Provisioning a device of a network

The provisional authentication mechanism in mesh networks uses a shared product identifier and temporal information to securely and efficiently determine device eligibility, reducing external communications and enhancing security against unauthorized access and attacks.

WO2025153436A1PCT designated stage expired Publication Date: 2025-07-24SIGNIFY HOLDING BV
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/050673
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-14
Filing Date
2025-01-13
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing network provisioning methods for devices, particularly in mesh networks, face challenges in ensuring security and reducing the number and size of communications to minimize resource consumption and mitigate risks of denial-of-service attacks.

Method used

A provisional authentication mechanism within the mesh network determines whether a new device is permitted to join or be provisioned using a shared product identifier and temporal information, employing different communication protocols for internal and external communications to reduce external communications and enhance security.

Benefits of technology

This approach enhances network security by minimizing external communications, reducing resource consumption, and mitigating risks of unauthorized access and denial-of-service attacks while ensuring efficient provisioning of devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025050673_24072025_PF_FP_ABST
    Figure EP2025050673_24072025_PF_FP_ABST
Patent Text Reader

Abstract

A mechanism for provisioning a device using a (mesh) network. A device that wishes to be provisioned by and / or connect to the network broadcasts a first communication containing information responsive to a first product identifier. A network device processes the information to determine whether the broadcasting device is permitted to join the network and / or be otherwise provisioned. Responsive to a positive determination, a communication is sent to a provisioning server, external to the network, to generate provisioning information for the originally broadcasting device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] PROVISIONING A DEVICE OF A NETWORK

[0002] FIELD OF THE INVENTION

[0003] The present invention relates to the field of network communications, and in particular to the provisioning of devices in a network.

[0004] BACKGROUND OF THE INVENTION

[0005] Networks, such as mesh networks, are commonly used to facilitate communication between devices. The use of (mesh) networks is becoming of increasing interest for a broad range of use-case scenarios. One example scenario is a hybrid lighting network architecture, in which luminaire or lighting devices will comprise a communication module that acts as a mesh network device of the mesh network.

[0006] In general, a mesh network comprises a mesh of mesh network devices that are able to communicate with one another using a shared communication protocol, such as Bluetooth, ZigBee or Lo-Fi. Examples of communication protocols are well known to the skilled person, and are typically radiofrequency communication protocols.

[0007] There are a variety of different types of mesh network devices, including gateway devices (which are able to communicate outside of the mesh network), mesh routers (which are able to route communications within the mesh network) and endpoint devices (which are only able to directly communicate with a mesh router). In some circumstances, a gateway device may also be able to function as a mesh router.

[0008] When a new device wishes to join the mesh network, there is a desire that they should be automatically provisioned (e.g., to facilitate secure communications). Typically, a new device will broadcast a beacon communication, including a device identifier, that is picked up by one of the mesh network devices. The device identifier will then be routed to an external provisioning server via a gateway device. The provisioning server (outside of the mesh network) will authenticate the new device using the device identifier, and produce provisioning information if authentication is successful. The provisioning information is then routed to the new device, via the gateway device, for joining the new device to the mesh network - e.g., during a mutual authentication process. The gateway device (or mesh router) may be able to function as a provisioner for the new device. US2019357043A1 discloses a solution for Bluetooth mesh network provisioning authentication, in which a server performs authentication for Bluetooth devices via Bluetooth gateways that have detected the Bluetooth devices.

[0009] US2020389490A1 discloses an solution for preventing man-in-the-middle attacks for transactions. An access device may receive, from one or more beacon transmitters, a plurality of broadcast messages, each broadcast message comprising a timestamp and a unique identifier for a beacon transmitter. The access device may store the timestamps and the unique identifiers. The access device may receive, from a user device, an access request comprising timestamps and unique identifiers corresponding to a subset of the broadcast messages received by the access device. The access device may verify that the stored timestamps and unique identifiers match the timestamps and unique identifiers received from the user device. Based on the verifying, the access device may authenticate the access request.

[0010] There is an ongoing desire to improve the security of the network and / or reduce a number and / or size of communications for improved operational efficiency.

[0011] SUMMARY OF THE INVENTION

[0012] The invention is defined by the claims.

[0013] According to examples in accordance with an aspect of the invention, there is provided a computer-implemented method for selectively identifying a first device to a provisioning server.

[0014] The computer-implemented method comprises: receiving, at a network device of a network, a first communication, over a first communication channel, from the first device, wherein the first communication contains first information responsive to a first product identifier; processing, at only the network device, the first information to determine whether or not the first device is permitted to be provisioned by the network device; and only responsive to determining that the first device is permitted to be provisioned by the network device, sending a second communication over a second communication channel to the provisioning server, wherein the second communication identifies the first device to the provisioning server. The first and second communication channels employ different communication protocols.

[0015] The proposed approach provides a mechanism for determining within the network itself whether or not a new device is permitted to be provisioned. This avoids reporting of an attempted provisioning by an unauthorized device outside of the network, thereby reducing use of the second communication channel or second communication protocol - which may otherwise consume significant processing resource (e.g., power and / or memory usage). This approach can also reduce a risk of DoS attacks to the provisioning server.

[0016] In the proposed approach, a network device processes a communication from a device wishing to join or be otherwise provisioned by the network. The network device decides whether or not the device is permitted to join or otherwise be provisioned by the network based on information contained in the communication (e.g., alone). In this way, the network device effectively performs a provisional authentication of the device that wishes to join. This provisional authentication approach does not need to perform multiple rounds of communication (e.g., key exchanges) in order to be performed. Rather, the provisional authentication may be performed using only the first communication.

[0017] Proposed approaches are particularly useful when the network is a mesh network, such that the network device is a mesh network device. This is because provisioning of a first device to the network can be performed via a plurality of different nodes or routers of the mesh network.

[0018] The processing of the first information comprises determining whether or not the first product identifier matches a second product identifier stored by the network device. This approach effectively relies upon a shared product identifier, such as a product key, being included with each device that is permitted to form part of the network. The network device can effectively act to determine or decide whether or not the first device contains or carries this shared product identifier as part of the determination process as to whether or not the first device is permitted to be provisioned.

[0019] The first information may comprise a hashing result of processing at least the first product identifier using a hashing algorithm. Using a hashing result effectively acts to encode the first product identifier, thereby avoids or reducing a risk of an authorized device gaining access to the first product identifier - e.g., using interception, packet sniffing or the like. Thus, a security of the network is significantly improved.

[0020] The first product identifier and the second product identifier may be defined during manufacture of the first device and the network device. This provides the common product identifier for use by all devices that are permitted to form part of the network. Defining the product identifier during manufacture significantly reduces a risk of an unauthorized device gaining access to the product identifier (e.g., using packet sniffing or the like). The first communication may further contain first temporal information produced by the first device. The first temporal information may be processed by the networking device as part of the procedure for determining whether or not the first device is permitted to join or be provisioned by the network. The first temporal information introduces a time-based consideration into the determination of whether or not the first device is permitted to join.

[0021] The processing the first information may comprise: producing, at the network device, second temporal information; and determining whether or not a similarity between the first temporal information and the second temporal information meets one or more predetermined conditions.

[0022] In particular examples, the first temporal information comprises a first timestamp and the second temporal information comprises a second timestamp.

[0023] In some examples, the one or more predetermined conditions includes a condition that a difference between the first timestamp and the second timestamp is less than a predetermined value. This approach helps ensure that the first communication is a fresh or newly generated communication, to minimize or mitigate against the risk of a replay attack by an unauthorized device.

[0024] In some examples, the network device of the network is a gateway device of the network.

[0025] The method may comprise, only responsive to determining that the first device is not permitted to be provisioned by the network device, discarding the first communication. This reduces storing or retaining communications that are not required, thereby saving on memory space.

[0026] In some examples, the method comprises preventing the sending of any communication from the network device to the first device at least until after determining that the first device is permitted to be provisioned by the network device. This approach recognizes that it is possible to perform provisional authentication of the first device without needing to directly communicate with the first device. This approach can advantageously avoid processing and / or resource depletion (e.g., power usage), whilst also reducing a risk of a brute force attack by an authorized device. In particular, as the first device will not receive any response from the network device if provisional authentication fails, then the first device will not be able to respond to a communication in an effort to brute force provisioning from the network. The first communication channel may be a radiofrequency communication channel.

[0027] There is also provided a computer program product comprising computer program code means which, when executed on a computing device having a processing system, cause the processing system to perform all of the steps of the method. The processing system may, in this embodiment, comprise at least the network device of the network. Optionally, the processing system comprises one or more other devices of the network (e.g., all the devices of the network). The processing system may comprise the provisioning server. The precise makeup of the processing system will depend upon the steps of the method employed by the processing system.

[0028] There is also provided a computer-implemented method for provisioning a first device, the computer-implemented comprising: performing any previously disclosed method; receiving, at the network device of the network, provisioning information from the provisioning server; and provisioning the first device using the provisioning information.

[0029] There is also provided a network device, for a network, for selectively identifying a first device to a provisioning server. The network device is configured to: receive a first communication, over a first communication channel, from the first device, wherein the first communication contains first information responsive to a first product identifier; process the first information to determine whether or not the first device is permitted to be provisioned by the network device; and only responsive to determining that the first device is permitted to be provisioned by the network device, send a second communication over a second communication channel to the provisioning server, wherein the second communication identifies the first device to the provisioning server.

[0030] The first and second communication channels employ different communication protocols.

[0031] The network device may be further configured to: receive provisioning information from the provisioning server; and provision the first device using the provisioning information.

[0032] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiment s) described hereinafter.

[0033] BRIEF DESCRIPTION OF THE DRAWINGS

[0034] For a better understanding of the invention, and to show more clearly how it may be carried into effect, reference will now be made, by way of example only, to the accompanying drawings, in which:

[0035] Fig. 1 illustrates a mesh network environment;

[0036] Fig. 2 is a flowchart illustrating a proposed method;

[0037] Fig. 3 is a flowchart illustrating another proposed method; and

[0038] Fig. 4 illustrates a flow of communications between devices.

[0039] DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] The invention will be described with reference to the Figures.

[0041] It should be understood that the detailed description and specific examples, while indicating exemplary embodiments of the apparatus, systems and methods, are intended for purposes of illustration only and are not intended to limit the scope of the invention. These and other features, aspects, and advantages of the apparatus, systems and methods of the present invention will become better understood from the following description, appended claims, and accompanying drawings. It should be understood that the Figures are merely schematic and are not drawn to scale. It should also be understood that the same reference numerals are used throughout the Figures to indicate the same or similar parts.

[0042] The disclosure provides a mechanism for provisioning a device using a (mesh) network. A device that wishes to be provisioned by and / or connect to the (mesh) network broadcasts a first communication containing information responsive to a first product identifier. A (mesh) network device processes the information to determine whether the broadcasting device is permitted to join the (mesh) network and / or be otherwise provisioned. Responsive to a positive determination, a communication is sent to a provisioning server, external to the (mesh) network, to generate provisioning information for the originally broadcasting device.

[0043] Embodiments are based on the realization that is would be advantageous to perform a provisional authentication check for a potential new device within the (mesh) network before communicating outside of the network to provision the potential new device. In particular, this would significantly reduce resource and power expensive communications outside of the network and reduce a risk of the network contributing to a denial-of-service (DoS) attack on a provisioning server.

[0044] The disclosure also recognizes further potential routes of attack by an authorized potential new device that can be mitigated using herein proposed techniques. Embodiments are disclosed in the context of a mesh network. However, the herein proposed approach and techniques can be applied for use with any form of network, e.g., non-mesh networks and the like.

[0045] Figure 1 illustrates a mesh network environment 100 in which disclosed approaches may be employed. The mesh network environment 100 comprises a (e.g., wireless) mesh network 110, which is formed from a mesh of mesh network devices 111, 112, 113, 114, 115. The mesh network devices are able to communicate with one another using a same, shared communication protocol. There are a wide variety of mesh network communication protocols, such as that defined by the standard IEEE 802.1 Is, Bluetooth, ZigBee or Lo-Fi. Thus, conceptually, there may be an internal communication protocol for use in communicating between devices of the mesh network.

[0046] It will be appreciated that each mesh network device represents a node in the mesh network 110, such that any mesh network device may be alternatively referred to as a node.

[0047] The mesh network 110 will comprise at least one gateway device 111, which may be alternatively labelled a proxy device. Each gateway device I l l is able to communicate with (external) devices, such as a provisioning server 150, outside of the mesh network, e.g., over the internet 155 or the like. Thus, the gateway device is able to communicate using at least two different communication protocols, including at least the internal communication protocol and an external communication protocol (for use in communicating with one or more devices external to the mesh network 110). The gateway device 111 may, for instance, be a mobile device (such as a smartphone, tablet or laptop) or other dedicated device.

[0048] The mesh network 110 may comprise one or more mesh routers 112, 113. Mesh routers are able to route communications within the mesh network. In some examples, each or any gateway device 111 may be able to perform the function(s) of a mesh router.

[0049] The mesh network 110 may also comprise one or more endpoint devices 114, 115. An endpoint is only able to directly communicate with a mesh router (or a gateway device that is able to perform the functions of a mesh router).

[0050] The precise network arrangement and configuration of the mesh network 110 may depend upon the environment and / or use case scenario in which the mesh network is implemented. For instance, in some examples, a mesh network device may have the capability of operating as a gateway device, a mesh router or an endpoint device - with the precise decision as to which functionality being dependent upon signal strength and / or location. Thus, a mesh network device may have a dynamic functionality. In other examples, a mesh network device may have a fixed functionality (e.g., is only able to operate as an endpoint device).

[0051] Other labels for the devices of a mesh network are well known to the skilled person. For instance, a mesh router may be labelled a “repeater” in some examples. It will also be appreciated that different communi cational protocols may have different labels or names (as well as sub-groups) for the various devices of the mesh network.

[0052] For instance, a Bluetooth mesh network protocol may label: any gateway device as a “provisioner”, “proxy node” or “proxy server”; any mesh router as a “relay node” or a “friend node” (which is an example of a relay node); and any endpoint device as a “low- power node”.

[0053] As another example, the ZigBee communication protocol may label: any gateway device as a “ZigBee Coordinator” or simply “coordinator”; any mesh router as a “ZigBee Router” or simply “router”; and any endpoint device as a “ZigBee End Device” or simply “End Device”. In the context of the Bluetooth communication protocol, a device that is used to manage the transitions between an unprovisioned device and a node is known as a provisioner.

[0054] When a new device 120 wishes to join the mesh network, there is a desire that the new device should be automatically provisioned (e.g., to facilitate secure communications) to the mesh network. To provision a new device 120, a communication is sent from the new device 120 to a gateway device (e.g., via one or more mesh routers), which retrieves provisioning information from a provisioning server that is external to or outside of the mesh network (e.g., using an appropriately configured software program or the like). The provisioning server 150 may, for instance, act as a cloud application or cloud server for producing provisioning information. The provisioning information is then used by one of the mesh network devices to securely provision the new device 120 to the mesh network 110. Provisioning may comprise performed an authenticated mesh joining process for the first device, such as an authenticated secure Bluetooth mesh joining process.

[0055] It will be clear that any mesh network device comprises a processing unit (e.g., a microprocessor) and a transceiver. The transceiver may be designed for communication using only a single communication protocol (e.g., if the mesh network device is an endpoint device) or multiple communication protocols (e.g., if the mesh network device is a gateway device). The sophistication and structure of the mesh network device may depend upon a wide variety of needs and / or desires for the mesh network device. The present disclosure relates to an approach for selective provisioning of a new device 120 on the mesh network. In particular, it is herein proposed to only identify the new device to a provisioning server if the new device is permitted to be provisioned. In particular, a check is performed at the mesh network side of the mesh network environment as to whether or not a communication is sent to the provisioning server (e.g., an external communication is made).

[0056] In this way, a provisional authentication of the first device (i.e., a device requesting to join the mesh network) is performed by devices of the mesh network. This avoids or reduces an amount of external messages sent outside of the mesh network.

[0057] Figure 2 is a flowchart illustrating a proposed method 200 for identifying a first device to a provisioning server. The method 200 is performed using a network device of the mesh network. In this and subsequently described embodiments, the network device is labelled a mesh network device (for improved contextual understanding), but the skilled person will appreciate how the term “mesh network device” may be replaced by “network device” for use with other types of network.

[0058] The first device is a device that wishes or requests to join a mesh network. The provisioning server is an external (to the mesh network) device that provides or generates provisioning information for provisioning the first device, e.g., providing information for securely connecting the first device to the mesh network.

[0059] The method 200 comprises a step 210 of receiving, at a mesh network device of a mesh network, a first communication, over a first communication channel, from the first device. The mesh network device may be any gateway device and / or mesh router of the mesh network. Thus, in the context of method 200, a mesh network device is a device of the mesh network that receives a first communication from the first device.

[0060] The first communication contains first information responsive to a first product identifier (of the first device). The first communication channel may be a radiofrequency communication channel.

[0061] Thus, in practice, the first device generates and outputs a first communication over the first communication channel. The first communication channel employs or uses a (wireless) communication protocol used for internal communications within the mesh network. The first communication is responsive to a first product identifier carried by the first device (e.g., in a memory). As an example, the first communication may carry the first product identifier or a hashing result produced using the first product identifier. These and other examples of first communications are described in further detail later in this disclosure. The first communication may, for instance, be in the form of a beacon or nondirected communication emitted by the first device.

[0062] Although possible, the mesh network device does not need to be the device of the mesh network that first receives or detects the first communication. In some examples, the mesh network device is a device of the mesh network to which the first communication is routed by a device of the mesh network that first receives the first communication (e.g., using an internal communication protocol of the mesh network). In other examples, the mesh network device is the device of the mesh network that directly detects or receives the first communication.

[0063] The method 200 also comprise a step 220 of processing, at only the mesh network device, (at least) the first information to determine whether or not the first device is permitted to be provisioned by the mesh network device, e.g., connect to the mesh network. Thus, a decision is made at the side of the mesh network as to whether or not the first device is permitted to be provisioned by the mesh network device. In other words, a decision is made as to whether the first device is permitted to be provisioned before any communications are sent outside of the mesh network (e.g., without any communications being sent responsive to the first communication that make use of a different communication protocol).

[0064] Put another way, step 220 comprises determining whether one or more criteria are met (using at least the first information) to determine whether or not the first device is permitted to be provisioned. Suitable examples of criteria are later provided.

[0065] The method also comprises, only responsive to determining that the first device is permitted to be provisioned by the mesh network device, a step 230 of sending a second communication over a second communication channel from the mesh network device to the provisioning server. The second communication identifies the first device to the provisioning server.

[0066] The second communication may, for instance, comprise a device identifier of the first device. In some examples example, the first communication comprises a device identifier of the first device, which is copied or replicated into the second communication.

[0067] Thus, step 230 is only performed responsive to a positive determination in step 220.

[0068] Response to a negative determine in step 220, the method 200 may perform a step 240 of discarding the first communication. In some examples step 240 comprises sending a rejection communication from the mesh network device to the first device. In other examples, step 240 comprises preventing the sending of any communication from the mesh network device to the first device.

[0069] Where the mesh network device is a gateway device, step 230 may comprise simply sending the second communication directly over the second communication channel. Where the mesh network device is a mesh router, step 230 may comprise routing a request to the gateway device to send the second communication over the second communication channel. Thus, step 230 may comprise using a gateway device to send the second communication to the provisioning server. In some examples, this second communication may be transmitted as part of a software program or application run by the gateway device (e.g., a mobile application).

[0070] The first and second communication channels employ different communication protocols. Thus, the first communication channel employs an internal communication protocol, for internal messaging within the mesh network, and the second communication channel employs an external communication protocol, for external communicating outside of the mesh network.

[0071] In particular, the first and second communication channels may employ one or more of: different styles of communication (e.g., wired vs. wireless); different electromagnetic wave frequency bands; different communication standards (e.g., cellular vs. short-range standards or Bluetooth vs. ZigBee); and / or different network scales (e.g., PAN, LAN or WAN). Other examples will be readily apparent to the skilled person.

[0072] As an example, the first communication protocol may be a radiofrequency communication protocol and the second communication protocol may be a cellular communication protocol. As another example, the first communication protocol may be a wireless communication protocol and the second communication protocol may be a wired communication protocol. As yet another example, the first communication protocol may be a Bluetooth communication protocol and the second communication protocol may be a ZigBee communication protocol.

[0073] Step 220 may comprise processing the first information comprises determining whether or not the first product identifier matches a second product identifier stored by the mesh network device. Thus, in some examples, one of the criteria to determine that the first device is permitted be provisioned by the mesh network device is that the first product identifier matches (e.g., is identical to or otherwise has a predefined relationship with) the second product identifier. Thus, the mesh network device may store its own product identifier, which is compared to the first product identifier to determine whether or not the first device is permitted to access or connect to the mesh network. Only if the mesh network device and the first product share a same product identifier, i.e., have a common product identifier, will it be determined that the first device is permitted to be provisioned.

[0074] In other words, the first device and the mesh network device will both store their own versions of a product identifier. The mesh network device is designed to compare its own version of the product identifier to that of the first device in order to decide whether or not the first device should be provisioned. The comparison may be a direct comparison, or a comparison of hashing results that are produced using the product identifier(s).

[0075] This approach is based on the pre-condition that all devices that are permitted to form part of the mesh network will be installed with a common product identifier, e.g., a product key or the like. This can be easily achieved through factory control mechanisms. Thus, the first product identifier and the second product identifier may be defined during manufacture of the first device and the mesh network device.

[0076] In preferred examples, the first information comprises a hashing result of processing at least the first product identifier using a hashing algorithm. This can reduce the risk of any packet sniffing attacks on the mesh network, e.g., to reduce a risk of an unauthorized user or device gaining access to a product identifier provided in a communication from an authentic instance of a first device.

[0077] In such examples, processing the first information may comprise comparing the hashing result (in the first communication) with a second hashing result produced by the mesh network device to determine whether or not the first device is permitted to be provisioned, e.g., to join the mesh network.

[0078] It will be clear that processing information of the first communication responsive to the first product identifier forms at least part of the criteria for determining whether or not the first device is permitted be provisioned by the mesh network device. However, in some approaches, there may be further criteria or conditions that need to be met to determine that the first device is permitted be provisioned by the mesh network device.

[0079] In some examples, the first communication further contains first temporal information produced by the first device. In step 220, the first temporal information may need to meet one or more criteria for the mesh network device to determine that the first device is permitted to be provisioned by or to the mesh network.

[0080] The first temporal information may comprise, for instance, a first timestamp. In some approaches, one criterion for step 220 to determine that the first device is permitted be provisioned by the mesh network device is that the first timestamp falls within a certain time range or time of day. There may be a requirement for a first device attempting to join a mesh network that it only makes the request at a certain time of day. This can act as a further filter for requests.

[0081] In some approaches, one criterion for step 220 to determine that the first device is permitted be provisioned by the mesh network device is that the first timestamp occurs no later than a predetermined period of time after a user interaction with the mesh network device (e.g., indicating a manual permission for the first device to join the network). This can act as a further filter for requests.

[0082] In some approaches, step 220 may comprise producing, at the mesh network device, second temporal information; and determining whether or not a similarity between the first temporal information and the second temporal information meets one or more predetermined conditions. In particular, the one or more predetermined conditions may be a subset of criteria for step 220 to determine that the first device is permitted be provisioned by the mesh network device.

[0083] The first temporal information may comprise a first timestamp and the second temporal information may comprise a second timestamp, e.g., representing a current time at the mesh network device. Each timestamp may, for instance, be produced by a satellite navigation module (e.g., GPS module) of the respective device(s). Such modules are able to obtain highly precise and sensitive timestamps, and are therefore advantageous for use. However, other mechanisms and modules for producing a timestamp could be employed. The one or more predetermined conditions may include a condition that a difference between the first timestamp and the second timestamp is less than a predetermined value (e.g., less than 1 minute, less than 30 seconds, less than 10 seconds, or less than 5 seconds). This approach advantageously reduces a risk of an unauthorized device making a replay attack to successfully connect to the mesh network.

[0084] In one working example, the first communication may comprise a device identifier of the first device (such as a Universal Unique Identifier, Globally Unique Identifier or other form of identifier); first temporal information (e.g., a first time stamp); and a first hashing result. The first hashing result is produced by the first device by hashing the first product identifier using the device identifier and the first temporal information as data inputs. Thus, the first device may use a hash function to process the device identifier, the first temporal information and the product identifier to produce the first hash result. To perform step 220, the mesh network device may first process the temporal information to determine whether the first temporal information and second temporal information (of the mesh network device) meets one or more predetermined conditions. For instance, the mesh network may determine whether a difference between a first timestamp (of the first temporal information) and a second timestamp (e.g., representing a current time at the mesh network device).

[0085] In performing step 220, the mesh network device may then, if the one or more predetermined conditions are met, validate the first hashing result in the first communication by hashing, using a hash function, at least the second product identifier (stored by the mesh network device) using the device identifier and the first temporal information contained in the first communication. If the output of the hashing performed by the mesh network device is the same as the hashing result in the first communication, then it is determined that the first device is permitted to be provisioned.

[0086] This approach effectively tests both whether the first device carries the correct product identifier and is able to perform the same hashing function as the mesh network device, and thereby acts as a test to check whether the first device is permitted to connect to the mesh network and / or be provisioned (e.g., for joining the mesh network).

[0087] If the first hashing result is produced using the device identifier of the first device - then the hashing performed by the mesh network device may further use the device identifier of the first device (e.g., which should, accordingly, be included in the first communication).

[0088] In some examples, the method 200 further comprises, responsive to a positive determination in step 220, sending a mesh communication to (e.g., all) other devices in the mesh network. The mesh communication may, for instance, notify other devices in the mesh network that the first device is (to be) identified to the provisioning server. The other devices may, for instance, advantageously use this mesh communication to determine to not proceed with processing any further iterations of the first communication, thereby saving power.

[0089] Correspondingly, the method 200 may comprise (after receiving 210 the first communication) a step 260 of processing any mesh communication received by the mesh network device to determine whether or not to proceed with the assessment of the first communication. In particular, each mesh communication may be processed to determine whether or not the first device has already been identified to the provisioning server (e.g., by another device in the network). Responsive to a positive determination (to proceed), the method moves to step 220. Otherwise, the method may move to step 240. The method may comprise preventing the sending of any communication from the mesh network device to the first device at least until after determining that the first device is permitted to be provisioned by the mesh network device.

[0090] Figure 3 illustrates a method 300 for provisioning a first device.

[0091] The method 300 comprises performing any previously described method 200 for selectively identifying a first device to a provisioning server.

[0092] The method 300 further comprises a step 310 of receiving, at the mesh network device of the mesh network, provisioning information from the provisioning server.

[0093] The provisioning information is generated and sent by the provisioning server over at least the second channel (e.g., to reach the mesh network) and optionally further internal communications with the mesh network. In particular, the provisioning server may, for instance, prepare a set of network information for the first device, e.g., based on the device identifier of the first device.

[0094] The method 300 further comprises a step 320 of provisioning the first device on the mesh network using the provisioning information. This process may depend upon the precise nature of the mesh network.

[0095] In general, step 320 may comprise performing a secure authentication and / or joining process with the first device to join the first device to the mesh network. The provisioning information may contain information usable for securing the first device to the mesh network, e.g., first device specific information required for performing an authenticated joining procedure.

[0096] As an example, if the mesh network operates using the Bluetooth communication protocol, then step 320 may comprise performing an authenticated secure Bluetooth mesh joining process with the first device.

[0097] Figure 4 conceptually illustrates a proposed communication mechanism. More particularly, Figure 4 illustrates communications between an example first device 401, a mesh network device 402, a provisioning server 403 and (optionally and / or if required, a gateway device 404).

[0098] The first device 401 sends a first communication 410 to the mesh network device 402 over a first communication channel 491. The first communication may, for instance, be in the form of a beacon or broadcast communication (e.g., a non-directed communication). The first communication 401 comprises at least first information responsive to a first product identifier carried by the first device. The first communication acts as a request to join the mesh network and / or be provisioned by the mesh network. As a working example, the mesh network may be a Bluetooth mesh network, being a mesh network that performs internal communications using the Bluetooth communication protocol. In such examples, the gateway device of the mesh network may be a proxy node of the Bluetooth mesh network. The first device may broadcast, as the first communication, a Bluetooth Low Energy (BLE) beacon Bb as: Bb = {UUID, Tl, Hash (PK, UUID||T1)}, in which the UUID is the unique device ID of the first device, Tl is the current timestamp received from the GPS module of the first device, and Hash (PK, UUID||T1) is a keyed hash calculated using the product identifier (e.g., product key) PK and a data input of UUID and Tl.

[0099] In some examples, the first node may also broadcast a joining beacon or communication interleaved with the first communication - such as a Bluetooth mesh joining beacon. This helps facilitate a standard Bluetooth mesh provisioning procedure down the line.

[0100] The mesh network device 402 may receive the first communication directly from the first device 401. Alternatively, the first communication may be routed to the mesh network device 402 from one or more other devices of the mesh network (e.g., via one or more mesh routers of the mesh network).

[0101] The mesh network device 402 receives the first communication and determines whether or not the first device is permitted to be provisioned on or by the mesh network by processing at least the first information. Approaches for performing this determination have been previously disclosed.

[0102] In a continuation of the working example, upon receiving the beacon Bb, the mesh network device (e.g., the proxy node) may first receive a current timestamp T2, and check if T2 - Tl >At. If a positive determination is made, then the beacon Bb may be discarded. The value of At may be selected or adjusted based on real network situations or circumstances that may affect a time for a first communication to be processed, such as: maximum expected distances between devices in the mesh network; processing power and / or frequency of the mesh network device; memory usage of the mesh network device and so on.

[0103] In a continuation of the working example, the mesh network device may then validate the hash of the BLE beacon Bb using a product identifier stored by the mesh network device. If the validation fails, then the beacon Bb may be discarded. If the validation succeeds, then it may be determined that the first device is permitted to be provisioned.

[0104] The mesh network device 402 causes a second communication 420 over a second communication channel 492 to be sent to the provisioning server 403 only when it is determined that the first device is permitted to be provisioned. The second communication channel uses a different communication protocol to the first communication channel. The second communication identifies the first device to the provisioning server.

[0105] In examples where the mesh network device 402 is a gateway device, e.g., is able to directly communicate over the second communication channel, the mesh network device 402 may directly send the second communication (i.e., without needing to route the communication via any other device of the mesh network).

[0106] In examples where the mesh network device 402 is not a gateway device, e.g., is not able to directly communicate over the second communication channel, the mesh network device may send a first routing communication 491 to a gateway device 404 of the mesh network, i.e., using the communication protocol employed by the mesh network within a mesh network communication channel 493. The first routing communication 491 may, for instance, be an instruction carrying information for generating the second communication 420.

[0107] The provisioning server 403 receives the second communication 420 and generates provisioning information in response to the second communication. The provisioning information is suitable for provisioning the first device 401, e.g., for registering or securely connecting the first device 401 to the mesh network.

[0108] The provisioning server 403 then sends a third communication 430 to the mesh network device 402 over the second communication channel. The third communication 430 carries the provisioning information for the first device 401.

[0109] In examples where the mesh network device 402 is a gateway device, e.g., is able to directly communicate over the second communication channel, the mesh network device 402 may directly receive the third communication from the provisioning device (i.e., without the third communication needing to be routed via any other device of the mesh network).

[0110] In examples where the mesh network device 402 is not a gateway device, e.g., is not able to directly communicate over the second communication channel, then the third communication may be routed by a gateway device 404 of the mesh network (e.g., via a second routing communication 492). The gateway device 404 may route the third communication over the mesh network to the mesh network device 402 using the communication protocol employed by the mesh network, i.e., within a mesh network communication channel 493. It will be clear that the mesh network device 402 may be a mesh router or a gateway device of the mesh network. In some examples, the communi cational protocol employed by the mesh network may define or delimit which devices of the mesh network are able to act as the mesh network device (e.g., which devices are permitted to provision or securely connect new device to the mesh network).

[0111] The mesh network device 402 uses the provisioning information carried by the third communication 430 to provision the first device 401, e.g., securely connect the first device to the mesh network.

[0112] As a continuation of the working example, if the mesh network operates using the Bluetooth communication protocol, then the mesh network device 402 may perform an authenticated secure Bluetooth mesh joining process with the first device 401.

[0113] The skilled person would be readily capable of developing a mesh networking device for carrying out herein disclosed methods. Accordingly, each step of the flow chart may represent a different action performed by a mesh networking device.

[0114] The mesh networking device may comprise and employ a processing system for performing steps of disclosed methods. The processing system can be implemented in numerous ways, with software and / or hardware, to perform the various functions required. A processor is one example of a processing system which employs one or more microprocessors that may be programmed using software (e.g., microcode) to perform the required functions. A processing system may however be implemented with or without employing a processor, and also may be implemented as a combination of dedicated hardware to perform some functions and a processor (e.g., one or more programmed microprocessors and associated circuitry) to perform other functions.

[0115] Examples of processing system components that may be employed in various embodiments of the present disclosure include, but are not limited to, conventional microprocessors, application specific integrated circuits (ASICs), and field-programmable gate arrays (FPGAs).

[0116] In various implementations, a processor or processing system may be associated with one or more storage media such as volatile and non-volatile computer memory such as RAM, PROM, EPROM, and EEPROM. The storage media may be encoded with one or more programs that, when executed on one or more processors and / or processing systems, perform the required functions. Various storage media may be fixed within a processor or processing system or may be transportable, such that the one or more programs stored thereon can be loaded into a processor or processing system. It will be understood that disclosed methods are preferably computer- implemented methods. As such, there is also proposed the concept of a computer program comprising code means for implementing any described method when said program is run on a mesh networking device. Thus, different portions, lines or blocks of code of a computer program according to an embodiment may be executed by a processing system of a mesh networking device to perform any herein described method.

[0117] There is also proposed a non-transitory storage medium that stores or carries a computer program or computer code that, when executed by a processing system of a mesh networking device, causes the mesh networking device to carry out any herein described method.

[0118] In some alternative implementations, the functions noted in the block diagram(s) or flow chart(s) may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.

[0119] Variations to the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed invention, from a study of the drawings, the disclosure and the appended claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

[0120] In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. If the term "adapted to" is used in the claims or description, it is noted the term "adapted to" is intended to be equivalent to the term "configured to". If the term "arrangement" is used in the claims or description, it is noted the term "arrangement" is intended to be equivalent to the term "system", and vice versa.

[0121] A single processor or other unit may fulfill the functions of several items recited in the claims. If a computer program is discussed above, it may be stored / distributed on a suitable medium, such as an optical storage medium or a solid-state medium supplied together with or as part of other hardware.

[0122] Any reference signs in the claims should not be construed as limiting the scope.

Claims

CLAIMS:

1. A computer-implemented method (200) for selectively identifying a first device (120) to a provisioning server (150), the computer-implemented method comprising: receiving (210), at a network device (111, 112, 113) of a network (110), a first communication (410), over a first communication channel (491), from the first device, wherein the first communication contains first information responsive to a first product identifier; processing (220), at the network device, the first information to determine whether or not the first device is permitted to be provisioned by the network device; responsive to determining that the first device is permitted to be provisioned by the network device, sending (230), by the network device (111, 112, 113), a second communication (420) over a second communication channel (492) to the provisioning server, wherein the second communication identifies the first device to the provisioning server and the first and second communication channels employ different communication protocols; receiving, at the network device (111, 112, 113), of the network, provisioning information from the provisioning server (150); and provisioning, by the network device, the first device using the provisioning information.

2. The computer-implemented method of claim 1, wherein the processing of the first information comprises determining whether or not the first product identifier matches a second product identifier stored by the network device.

3. The computer-implemented method of claim 2, wherein the first information comprises a hashing result of processing at least the first product identifier using a hashing algorithm.

4. The computer-implemented method of any one of claims 2 to 3, wherein the first product identifier and the second product identifier are defined during manufacture of the first device and the network device.

5. The computer-implemented method of any one of claims 1 to 4, wherein the first communication further contains first temporal information produced by the first device.

6. The computer-implemented method of claim 5, wherein the processing the first information comprises: producing, at the network device, second temporal information; and determining whether or not a similarity between the first temporal information and the second temporal information meets one or more predetermined conditions.

7. The computer-implemented method of claim 6, wherein the first temporal information comprises a first timestamp and the second temporal information comprises a second timestamp.

8. The computer-implemented method of claim 7, wherein the one or more predetermined conditions includes a condition that a difference between the first timestamp and the second timestamp is less than a predetermined value.

9. The computer-implemented method of any one of claims 1 to 8, wherein the network is a mesh network.

10. The computer-implemented method of any one of claims 1 to 9, further comprising, only responsive to determining that the first device is not permitted to be provisioned by the network device, discarding the first communication.

11. The computer-implemented method of any one of claims 1 to 10, further comprising preventing the sending of any communication from the network device to the first device at least until after determining that the first device is permitted to be provisioned by the network device.

12. A computer program product comprising computer program code means which, when executed on a computing device having a processing system, cause the processing system to perform all of the steps of the method according to any one of claims 113. A network device (111, 112, 113), for a network (110), for selectively identifying a first device (120) to a provisioning server (150), the network device being configured to: receive (210) a first communication (410), over a first communication channel (491), from the first device, wherein the first communication contains first information responsive to a first product identifier; process (220) the first information to determine whether or not the first device is permitted to be provisioned by the network device; only responsive to determining that the first device is permitted to be provisioned by the network device, send (230) a second communication (420) over a second communication channel (492) to the provisioning server, wherein the second communication identifies the first device to the provisioning server and the first and second communication channels employ different communication protocols; receive provisioning information from the provisioning server; and provision the first device using the provisioning information.

14. The network device (111, 112, 113) of claim 13, wherein the processing of the first information comprises determining whether or not the first product identifier matches a second product identifier stored by the network device.

15. The network device (111, 112, 113) of claim 13, wherein the first communication further contains first temporal information produced by the first device (120) and the processing the first information comprises: producing, at the network device, second temporal information; and determining whether or not a similarity between the first temporal information and the second temporal information meets one or more predetermined conditions.

Citation Information

Patent Citations

  • Protect device communication in the Internet of Things

    CN110268690B

  • Secure device onboarding techniques

    US11399285B2

  • Network based provisioning of UE credentials for non-operator wireless deployments

    US20150092701A1

  • Monitoring device, control method, and recording medium

    US20180205721A1

  • Bluetooth mesh network provisioning authentication

    US20190357043A1