Onboarding technology
The secure BLE mesh topology enables efficient and secure automatic onboarding of IoT devices by distributing encrypted credentials, addressing the burden of manual entry and enhancing network reach.
Patent Information
- Application Number
- PCT/CN2024/106072
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-18
- Publication Date
- 2026-01-22
AI Technical Summary
The manual entry of wireless credentials for multiple IoT devices in a network is burdensome and time-consuming, particularly in large premises like homes or buildings, where many devices need to be on-boarded to a wireless network.
A secure on-boarding technique using a mesh topology with Bluetooth Low Energy (BLE) messaging to distribute encrypted wireless credentials from a master device to subordinate devices, eliminating the need for manual entry and enabling automatic onboarding across a network.
Facilitates efficient and secure onboarding of IoT devices by automatically distributing encrypted credentials, reducing installation time and minimizing errors, while expanding the reach of the network to peripheral devices.
Smart Images

Figure CN2024106072_22012026_PF_FP_ABST
Abstract
Description
ONBOARDING TECHNOLOGYBACKGROUNDTechnical Field
[0001] The present disclosure relates generally to on-boarding of devices to a network and, more specifically, to securely distributing credentials to devices for on-boarding to a network.
[0002] Background Information
[0003] A procedure used to on-board wireless devices, such as Internet of Things (IoT) devices, onto a wireless network typically involves manual entry of wireless credentials needed to access the network at a user interface for each device. Manual entry of the wireless credentials at each IoT device may be implemented by entering (e.g., typing) the credentials via the interface for input to an application of the device (or a Web page) that finds and connects to the wireless network. This on-boarding procedure is typically implemented because WiFi networks at a premise usually involve specific credentials, even in ad hoc mode, under control of premise administrators that is not available to a device manufacturer.
[0004] In a lighting control system for a premise (such as a large house or building) , there may be many (e.g., 5-150) IoT devices (such as light switches) that require on-boarding to one or more wireless networks which, using the on-boarding procedure, may be burdensome and consume a substantial amount of time (e.g., hours) . As such, it is desirable to have technique that automatically onboards the IoT devices of a premise once an initial device is onboarded.BRIEF DESCRIPTION OF THE DRAWINGS
[0005] The above and further advantages of the embodiments herein may be better understood by referring to the following description in conjunction with the accompanying drawings in which like reference numerals indicate identically or functionally similar elements, of which:
[0006] Fig. 1 is a diagram of a premise having a plurality of devices adapted for connection to one or more in-premise networks;
[0007] Fig. 2 is diagram of a premise having a mesh of IoT devices over a secondary wireless network;
[0008] Fig. 3 illustrates master IoT device communication with subordinate IoT devices;
[0009] Fig. 4a illustrates interaction with the IoT device to enter Roaming Automated Discovery (RAD) primary mode;
[0010] Fig. 4b illustrates a LED lighting sequence indicating RAD subordinate mode;
[0011] Fig. 4c illustrates a LED lighting sequence indicating RAD broadcast mode;
[0012] Fig. 4d illustrates a LED lighting sequence indicating RAD primary mode; and
[0013] Fig. 4e illustrates interaction with the IoT device to enter RAD subordinate mode.
[0014] OVERVIEW
[0015] The embodiments described herein are directed to an on-boarding technique configured to securely and efficiently provide encrypted wireless credentials needed by wireless devices (e.g., Internet of Things devices, such as light switches) of a system (e.g., a lighting control system) to join a wireless network (e.g., WiFi or IEEE 802.11 wireless protocol network) of a premise. The technique facilitates such on-boarding because wireless (WiFi) networks at a premise usually involve specific credentials, e.g., Secure Set Id (SSID) and password, even in ad hoc mode, under control of a premise administrator that is not available to a device manufacturer. According to the technique, the encrypted wireless credentials are provided via one or more secure messages of another wireless protocol (e.g., Bluetooth, BLE) transmitted by the devices over a mesh topology to onboard other devices to the WiFi network without need for initial communication via the network. A master (primary) device is initially configured (e.g., manually by an administrator) with credential information (e.g., an identifier of the wireless network and a password needed to access the network) and automatically (without administrator involvement) distributes the credential information using the secure messaging protocol to the other (subordinate) devices via the mesh topology. Illustratively, the primary device is configured with the wireless credentials via an initial physical interaction between the administrator and an application (e.g., a WiFi onboarding application) executing on the primary device to, e.g., enhance security and obviate possibilities of compromising the credentials. Once the physical interaction completes, the primary device becomes a controlling device of the mesh topology that enables onboarding of the subordinate devices of the system to the wireless network. Notably, the subordinate devices, upon being onboarded, may then also securely broadcast the credential information to yet other devices, thereby expanding reach of the mesh to cover the premise and provide the credential information to any device even if located at a periphery of the premise.DESCRIPTION
[0016] Fig. 1 is a block diagram of a premise (e.g., a residential dwelling 100 or commercial building) having a plurality of devices 110a-d (e.g., Internet of Things devices) adapted for connection to one or more in-premise networks, e.g., a local area network (LAN) such as a wired Ethernet and / or a wireless network such as WiFi 130 via a wireless access point 120. The Internet of Things (IoT) devices 110a-d are illustratively embodied as lighting devices (e.g., light switches, light fixtures, and / or dimmer modules) with interfaces (e.g., keypads and / or touch screens) and organized as a lighting control system. However, the IoT devices may also include light bulbs, cameras, water sensors, and other consumer electronic devices. Each IoT device may include hardware components such as a processor, a memory and a storage device, which collectively store and execute software (e.g., one or more applications) configured to monitor and control operations of device. The device may also include a LAN interface (e.g., an Ethernet or WiFi module) and / or a wireless personal area network (WPAN) interface, e.g., a Bluetooth or Bluetooth low Energy (BLE) transmitter / receiver (transponder) module and WiFi transponder antenna to enable network communication with other devices. Notably, the IoT devices have two or more networks over which to communicate: a primary premise provided / controlled network, e.g., WiFi 130, and a secondary wireless network, e.g., BLE 140, for communication among the IoT devices that operates independently of the primary network and need not depend on premises communication infrastructure, e.g., wireless access point 120.
[0017] The embodiments described herein are directed to an on-boarding technique configured to securely and efficiently provide encrypted wireless credentials 150 needed by wireless devices (e.g., IoT devices) of a system (e.g., a lighting control system) to join a wireless network of a premise (e.g., premise-controlled WiFi network 130) . The encrypted wireless (e.g., WiFi) credentials are illustratively provided via one or more secure messages over a wireless protocol (e.g., Bluetooth, BLE) transmitted via a mesh topology. Use of the mesh topology is advantageous because secure messaging over the wireless protocol obviates the need for control command messages as well as a coordinator device, and also eliminates the need to manually onboard each device on the premises. Thus, in an embodiment, the technique employs BLE transmission (e.g., a BLE advertisement) using a secure messaging protocol (e.g., encrypted payload for the BLE advertisement) to distribute WiFi credentials to IoT devices to enable access to one or more WiFi networks in the premise.
[0018] Fig. 2 is diagram of a premise having a mesh of IoT devices over the secondary wireless network, e.g., BLE. In an embodiment, short-range low power BLE signals broadcast by the devices are used to bootstrap onboarding to the longer-range greater bandwidth WiFi network for the devices by gradually building a broadcast mesh 210a-b to increase reach of the BLE signals to the periphery of the premise as devices are onboarded. Notably, use of BLE advertisements avoids the need to manually pair devices. Illustratively, an unencrypted (e.g., open text) marker may be used in the BLE advertisement so that the devices can identify specific advertisements as containing encrypted wireless credentials. Also, the technique need not rely on any native Bluetooth encryption that usually requires pairing devices to benefit from BLE encryption capabilities, such as Diffie-Hellman dynamic key exchanges.
[0019] Fig. 3 illustrates master IoT device communication with subordinate IoT devices. A master (primary) 110a is initially configured (e.g., manually by an administrator) with credential information 150 (e.g., an identifier of the wireless network and a password needed to access the network) and automatically (without administrator involvement) distributes the credential information via the secure messaging protocol, e.g., using shared keys 315 embedded in the devices, as encrypted data 320 to other (subordinate) devices 330 (110b-c) on the mesh topology 210a-b over the secondary network 140. Illustratively, the primary device 110a is configured with the wireless credentials via an initial physical interaction between the administrator and an application (e.g., a WiFi driver operating over BLE 140 and WiFi 130 in one of several modes to receive or broadcast the credentials 150) of the device to, e.g., enhance security and obviate possibilities of compromising the credentials. Once the administrator interaction completes, the primary device 110a becomes a controlling device 310 of the mesh topology that is responsible for onboarding the subordinate devices of the system. Each subordinate device 330 (110b-c) uses the received credential information to join the primary network 130 and transmit a checksum 335a-b as an acknowledgement back to the controlling device verifying successful access to the primary network. The primary device expands the mesh by sending back a re-acknowledgement 435a-b over the primary network to each subordinate device as an instruction for the respective subordinate device to begin independently broadcasting the credential information.
[0020] In an embodiment, the on-boarding technique provides a plurality of Roaming Assistant Discovery (RAD) modes for configuring and distributing the encrypted wireless credential information 320 among the IoT devices 110a-d of the system: (i) primary mode (obtain administrator input of credentials and securely broadcast) , (ii) subordinate mode (listen for the secure broadcast of the credentials) and (iii) subordinate broadcaster mode (once onboarded, securely broadcast the credentials to expand the mesh 210) . The primary (RAD primary) device 310 is configured to initially (e.g., boot) operate in primary mode and is configured to broadcast the input of the wireless credentials 150 needed to access the wireless (WiFi) network, i.e., the device is configured per service set identifier (SSID) that identifies the wireless network (primary network) . Notably, the primary device may include a keypad and / or display to receive input of the credentials or via BLE using input capabilities of a mobile device.
[0021] Once the RAD primary device 310 is configured, one or more subordinate devices may be manually place into “subordinate” (listening) mode via physical interaction with the administrator, e.g., via key press sequence of specific buttons. Alternatively, such physical interaction is not required and the subordinate devices 330 may be configured to initialize (boot) into listening mode upon power-up. Once the RAD primary device is activated and begins broadcasting (distributing) the encrypted wireless credential information over the secure messaging protocol, the subordinate device receives and decrypts the credential information, and loads the credentials into the application (WiFi driver) to join the wireless network. The ability to place / initialize IoT devices into the listening mode to acquire the wireless credential information obviates the need to manually enter relatively large (e.g., 16 characters) information into many remote devices, which would be both time consuming and error prone.
[0022] Upon transmitting the checksum 335 and receiving the final re-acknowledgement 345, the subordinate device transitions to “subordinate broadcaster” mode in which the device 110b, c again broadcasts the encrypted wireless credential information over the secure messaging protocol (carried over BLE) to share with other IoT subordinate devices 110d in the same manner as the primary device. Note that the subordinate broadcaster mode is not a re-broadcast or repeater function that merely “echos” the credential information from the RAD primary device, but rather is an independent broadcast message over the BLE mesh topology 210a, b that facilitates propagation of the broadcast transmission and distribution to increase (grow) the size of the mesh as more IoT subordinate devices join. In this manner, the WiFi credentials are securely broadcast to yet other devices 110d, thereby expanding reach of the mesh (i.e., from 210a to 210b) to cover the premise and provide the credential information to any device even if located at a periphery of the premise.
[0023] Fig. 4a illustrates interaction with the IoT device to enter RAD primary mode. In an embodiment, entry into the various RAD modes (primary, subordinate, or subordinate broadcaster) , is via a button 430, 435 depression action (e.g., sequence of button presses) activated on the keypad of a device. For example, to enter primary mode, an administrator (i) depresses a specified button 430 on the keypad (indicated by circled numeral “1” ) and then (ii) presses and releases a service switch 435 (or button as indicated by circled numeral “2” ) on the keypad to essentially “de-power” the device to provide an air gap (thus creating an electromechanical disconnection of electricity to the device) and reintroduce power so that the device reboots. The administrator continues to hold the specified button for several seconds (e.g., 10 seconds) as power is re-introduced to the device and the device reboots. Software (e.g., firmware) resident on the device detects the state of the button depression (at initialization) and proceeds to enter primary mode based on a length of time (e.g., 10 seconds) that the specified button remains depressed immediately following initialization. Illustratively, a set of light emitting diodes (LEDs) 410 visible on the device indicate the RAD mode.
[0024] Figs. 4b-d illustrate a LED lighting sequence indicating the RAD mode of the IoT device. In an embodiment, a color of the LEDs turning on and off in a sequence indicates the RAD mode: (i) white LEDs illuminating in a specific direction (left to right) indicate RAD primary mode (already onboarded root or primary device) ; (ii) red LEDs illuminating right to left indicate RAD subordinate mode (waiting to onboard) , and (iii) green LEDs illuminating left to right indicate RAD subordinate broadcast mode (successfully onboarded device now a broadcaster) .
[0025] Fig, 4e illustrates interaction with the IoT device to enter RAD subordinate mode to receive the WiFi credentials from the primary device. Illustratively, the administrator presses and holds the same specified button 430 on the other IoT devices 110b, c (for the same length of time, e.g., 10 seconds) . Notably, however, the service switch is not depressed so this action does not disconnect power from those devices. The devices then enter subordinate mode. In some embodiments, the IoT devices may be factory configured to enter RAD subordinate mode on first power-on so that the administrator need not configure devices other than primary devices (note that some devices may have no buttons or interface) . Although the technique contemplates these physical interactions to transition the device for security purposes, the various modes may alternatively be entered through software configuration or via a mobile device. In any event, there is a trigger, e.g., manual interaction, such as a press and hold physical interaction of a keypad button, needed to place the devices into the various RAD modes, that may be either hardware-based, software-based or pre-configured as a factory default “out of the box. ” As for the latter, some IoT devices, such as light bulbs, without a physical user interface may have the factory pre-configured default mode to immediately place the devices into the subordinate “listening” mode at power-on to search for the onboard protocol to join the wireless network.
[0026] In an embodiment, the RAD primary device enters the RAD mode where it broadcasts (transmits) , via the secure messaging protocol (e.g., using one or more embedded shared keys among devices) over BLE, the encrypted wireless credentials to any subordinate device configured to receive the wireless credentials in RAD subordinate mode to join the wireless network. Illustratively, each device includes one or more pre-configured encryption keys needed to encrypt and decrypt the secure message to securely send / receive the credentials. Illustratively, a variety of symmetric or asymmetric encryption algorithms, such as the Advanced Encryption Standard (AES) , elliptic cyphers and the like, may be used. The subordinate device is also initially provisioned (e.g., via manual physical interaction by the administrator or factory default) to enter the subordinate “listening” mode where the device listens for the primary device broadcast (announcement) of the wireless credential transmission.
[0027] Upon receiving the secure message transmission, the subordinate device decrypts the credentials and loads them into the application to join the wireless network. Subsequently, a handshake (i.e., message sequence 335 followed by message 345) between the device and the RAD primary device occurs over the WiFi network to confirm successful access to the wireless network and signal the device to then enter RAD subordinate broadcast mode to expand the mesh and reach further subordinate devices. Specifically, the device returns the acknowledgement (confirmation) message 335 (e.g., a checksum of the wireless credentials to verify receipt and valid decryption of those credentials) over the wireless network (primary network) to the RAD primary device that acknowledges successful on-boarding to the wireless network. The RAD primary device thereafter replies with a final answer (re-acknowledgement 435) to the subordinate device that confirms receipt of the acknowledgement and signals (permits) the subordinate device to enter the subordinate broadcaster mode. The subordinate device may then proceed to propagate (broadcast) the secure message with encrypted wireless credentials to other Internet of Things (IoT) devices of system over the mesh topology, inviting them to join the wireless network.
[0028] In an embodiment, each IoT device is configured with one or more encryption keys 315 that, e.g., is embedded (stored) in firmware of the device and used to encrypt and decrypt the wireless credential information carried in the messages of the BLE transmission, e.g., the credentials are encrypted and stored as contents of the messages, such as BLE advertisements. The secure messaging protocol may be leveraged to transmit other information and provide firmware updates to, e.g., replace or update encryption keys at the IoT devices. Illustratively, each secure message (payload) includes (i) the SSID of the wireless network, (ii) the encrypted wireless credentials (e.g., password and / or username) needed to connect to and join the wireless network, and (iii) the network (IP) address of the RAD primary device (source) initiating the secure messaging. Note that a source IP address of the subordinate device acknowledgement may be used by a primary device to reply to the acknowledgement (checksum) message over the wireless network.
[0029] In an embodiment, the onboarding technique establishes various time intervals / periods for the devices to operate in accordance with, and then exit from, the various RAD modes using, e.g., different clocks. Illustratively, a RAD primary device utilizes a primary clock to establish the primary mode of operation to onboard subordinate device (s) , wherein the primary mode is active for a predefined period of time, e.g., 15 minutes. In response to onboarding each subordinate device, the primary clock resets for another time period (e.g., another 15 minutes) to enable further onboarding of device (s) . In this manner, onboarding may proceed throughout the premises as broadcasts from each primary device reach a limit of their wireless range and subsequently shutdown for lack of acknowledgements from already onboarded devices within their wireless range. A next RAD broadcast mode device then continues to onboard devices, extending reach of the WiFi credential broadcast until a periphery of the premises is reached. In essence, the RAD secure messaging protocol creates a cascading mesh (RAD primary to RAD subordinate broadcaster to yet another RAD subordinate broadcaster) to broadcast the wireless credentials throughout the premise where each broadcaster terminates once no further acknowledgements are received for the time period.
[0030] In an embodiment, each subordinate device utilizes a subordinate clock to establish the subordinate broadcaster mode of operation to onboard other subordinate device (s) , wherein each subordinate clock runs separately (independently) from the primary clock and other subordinate clocks. Illustratively, the subordinate mode is active for the predefined period of time, e.g., 15 minutes, at which point the subordinate device exits the mode if it has not on-boarded any device (i.e., not received an onboarding acknowledgement via the wireless network) . Once the subordinate device exits the RAD mode, any IoT device with wireless range of the WiFi credential broadcast is onboarded, i.e., connected to the WiFi network. As such, all devices exit RAD mode once all IoT devices within reach of the wireless broadcast of the WiFi credentials are onboarded or fail to receive the broadcast.
[0031] In an embodiment, the entire onboarding procedure (session) across the entire network may be terminated manually by, e.g., pressing a button on the keypad of the RAD primary device, which informs all connected devices that the broadcast session has ended and that the devices must restart (re-initialize) to join the network. In this manner, incorrect or changed credentials can be recalled and all devices reset to receive new credentials. Depression (activation) of another button on the RAD primary device keypad may terminate the session for a specific (IoT) device; activation of the button creates a reset message that is transmitted (or broadcasted) to the specific device (or all devices) to end the session. Notably, the reset message may broadcast via BLE in a similar manner to the broadcast of the wireless credentials and may also be transmitted via WiFi for those devices already on-boarded. The latter transmission may be used to change wireless networks (e.g., change devices to use another SSID) .
[0032] In an embodiment, the secure messaging of the on-boarding technique may be suspended and re-started at any time to accommodate additional installation / onboarding of devices. For example, the lighting control system may be initially installed with only interior light switches (within the premise) on-boarded to the wireless network. Subsequently, exterior light switches (outside the premise) may be installed and on-boarded to the wireless network by reactivating the RAD secure messaging protocol without having to reenter the wireless credentials (e.g., at the RAD primary device) . Illustratively, the secure messaging protocol is a stateful protocol (retains the necessary configured wireless information) that also allows any existing device on the wireless network to subsequently assume the role (act) as the RAD primary device to onboard other IoT devices of the system. That is, the primary device, upon re-entering RAD primary mode, may prompt the administrator to use existing wireless credentials (or new credentials) to onboard additional devices.
[0033] The onboarding technique facilitates onboarding of devices across multiple networks for large premises. On-boarding of the devices may then be suspended and thereafter re-started so that all devices of all networks are on-boarded. In an embodiment, once an administrator has provided (loaded) the wireless credentials to a RAD primary device, other users may proceed to onboard additional devices to the wireless network without knowledge of the wireless credentials. This aspect of the technique conserves (saves) a substantial amount of installation time compared to existing onboarding solutions. Moreover, the technique provides an additional level of security by obviating the need to provide the security (wireless) information to another person. For example, a premise (house) owner can enter the wireless credential information once into the RAD primary device and thereafter a contractor (user) can complete the onboarding procedure of other devices without having access to the credential information.
[0034] In an embodiment, the onboarding technique is directed to onboarding IoT devices to a wireless network of the lighting control system to enable communication between the devices and a host of the system, e.g., over a router connecting various wireless networks. In a large premise deployment of the lighting control system, there may be various access points that allow various devices to connect to a wireless network. Notably, a RAD primary device illustratively has only one configuration, but that configuration may be reset to enable the device to onboard devices onto different wireless networks having different SSIDs using the RAD secure messaging protocol and selectively placing subordinate devices into the RAD subordinate mode. Alternatively a reset message as described above be used. Recall that any suitable device can be configured to a RAD primary or subordinate device “role” via a keypad of the device so as to place the device into the desired role.
[0035] In an embodiment, different SSIDs acting as distinct wireless address spaces facilitate multiple sessions of the onboarding technique during a setup phase of the session, i.e., setup may occur initially or at any subsequent point in time with no time restriction (e.g., 6 months later) for the same or different SSID relating a different network and / or area of the premise. Note that the same RAD primary device can be re-used to facilitate onboarding of devices for each different network / SSID; however, illustratively, a different RAD primary device with different wireless credentials may be used for each (different) wireless network / SSID. Existing (already) onboard devices can remain configured, whereas new devices can be placed in RAD subordinate mode to be configured with different wireless credentials (i.e., different SSID and password) .
[0036] The onboarding technique described herein may be distinguishable over preexisting onboarding topologies, such as those used by Apple Air Drop / Cloud Keychain, that require either established WiFi connection or paired Bluetooth connection between devices. The technique also differs by leveraging the mesh topology (e.g., a cascading mesh or pseudo-mesh topology) that cooperates with aspects of the technique to facilitate broadcasting of messages to expand device onboarding onto one or more wireless networks of a premise. Specifically, the onboarding technique involves (i) configuration of a primary device with wireless credential information, (ii) secure broadcasting of the information from the primary device to one or more subordinate devices, (iii) return of initial acknowledgements to the primary device from successfully on-boarded subordinate devices, (iv) reply of re-acknowledgement from the primary device to the subordinate devices authorizing transition to subordinate broadcaster mode to distribute the wireless credential information to other subordinate devices, (v) establishment of time-out periods for mode operation and exiting, and (vi) restart / reboot modes, as discussed herein. The technique further leverages a pre-established security (encryption) key at each device that facilitates an “automated” onboarding procedure as described herein, compared to prior art solutions (Apple Air Drop) that require manual keypad button manipulation at each device (as well as confirmation of such manipulation by a primary device for each subordinate onboarding event) .
[0037] Advantageously, the technique described herein is directed to a secure and efficient way to rapidly on-board many IoT devices to a WiFi network using a button sequence employed by a RAD primary device. Messages with encrypted WiFi credentials are transmitted (e.g., broadcasted) over a BLE secure messaging protocol to subordinate devices that decrypt the messages (e.g., identified by SSID) using encryption keys (stored in device firmware) to obtain the WiFi credentials needed to access the WiFi network. A visual indicator of the IoT device displays successful on-boarding by e.g., flashing keypad LEDs according to a predetermined frequency, color, and / or lighting pattern. A confirmation message exchange reports status of the devices over a reliable transport (e.g., TCP / IP) on the WiFi network. The confirmation message confirms that the device has received the wireless credentials, successfully on-boarded to the WiFi network and can send / receive messages over the network. Failure to on-board manifests as an absence of the confirmation message after a predetermined period of time has elapsed, because the device cannot access the network to indicate a failure. In essence, the technique involves a distributed propagation of encrypted wireless (WiFi) credentials using any type of secure messaging protocol. In this context, distributed propagation denotes broadcasting of the encrypted credentials by a primary device to subordinate devices that cascade as separate broadcast devices to form a ( “pseudo” ) mesh topology.
[0038] The foregoing description has been directed to specific embodiments of this invention. It will be apparent, however, that other variations and modifications may be made to the described embodiments, with the attainment of some or all of their advantages. For example, it is expressly contemplated that the teachings of this invention can be implemented as software, including a computer-readable medium having program instructions executing on a processor, computer, hardware, firmware, or a combination thereof. Accordingly, this description is to be taken only by way of example and not to otherwise limit the scope of the invention. It is thus the object of the appended claims to cover all such variations and modifications as come within the true spirit and scope of the invention.
[0039] What is claimed is:
Claims
1.A method comprising:configuring a first internet of things (IoT) device with credentials for accessing a first wireless network controlled by a premise;encrypting the credentials using an encryption key shared among a plurality of IoT devices;broadcasting the encrypted credentials from the first IoT device over a second wireless network;receiving an acknowledgment at the first IoT device from a second IoT device via the first wireless network acknowledging receipt of the encrypted credentials; andinstructing the second IoT device to broadcast the encrypted credentials via the second wireless network.2.The method of claim 1 wherein the first wireless network employs an 802.11 wireless protocol and the second wireless network employs Bluetooth (BLE) .3.The method of claim 1, further comprising:cease broadcasting of the encrypted credentials by the first IoT device upon failure to receive acknowledgement from another IoT device after a time period.4.The method of claim 1 further comprising:in response to receiving the broadcasted encrypted credentials, receiving at the second IoT device another acknowledgment from a third IoT device via the first wireless network acknowledging receipt of the encrypted credentials; andinstructing the second IoT device to broadcast the encrypted credentials via the second wireless network.5.The method of claim 4, further comprising:cease broadcasting of the encrypted credentials by the first IoT device upon failure to receive acknowledgement from another IoT device after a time period, wherein the second IoT device continues to broadcast the encrypted credentials.6.The method of claim 4, wherein the first IoT device is out of range of the third IoT device via the second wireless network.7.The method of claim 4, wherein instructing the second IoT device further comprises sending a re-acknowledge from the second IoT device via the first network to the third IoT device.8.The method of claim 4, wherein second wireless network is Bluetooth (BLE) , and the second and third IoT devices are not manually paired via BLE.9.The method of claim 1, further comprising:placing the first IoT device into a primary mode to broadcast the input of the encrypted credentials.10.The method of claim 1, wherein the second IoT device is configured to power-on in a mode to receive the encrypted credentials via the second wireless network and in response, send the acknowledgement back to the first IoT device.11.The method of claim 1, wherein the acknowledgement includes a checksum of the credentials for verifying receipt and decryption of the encrypted credentials sent via the second wireless network.12.The method of claim 1, further comprising:in response to receiving at the first IoT device a stop broadcast key press, ceasing broadcast of the encrypted credentials and broadcasting a stop broadcast message via the second wireless network; andin response to receiving the stop broadcast message at the second IoT device, ceasing broadcast of the encrypted credentials and broadcasting a stop broadcast message via the second wireless network.13.The method of claim 1 wherein instructing the second IoT device further comprises sending a re-acknowledge from the first IoT device via the first wireless network to the second IoT device.14.The method of claim 1, further comprising:illuminating a plurality of light emitting diodes in a directional repeating sequence at the second IoT device indicating that a re-acknowledgement instruction has been received and that the encrypted credentials are broadcast via the second wireless network.15.A non-transitory computer readable medium including program instructions for execution on a processor, the program instructions configured to:configure a first internet of things (IoT) device with credentials for accessing a first wireless network controlled by a premise;encrypt the credentials using an encryption key shared among a plurality of IoT devices;broadcast the encrypted credentials from the first IoT device over a second wireless network;receive an acknowledgment at the first IoT device from a second IoT device via the first wireless network acknowledging receipt of the encrypted credentials; andinstruct the second IoT device to broadcast the encrypted credentials via the second wireless network.16.The non-transitory computer readable medium of claim 15, wherein the program instructions are further configured to cease broadcast of the encrypted credentials by the first IoT device upon failure to receive acknowledgement from another IoT device after a time period.17.The non-transitory computer readable medium of claim 15, wherein the program instructions are further configured to:in response to receiving the broadcasted encrypted credentials, receive at the second IoT device another acknowledgment from a third IoT device via the first wireless network acknowledging receipt of the encrypted credentials; andinstruct the second IoT device to broadcast the encrypted credentials via the second wireless network.18.The non-transitory computer readable medium of claim 15, wherein the program instructions are further configured to place the first IoT device into a primary mode to broadcast the input of the encrypted credentials.19.The non-transitory computer readable medium of claim 15, wherein the acknowledgement includes a checksum of the credentials for verifying receipt and decryption of the encrypted credentials sent via the second wireless network.20.An apparatus comprising:a processor and persistent storage, wherein the processor is configured to execute program instructions configured to:configure a first internet of things (IoT) device with credentials for accessing a first wireless network controlled by a premise;encrypt the credentials using an encryption key shared among a plurality of IoT devices;broadcast the encrypted credentials from the first IoT device over a second wireless network;receive an acknowledgment at the first IoT device from a second IoT device via the first wireless network acknowledging receipt of the encrypted credentials; andinstruct the second IoT device to broadcast the encrypted credentials via the second wireless network.
Citation Information
Patent Citations
Social mesh networks
US20190089777A1
Hierarchical Wakeup Apparatus and Method
US20190191372A1
System and Method for Efficient Onboarding to a Wireless Network of a Group of WLAN Devices Owned by a User
US20230262454A1