating devices; the beacon includes the network name and steering data indicating one or more participating devices that are permitted to join the mesh network; the joiner router is configured to receive DTLS-ClientHello messages from participating devices using the User Datagram Protocol (UDP); and the DTLS relay receive notification message includes the address of the participating device, the address of the joiner router, and the received DTLS-ClientHello message, and the DTLS relay send notification message includes the address of the participating device, the address of the joiner router, and the DTLS-HelloVerify message.
[0201] The method for authorizing a commissioning device to become a commissioner in order to commission one or more participating devices to join a mesh network involves the following steps: the border router receives an application from the commissioning device to become a commissioner for the mesh network, and the receiving application is authorized by the border router to become a commissioner for the mesh network. The method includes the steps of sending to a reader device and receiving a response from the reader device to the application, the response indicating acceptance or rejection of the application, and the method further includes the step of sending an indication of acceptance or rejection of the application to a commissioning device in response to the step of receiving the response.
[0202] Alternatively, or in addition to the above-described method, the method further includes the step of the border router advertising the availability of the mesh network for the commissioning device, wherein the step of receiving the application means that the commissioning device has responded to receiving the advertisement; the step of the border router further includes the step of receiving from the commissioning device a request to securely connect to the border router; the secure connection is established using Datagram Transport Layer Security (DTLS); the step of sending an indication of acceptance of the application means that a secure commissioning session is established; the step of registering the identity of the commissioning device with the border router in order to establish a secure commissioning communication session means that the registration step means that encrypted commissioning credentials The process includes the step of providing the Border Router with the encrypted commissioning credentials, which are derived from the commissioning credentials entered into the commissioning device by the user; the Border Router includes a copy of the encrypted commissioning credentials that can be used to authenticate the commissioning device to the mesh network; and the copy of the encrypted commissioning credentials was previously derived from the commissioning credentials, which were injected into a mesh network leader device that derived the copy of the encrypted commissioning credentials, and the leader device securely communicated the copy of the encrypted commissioning credentials to the Border Router.
[0203] A mesh network device implemented as a border router, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application is configured to receive an application from a commissioning device via the mesh network interface to become a commissioner for the mesh network to commission one or more participating devices to join the mesh network, to initiate sending the received application to a leader device of the mesh network, to receive a response to the application from the leader device, the response indicating acceptance or rejection of the application, and the commissioning application is further configured to initiate sending an indication of acceptance or rejection of the application to the commissioning device in response to the received response to the application.
[0204] In place of, or in addition to, the aforementioned mesh network devices, the commissioning application is configured to advertise the availability of the mesh network for the commissioning device and to receive applications in response to the commissioning device receiving the advertised availability, with the advertised availability being done using a service discovery protocol including the Multicast Domain Name System (mDNS); the commissioning application is configured to receive requests from the commissioning device for secure connection to the border router, with the secure connection being established using Datagram Transport Layer Security (DTLS); acceptance of the application by the leader device authorizes the commissioning device to become a commissioner for the mesh network, and the leader device updates its internal state tracking the active commissioners for the mesh network. Acceptance of an application that enables this means setting the grant participation flag for the mesh network to true and propagating the commissioning dataset within the mesh network, and the transmitted indication of acceptance of the application means establishing a secure commissioning session; the commissioning application is configured to register the identity of the commissioning device with the border router in order to establish a secure commissioning communication session, including encrypted commissioning credentials provided to the border router, the encrypted commissioning credentials being derived from the commissioning credentials entered into the commissioning device by the user, and the border router having a copy of the encrypted commissioning credentials that can be used to authenticate the commissioning device to the mesh network; the commissioning device and the border router communicate through a network other than the mesh network; and the other network includes either a Wi-Fi network or an Ethernet network, or a combination thereof.
[0205] A mesh network system includes a commissioning device configured to apply to become a commissioner for commissioning one or more participating devices to join the mesh network, and a border router, the border router being configured to receive an application from the commissioning device to become a commissioner for the mesh network, send the received application to the leader device of the mesh network, receive a response to the application from the leader device, the response indicating acceptance or rejection of the application, and the border router being further configured to send the acceptance or rejection indication to the commissioning device.
[0206] In lieu of, or in addition to, the mesh network system described above, the border router is configured to advertise the availability of the mesh network for commissioning devices and to receive applications in response to the commissioning devices receiving the advertisement; the commissioning devices and the border router communicate through a network other than the mesh network; the other network is either a Wi-Fi network or an Ethernet network; and the border router is configured to send an indication of acceptance of an application in order to establish a secure commissioning session, or any one or a combination thereof.
[0207] A method implemented by a mesh network leader device includes the steps of: receiving an application from the leader device to accept a commissioning device as a commissioner for commissioning participating devices to join the mesh network; determining whether to accept or reject the received application; sending a response including an indication of the decision; and updating an internal state that tracks the active commissioner for the mesh network in response to the decision being an acceptance.
[0208] Alternatively, or in addition to the above-described method, the method further includes the step of receiving a command from the commissioning device to initiate join mode for the mesh network; further includes the step of propagating the commissioning dataset within the mesh network; the commissioning dataset includes a commissioner session identifier, a commissioner timestamp, encrypted commissioner credentials, and a security policy indicating which security-related actions are permitted in the mesh network; encrypted from the commissioning credentials injected into the leader device during commissioning of the leader device The commissioning dataset includes one or a combination of the following: further including the step of deriving the encrypted commissioning credentials; the derivation of the encrypted commissioning credentials is performed by applying a key derivation function, the key derivation function performing multiple hashing operations using a cryptographic-based message authentication code (CMAC); further including the step of sending a copy of the encrypted commissioning credentials to the border router, which is valid to enable the border router to authenticate the commissioning device to the mesh network; and, if the commissioner is active on the mesh network, further including the location of the border router.
[0209] A mesh network device implemented as a leader device of a mesh network, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application is configured to receive requests via the mesh network interface to accept the commissioning device as a commissioner for commissioning participating devices to join the mesh network, to determine whether to accept or reject the received request, to initiate sending a response including an indication of the decision to accept or reject the received request, and to update an internal state tracking an active commissioner for the mesh network in response to the decision being to accept the received request.
[0210] In place of, or in addition to, the aforementioned mesh network devices, the commissioning application is configured to receive commands from the commissioning device to initiate join mode for the mesh network; the commissioning application is configured to propagate the commissioning dataset within the mesh network; the commissioning dataset includes a commissioner session identifier, a commissioner timestamp, encrypted commissioner credentials, and a security policy indicating which security-related actions are permitted within the mesh network; and the commissioning application further includes the commissioning data injected into the leader device during the commissioning of the leader device. The commissioning application is configured to derive encrypted commissioning credentials from commissioning credentials, the derivation of which is performed by applying a key derivation function, which hashs multiple times using a cryptographically based message authentication code (CMAC); the commissioning application is configured to send a copy of the encrypted commissioning credentials to the border router, which is effective in enabling the border router to authenticate the commissioning device to the mesh network; and, if the commissioner is active on the mesh network, the commissioning dataset further includes the location of the border router, one or a combination thereof.
[0211] A mesh network system includes a commissioning device configured to apply to become a commissioner for commissioning one or more participating devices to join the mesh network, and a leader device of the mesh network, the leader device receiving applications to accept the commissioning device as a commissioner for commissioning participating devices to join the mesh network, determining whether to accept or reject the received application, sending a response that includes an indication of the decision regarding whether to accept or reject the received application, and tracking an active commissioner for the mesh network in response to the decision being an acceptance. It is configured to update its internal state.
[0212] In lieu of, or in addition to, the aforementioned mesh network system, the leader device is configured to receive commands from the commissioning device to initiate join mode for the mesh network; the leader device is configured to propagate the commissioning dataset within the mesh network; the commissioning dataset includes a commissioner session identifier, a commissioner timestamp, encrypted commissioner credentials, and a security policy indicating which security-related actions are permitted within the mesh network; and the leader device further propagates the commissioning credentials injected into the leader device during the leader device's commissioning. The commissioning dataset includes one or a combination of the following: it is configured to derive encrypted commissioning credentials from a densial, the derivation of which is performed by applying a key derivation function, which hashs multiple times using a cryptographic-based message authentication code (CMAC); the leader device is configured to send a copy of the encrypted commissioning credentials to the border router, which is valid to enable the border router to authenticate the commissioning device to the mesh network; and, if the commissioner is active on the mesh network, the commissioning dataset further includes the location of the border router.
[0213] A method for securely establishing a network communication session to allow one or more participating devices to join a mesh network includes the steps of: establishing a secure commissioning communication session between the mesh network's commissioning device and the border router; initiating participation for the mesh network; the commissioning device receiving a request from one of the participating devices to join the mesh network; establishing a secure joiner communication session between the commissioning device and the participating device; and allowing the participating device to join the mesh network.
[0214] Alternatively, or in addition to, the steps for establishing a secure commissioning communication session include: sending an application from the commissioning device to the leader device of the mesh network to request acceptance of the commissioning device as an active commissioner for the mesh network; and receiving an indication of acceptance of the application from the leader device; initiating participation for the mesh network includes the commissioning device initiating a participation mode that causes one or more routers in the mesh network to advertise that the mesh network has accepted participation requests; and initiating participation for the mesh network includes sending an administrative message to the leader device to make the mesh network participateable, the administrative message being sent to the leader device The method is effective in enabling the device to update network data for a mesh network and propagate the network data to one or more router devices in the mesh network, wherein the network data includes an indication that the mesh network is available for participation; further including a step of authenticating a participating device using an encrypted device identifier; the method further includes a step of receiving a request from one of the participating devices to join the mesh network, which is received via the joiner router, and the method further includes a step of sending an indication to the joiner router that the participating device should be commissioned to receive network credentials for the mesh network and a key encryption key (KEK) shared between the commissioning device and the participating device, which the joiner router receives The KEK is effective in securely transmitting network credentials to participating devices and enabling the participating devices to be commissioned to a mesh network; the step of receiving a request from a participating device includes the step of receiving an encrypted device identifier of the participating device, the encrypted device identifier being derived from the device identifier of the participating device using Juggling Password Authenticated Key Exchange (J-PAKE); and the step of establishing a secure joiner communication session includes one or a combination of the following: the commissioning device determines from a copy of the device identifier received from the participating device that the encrypted device identifier received from the participating device matches the encrypted device identifier derived by the commissioning device, and the step of using the encrypted device identifier as a shared secret to secure the joiner communication session.
[0215] A mesh network device is implemented as a commissioning device for getting one or more participating devices to join a mesh network, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application is configured to establish a secure commissioning communication session between the commissioning device and the border router of the mesh network, initiate participation for the mesh network, receive a request to join the mesh network from one of the participating devices via the mesh network interface, establish a secure joiner communication session between the commissioning device and the participating device, and get the participating device to join the mesh network.
[0216] In place of, or in addition to, the aforementioned mesh network devices, the commissioning application is configured to send a request from the commissioning device to the leader device of the mesh network to request acceptance of the commissioning device as an active commissioner for the mesh network, and to receive an indication of acceptance of the request from the leader device; the commissioning application is configured to initiate participation for the mesh network by initiating participation mode, which causes one or more routers in the mesh network to advertise that the mesh network has accepted the participation request; the commissioning application is configured to initiate participation for the mesh network by sending an administrative message to the leader device to make the mesh network available, which causes the leader device to update the network data for the mesh network and to inform one or more router devices in the mesh network that the network data is available. The following conditions apply: Network data can be propagated, and the network data includes an indication that the mesh network is available for joining; requests received from joining devices include the encrypted device identifier of the joining device, which is derived from the device identifier of the joining device using Juggling Password Authenticated Key Exchange (J-PAKE); the commissioning application is configured to determine from a copy of the device identifier received from the joining device that the encrypted device identifier received from the joining device matches the encrypted device identifier derived by the commissioning device, and to establish a secure joiner communication session, further configured to use the encrypted device identifier as a shared secret to secure the joiner communication session; the commissioning application is configured to forward requests from joining devices to join the mesh network, and the request is one or more in the mesh network. This includes one or a combination of the following: forwarding to the commissioning device by the router device.
[0217] A mesh network system includes one or more participating devices configured to request participation in the mesh network, and a commissioning device for the mesh network, the commissioning device is configured to establish a secure commissioning communication session between the commissioning device and the border router of the mesh network, initiate participation for the mesh network, receive a request to join the mesh network from one of the participating devices, establish a secure joiner communication session between the commissioning device and the participating device, and allow the participating device to join the mesh network.
[0218] In lieu of, or in addition to, the aforementioned mesh network system, the commissioning device is configured to send a request from the commissioning device to the leader device of the mesh network to request acceptance of the commissioning device as an active commissioner for the mesh network in order to establish a secure commissioning communication session, and to receive an indication of acceptance of the request from the leader device; the commissioning device is configured to initiate participation for the mesh network by initiating a participation mode that causes one or more routers in the mesh network to advertise that the mesh network has accepted a participation request; the commissioning device is configured to initiate participation for the mesh network by sending an administrative message to the leader device to make the mesh network available, the administrative message being, The following are included, or a combination thereof: a leader device updates network data for a mesh network and enables the network data to propagate to one or more router devices in the mesh network, the network data includes an indication that the mesh network is available for joining; a commissioning device is configured to receive a request from one of the participating devices to join the mesh network via a joiner router, and the participating device is to send an indication to the joiner router that it should be commissioned to receive network credentials for the mesh network and a key encryption key (KEK) shared between the commissioning device and the participating device, the transmitted indication enables the joiner router to securely transmit the network credentials to the participating device using the received KEK, thereby commissioning the participating device to the mesh network.
[0219] A method for provisioning participating devices in a mesh network includes the steps of establishing a commissioning communication session between a commissioning device and a border router of the mesh network, establishing a joiner communication session between a participating device and the commissioning device, and transmitting commissioning information to the participating device, the commissioning information being available to the participating device for joining the mesh network. The method further includes the steps of receiving a location indication of the commissioner application from the participating device, and running the commissioner application to provision the participating device.
[0220] Alternatively, or in addition to the above method, the method further includes the step of using the received indication to search for the commissioner application; the received indication of the commissioner application's location is a uniform resource locator (URL); the commissioner application is accessed via the internet through the cloud The service is searchable; the commissioning device uses the received URL to determine whether the commissioner application is stored in the commissioning device's memory; the service further includes a step of terminating the commissioning of a participating device in response to the completion of provisioning the participating device, the terminating step being effective in enabling the participating device to join the mesh network; provisioning of a participating device includes updating the software on the participating device; provisioning of a participating device includes linking the participating device to a user account on the cloud service; provisioning of a participating device includes configuring the participating device; and the configuration is a local configuration related to other devices in the mesh network, one or a combination thereof.
[0221] A mesh network device implemented as a commissioning device, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application being configured to establish a commissioning communication session between the commissioning device and the border router of the mesh network, establish a joiner communication session between participating devices and the commissioning device, and transmit commissioning information to participating devices, the commissioning information being available to participating devices for joining the mesh network, and the commissioning application being further configured to receive an indication of the location of the commissioner application from the participating devices and to run the commissioner application in order to provision the participating devices.
[0222] In place of, or in addition to, the aforementioned mesh network devices, the commissioning application is configured to use received indications to locate the commissioner application; the received indication of the commissioner application's location is a uniform resource locator (URL); the commissioner application is searched for from cloud services over the internet; and the commissioning device uses the received URL to determine whether the commissioner application is stored in the commissioning device's memory. This includes one or a combination of these.
[0223] A mesh network system includes a participant device configured to request participation in the mesh network, and a commissioning device for the mesh network, the commissioning device being configured to establish a commissioning communication session between the commissioning device and the mesh network's border routers, establish a joiner communication session between the participant device and the commissioning device, and send commissioning information to the participant device, which is available to the participant device for joining the mesh network, and the commissioning device is further configured to receive an indication of the location of the commissioner application from the participant device and run the commissioner application to provision the participant device.
[0224] In lieu of, or in addition to, the aforementioned mesh network system, the commissioning application is configured to use received indications to locate the commissioner application; the received indications of the commissioner application's location are used by the uniform resource locator (URL). This includes one or a combination of the following: the commissioner application is retrieved from a cloud service via the internet; and the commissioning device uses the received URL to determine whether the commissioner application is stored in the commissioning device's memory.
[0225] A method for identifying devices permitted to join a mesh network includes the step of obtaining steering data for the mesh network, the steering data including a representation of a device identifier associated with a device permitted to join the mesh network, the method further includes the step of propagating the steering data from a commissioning device for the mesh network to one or more routers in the mesh network, the propagation step enabling one or more routers to transmit the steering data in a beacon message, the steering data is effective in enabling a device associated with a device identifier to identify that the device is permitted to join the mesh network.
[0226] Alternatively, or in addition to, the steering data includes one or a combination thereof: the steering data includes a 16-bit cyclic redundancy check (CRC16) of the device identifier; the device identifier is an IEEE 64-bit extended unique identifier (EUI-64); the step of obtaining the steering data for the mesh network further includes a step of obtaining steering data for additional device identifiers associated with additional devices that are permitted to participate in the mesh network; the step of propagating the steering data is effective in enabling devices to distinguish the mesh network from other networks; the other networks are IEEE 802.15.4 networks; and the steering data indicates that the commissioner is active on the mesh network.
[0227] A mesh network device implemented as a commissioning device, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application configured to request steering data for the mesh network, the steering data including an indication of a device identifier associated with a device authorized to join the mesh network, the commissioning application further configured to propagate the steering data from the commissioning device for the mesh network to one or more routers in the mesh network, the propagation enabling one or more routers to transmit the steering data in beacon messages, the steering data being effective in enabling a device associated with a device identifier to identify that the device is authorized to join the mesh network.
[0228] In place of, or in addition to, the mesh network devices described above, the steering data includes a 16-bit cyclic redundancy check (CRC16) of the device identifier; the device identifier is an IEEE 64-bit extended unique identifier (EUI-64); the commissioning application is configured to request steering data for additional device identifiers associated with additional devices permitted to join the mesh network in order to request steering data for the mesh network; the steering data is available to devices to distinguish the mesh network from other networks; other networks are IEEE 802.15.4 networks; and The steering data includes one or a combination of the following: that the commissioner is active on the mesh network.
[0229] A mesh network system includes a participating device configured to request participation in the mesh network, and a commissioning device for the mesh network, the commissioning device being configured to request steering data for the mesh network, the steering data including an indication of a device identifier associated with a device permitted to participate in the mesh network, the commissioning device being further configured to propagate the steering data from the commissioning device for the mesh network to one or more routers in the mesh network, the propagation enabling one or more routers to send the steering data as a beacon message, the steering data being useful in enabling a device associated with a device identifier to identify that the device is permitted to participate in the mesh network.
[0230] In lieu of, or in addition to, the mesh network system described above, the steering data includes one or a combination of the following: 16-bit cyclic redundancy check (CRC16) of the device identifier; the device identifier is an IEEE 64-bit extended unique identifier (EUI-64); the commissioning device is configured to request steering data for additional device identifiers associated with additional devices permitted to join the mesh network in order to request steering data for the mesh network; the steering data enables devices to distinguish between the mesh network and other networks; and the steering data indicates that the commissioner is active on the mesh network.
[0231] A method for identifying devices permitted to join a mesh network includes the step of obtaining steering data for the mesh network, the steering data including a representation of a device identifier associated with a device permitted to join the mesh network, the representation being represented as a set of values in a Bloom filter representing the device identifier, the method further includes the step of propagating the steering data from a commissioning device for the mesh network to one or more routers in the mesh network, the propagation step enabling one or more routers to transmit the steering data in a beacon message, the steering data enabling a device associated with a device identifier to identify that the device is permitted to join the mesh network by comparing a set of values in a Bloom filter with a second set of values obtained by the device.
[0232] Alternatively, or in addition to, the steps for obtaining steering data include: applying a first hash function to the device identifier to generate a first hash value; applying a second hash function to the device identifier to generate a second hash value; performing a modulo operation on the first hash value to determine the first bit field position in the Bloom filter; performing a modulo operation on the second hash value to determine the second bit field position in the Bloom filter; setting the value at the first bit field position in the Bloom filter to 1; and setting the value at the second bit field position in the Bloom filter to 1; the first and second hash functions are cyclic redundancy checks (CRC), the first hash function being CRC16-CCITT and the second hash function being CRC16-ANSI; the divisor for the modulo operation being the length of the bit array of the Bloom filter; and the device identifier being IEEE 64-bit extended. The process includes one or a combination of the following: the device identifier is a unique EUI-64; the device identifier is the least significant 24 bits of the EUI-64; the step of obtaining steering data for a mesh network further includes a step of obtaining steering data for additional device identifiers associated with additional devices that are permitted to join the mesh network; the step of setting the value of the steering data to a value of 0 to prevent participation in the mesh network; and the step of setting all bit field values in the steering data to a value of 1 to indicate that the mesh network is open to any device.
[0233] A mesh network device implemented as a commissioning device, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application configured to request steering data for the mesh network, the steering data including a representation of a device identifier associated with a device permitted to join the mesh network, the representation being represented as a set of values in a Bloom filter representing the device identifier, the commissioning application further configured to propagate the steering data to one or more routers in the mesh network, the propagation being effective in enabling one or more routers to send the steering data in beacon messages, the steering data enabling a device associated with a device identifier to identify that the device is permitted to join the mesh network by comparing a set of values in a Bloom filter with a second set of values requested by the device.
[0234] In place of, or in addition to, the mesh network device described above, the commissioning application is configured to apply a first hash function to a device identifier to generate a first hash value, apply a second hash function to a device identifier to generate a second hash value, perform a modulo operation on the first hash value to determine the first bit field position in the Bloom filter, perform a modulo operation on the second hash value to determine the second bit field position in the Bloom filter, set the value at the first bit field position in the Bloom filter to 1, and set the value at the second bit field position in the Bloom filter to 1; the first and second hash functions are cyclic redundancy checks (CRCs), with the first hash function being CRC16-CCITT and the second hash function being CRC16-ANSI; and the divisor for the modulo operation is the length of the bit array of the Bloom filter; and the device identifier is an IEEE 64-bit Extended Unique Identifier (EUI-64).
[0235] A mesh network system includes a participating device configured to request participation in the mesh network, and a commissioning device, the commissioning device configured to request steering data for the mesh network, the steering data including a representation of a device identifier associated with a device permitted to participate in the mesh network, the representation being represented as a set of values in a Bloom filter representing the device identifier, the commissioning device further configured to propagate the steering data to one or more routers in the mesh network, the propagation being effective in enabling one or more routers to send the steering data in beacon messages, the steering data being a set of values in a Bloom filter obtained by the device associated with the device identifier, and a second set of values obtained by the device. In comparison, this allows the device to be identified as being permitted to join the mesh network.
[0236] In place of, or in addition to, the above-described mesh network system, the commissioning device is configured to apply a first hash function to a device identifier to generate a first hash value, apply a second hash function to a device identifier to generate a second hash value, perform a modulo operation on the first hash value to determine the first bit field position in the Bloom filter, perform a modulo operation on the second hash value to determine the second bit field position in the Bloom filter, set the value at the first bit field position in the Bloom filter to 1, and set the value at the second bit field position in the Bloom filter to 1. The following are included, or a combination thereof: the first and second hash functions are cyclic redundancy checks (CRCs), with the first hash function being CRC16-CCITT and the second hash function being CRC16-ANSI; the divisor for the modulo operation is the length of the bit array of the Bloom filter; the device identifier is an IEEE 64-bit Extended Unique Identifier (EUI-64); and the commissioning device is configured to request steering data for additional device identifiers associated with additional devices permitted to join the mesh network in order to request steering data for the mesh network.
[0237] A method for updating commissioning data at a node in a mesh network includes the steps of: receiving a commissioning dataset at a node device in the mesh network; comparing a timestamp contained in the received commissioning dataset with a stored timestamp contained in a commissioning dataset stored at the node device; determining from the comparison that the stored timestamp is more recent than the received timestamp; and sending a message to a leader device in the mesh network in response to the determination, the message including the stored commissioning dataset, which is useful for enabling the leader device to accept the stored commissioning dataset as the most recent commissioning dataset for the mesh network and propagate the stored commissioning dataset to the mesh network.
[0238] Alternatively, or in addition to the above-described method, the method further includes the step of determining from the comparison step that the received timestamp is more recent than the stored timestamp, and in response to the step of determining that the received timestamp is more recent than the stored timestamp, updating the stored commissioning dataset to match the received commissioning dataset; the received commissioning dataset includes the received timestamp, commissioning credentials, the network name of the mesh network, and security policies indicating which security-related actions are permitted in the mesh network; the received timestamp The imstamp includes a time value and an indication that the time value is traceable to Coordinated Universal Time (UTC); node devices and leader devices were previously commissioned to the mesh network, and the previous commissioning stored the same commissioning dataset in the node devices and leader devices; the stored commissioning dataset in the node devices is updated after the mesh network splits, and the split separates the mesh network into multiple sections, with the first section of the mesh network containing leader devices and the second section of the mesh network containing node devices; the split stops communication between node devices and leader devices on the mesh network. The steps include: the node device receiving the commissioning dataset occurring after the merger of the first and second sections of the mesh network, the merger re-establishing the communication path between the node device and the leader device on the mesh network; and the node device being either a router device or a router-eligible device, or a combination thereof.
[0239] A mesh network device implemented as a router, the mesh network device includes a mesh network interface configured for communication in the mesh network, and a memory and processor system for implementing a commissioning application, the commissioning application being configured to receive a commissioning dataset, compare the timestamp contained in the received commissioning dataset with a stored timestamp contained in a commissioning dataset stored in the router, determine from the comparison that the stored timestamp is more recent than the received timestamp, and in response to the determination, send a message to the mesh network leader device, the message including the stored commissioning dataset, which is useful for the leader device to accept the stored commissioning dataset as the most recent commissioning dataset for the mesh network and propagate the stored commissioning dataset to the mesh network.
[0240] In place of, or in addition to, the aforementioned mesh network device, the commissioning application is configured to determine from comparison that the received timestamp is more recent than the stored timestamp, and in response to this determination that the received timestamp is more recent than the stored timestamp, to update the stored commissioning dataset to match the received commissioning dataset; the received commissioning dataset contains the received timestamp, the commissioning credentials, the network name of the mesh network, and a set of security-related actions that indicate which actions are permitted in the mesh network. The following conditions must be met or be met: the security policy must be included; the received timestamp must include a time value and an indication that the time value is traceable to Coordinated Universal Time (UTC); the routers and leader devices must have been previously commissioned to the mesh network, and the previous commissioning must have stored the same commissioning dataset in the routers and leader devices; and the stored commissioning dataset in the routers must be updated after the split of the mesh network, and the split must divide the mesh network into multiple sections, the first section of the mesh network must include leader devices, and the second section of the mesh network must include routers.
[0241] A mesh network system includes a leader device and a router device configured to maintain commissioning data for the mesh network, the router device receiving a commissioning dataset, comparing the timestamp contained in the received commissioning dataset with a stored timestamp contained in a commissioning dataset stored in the router, determining from the comparison that the stored timestamp is more recent than the received timestamp, and in response to this determination, sending a message to the mesh network's leader device, the message containing the stored commissioning dataset, which is useful for the leader device to accept the stored commissioning dataset as the most recent commissioning dataset for the mesh network and propagate the stored commissioning dataset to the mesh network.
[0242] In lieu of, or in addition to, the mesh network system described above, the router device is configured to determine from comparison that a received timestamp is more recent than a stored timestamp, and in response to this determination that the received timestamp is more recent than a stored timestamp, to update the stored commissioning dataset to match the received commissioning dataset; the received commissioning dataset includes the received timestamp, commissioning credentials, the network name of the mesh network, and security policies indicating which security-related actions are permitted in the mesh network; the received timestamp includes a time value and an indication that the time value is traceable to Coordinated Universal Time (UTC); and the router and reader devices have previously been commissioned to the mesh network, and the previous commissioning stored the same commissioning dataset in the router and reader devices, or a combination thereof.
Claims
1. A method for securely involving a device in a mesh network, wherein the method is: The steps include: receiving beacon requests from participating devices at the joiner router, The steps include receiving a message from a participating device requesting to join the mesh network, The steps include: forwarding the received message to the commissioning device of the mesh network, The process includes the step of transmitting network information received from the commissioning device to the participating devices, Network information is a useful method for enabling participating devices to join a mesh network.
2. The step of receiving a beacon request further includes the step of sending a beacon from the joiner router to the participating device in response to the step of receiving a beacon request, The method according to claim 1, wherein the beacon provides an indication that the mesh network is available for participation.
3. The method according to claim 2, wherein the step of transmitting the beacon is effective in enabling a participating device to establish a local link between the participating device and the joiner router.
4. The method according to any one of claims 1 to 3, wherein the steps of receiving the message and transferring the received message are performed using datagram transport layer security (DTLS).
5. The method according to any one of claims 1 to 3, wherein the steps of receiving the message and transferring the received message are performed using the User Datagram Protocol (UDP).
6. Messages received from participating devices include encrypted device identifiers that can be used to authenticate the participating devices. Participating devices are authenticated using Juggling-based password-authenticated key exchange (J-PAKE). The method according to any one of claims 1 to 3, wherein authentication is effective in establishing a secure communication session between a commissioning device and a participating device.
7. The method according to any one of claims 1 to 3, wherein the step of forwarding the received message to the commissioning device includes the step of forwarding the received message through one or more routers of the mesh network in the communication path between the joiner router and the commissioning device.
8. The method according to claim 7, wherein one of the one or more routers is a border router that connects the mesh network to an external network, and the commissioning device is attached to the external network.
9. A mesh network device implemented as a joiner router, and the mesh network device is A mesh network interface configured for communication in a mesh network, It includes a memory and processor system for implementing the commissioning application, and the commissioning application is It receives beacon requests from participating devices via the mesh network interface. Receive a message from a participating device requesting to join the mesh network. The received message is forwarded to the commissioning device of the mesh network. It is configured to send network information received from the commissioning device to participating devices. Network information is useful for mesh network devices, enabling participating devices to join the mesh network.
10. The commissioning application is It is configured to initiate the transmission of a beacon from the joiner router to participating devices in response to the receipt of a beacon request. The mesh network device according to claim 9, wherein the beacon provides an indication that the mesh network is available for participation.
11. The mesh network device according to claim 10, wherein the beacons are effective in enabling participating devices to establish a local link between participating devices and joiner routers.
12. The mesh network device according to any one of claims 9 to 11, wherein the commissioning application is configured to receive messages using Datagram Transport Layer Security (DTLS) and to forward the received messages.
13. The mesh network device according to any one of claims 9 to 11, wherein the commissioning application is configured to receive messages using the User Datagram Protocol (UDP) and to forward the received messages.
14. Messages received from participating devices include encrypted device identifiers that can be used to authenticate the participating devices. Participating devices are authenticated using Juggling-based password-authenticated key exchange (J-PAKE). The mesh network device according to any one of claims 9 to 11, wherein authentication is effective in establishing a secure communication session between a commissioning device and participating devices.
15. The mesh network device according to any one of claims 9 to 11, wherein the commissioning application is configured to forward received messages through one or more routers of the mesh network in the communication path between the joiner router and the commissioning device.
16. The mesh network device according to claim 15, wherein one of the one or more routers is a border router that connects the mesh network to an external network, and the commissioning device is attached to the external network.
17. A mesh network system, A participating device configured to request to join a mesh network, Includes a joiner router, and the joiner router is Upon receiving a beacon request from a participating device, Receive a message from a participating device requesting to join the mesh network. The received message is forwarded to the commissioning device of the mesh network. It is configured to send network information received from the commissioning device to participating devices. Network information is useful for a mesh network system, enabling participating devices to join the mesh network.
18. The joiner router is It is configured to send a beacon to participating devices in response to receiving a beacon request. The mesh network system according to claim 17, wherein the beacon provides an indication that the mesh network is available for participation, and the beacon is effective in enabling participating devices to establish a local link between the participating device and the joiner router.
19. Messages received from participating devices include encrypted device identifiers that can be used to authenticate the participating devices. Participating devices are authenticated using Juggling-based password-authenticated key exchange (J-PAKE). The mesh network system according to claim 17 or 18, wherein authentication is effective in establishing a secure communication session between a commissioning device and participating devices.
20. The mesh network system according to claim 17 or 18, wherein the joiner router is configured to forward received messages to the commissioning device through one or more routers of the mesh network in the communication path between the joiner router and the commissioning device, and one of the routers is a border router that connects the mesh network to an external network.