Provisioning devices to talk over WI-FI in field

The method addresses security risks and operational overhead in provisioning Wi-Fi credentials for field devices by generating and exchanging keys to establish secure wireless communication sessions, ensuring secure connectivity without default secrets.

WO2026030211A1PCT designated stage Publication Date: 2026-02-05LANDIS GYR TECH INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/039473
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-29
Filing Date
2025-07-28
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing methods for provisioning Wi-Fi credentials in field devices, such as utility meters, pose security risks with default or pre-provisioned credentials and introduce operational overhead, particularly in environments without cellular network coverage.

Method used

A method for provisioning Wi-Fi credentials in the field using a secure wireless communication protocol based on IEEE 802.11 standards, involving the generation and exchange of public and private keys to establish a wireless communication session, eliminating the need for default secrets during manufacturing.

Benefits of technology

Enables secure wireless communication sessions between field devices and field tools, enhancing security and reducing operational overhead by generating credentials on demand, even in areas without cellular coverage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025039473_05022026_PF_FP_ABST
    Figure US2025039473_05022026_PF_FP_ABST
Patent Text Reader

Abstract

A method of provisioning a first device with a secret for establishing a wireless communication session with a second device, wherein the second device is a deployed field device, the method comprising: receiving, a probe request comprising a first public key and a second public key, wherein the first public key is signed using the second private key and the second public key is signed using a third private key, validating the second public key using a third public key, extracting the second public key, validating the first public key using the second public key, extracting the first public key, generating a secret for establishing a wireless communication session, encrypting the secret using the first public key; and transmitting the encrypted secret to the first device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] PROVISIONING DEVICES TO TALK OVER WI-FI IN FIELD

[0002] Field of Disclosure

[0003] The present application relates to a method and system for provisioning Wi-Fi credentials in field, and in particular but not limited to methods for provisioning Wi-Fi credentials in field to utility meters.

[0004] Background

[0005] A resource provider, such as a utility company, may deploy large numbers of metering, sensor, or actuator devices across its service areas. Metering devices are used to measure the consumption of a utility at residential or commercial premises. Metering devices may comprise, for example, electric metering devices for measuring the consumption of electrical power, water metering devices for measuring the consumption of water, or gas metering devices for measuring the consumption of gas, etc.

[0006] After devices are deployed in the field, the resource provider or manufacturer may need to connect to its devices, e.g. for troubleshooting or to provide updates for additional or enhanced functions.

[0007] An example system 100 is shown in Fig. 1 . The system comprises a deployed cellular device 108 that relies on a cellular network 106 for connectivity. Thus, a field tool 102 may connect to the device 108 via the cellular network 106, through cellular connections 114a and 1 14b. Without cellular provider coverage, there is no secure method by which the field tool 102 can communicate with device 108 for troubleshooting in the field.

[0008] A cellular metering device comprises two main components: a cellular modem with embedded radio firmware and a metering unit. Some devices have been provided with optical ports on the meter, to provide a secondary connection point for commands to flow through the meter to the radio. However, this method presents limitations, particularly regarding the security of the optical connection.

[0009] The next generation of cellular devices may feature an edge card configured to receive Wi-Fi communications, offering a more versatile connectivity option. However, a challenge arises in securely provisioning Wi-Fi credentials. One approach is to pre-provision default credentials to all devices during manufacturing. However, this poses a security risk as default credentials are typically not secure. Another option is to provision unique credentials for each device during manufacturing. However this introduces operational overhead for managing and maintaining the credentials, and creates a risk associated with maintaining a credentials database.

[0010] For these and other reasons, the Applicant has recognised a need for a method for provisioning Wi-Fi credentials in the field, thereby mitigating the security risks associated with default or pre-provisioned credentials.

[0011] Summary

[0012] Aspects and preferred features are outlined in the accompanying claims.

[0013] According to a first aspect of the present disclosure, there is provided a method of provisioning a first device with a secret for establishing a wireless communication session with a second device, wherein the second device is a deployed field device, the method comprising: receiving, by the second device, a probe request, wherein the probe request comprises a first public key of a first private-public key pair and a second public key of a second private-public key pair, wherein the first public key is signed using the second private key of the second private-public key pair and the second public key is signed using a third private key of a third private-public key pair; validating the second public key using a third public key of the third private-public key pair; extracting the second public key; validating the first public key using the second public key; extracting the first public key; generating a secret for establishing a wireless communication session; encrypting the secret using the first public key; and transmitting the encrypted secret to the first device.

[0014] The wireless communication session may utilise wireless network protocols based on the IEEE 802.11 family of standards. For example, the wireless communication session is a WiFi communication session.

[0015] Methods according to the first aspect may remove the need for the provisioning of default secrets during manufacturing of field devices such as utility meters. Instead, a secret for establishing wireless connections may be generated and provided to a field tool upon request. Implementations described herein may be leveraged in radiofrequency (RF) networks to thereby eliminate the need for communication adapters to connect to deployed RF devices.

[0016] The secret may be any confidential code, sign or data for use in confirming an identity of the a user or a device. It will be understood that the term secret is used herein to refer to any critical component that may be shared in confidence with a peer over a physically unsecured link to thereby devalue sniffing or other unauthorised attempts to monitor the traffic. For example, the secret may comprise a password, PIN, or any other identifier. A password may be, for example, a text password comprising a string of letters, numbers and / or other symbols. It will be further understood that descriptions of implementations containing references to specific types of secrets, such as passwords, are equally applicable to any other suitable type of secret.

[0017] The method may further comprise establishing a secure wireless communication session between the first device and the second device. Establishing the secure wireless communication session may comprise authenticating the communication session using the secret, for example via a EAP-PSK authentication procedure or any other means.

[0018] In implementations, the method may comprise processing the probe request. For example, the second device may process the probe request to determine what data is being requested.

[0019] In implementations, the method may comprise: generating, by the first device, the first private-public key pair; transmitting the first public key to a headend system; receiving, by the first device, the first public key signed using the second private key.

[0020] Generating the secret may comprise generating a random secret.

[0021] In implementations, the second device may be metering, sensor, or actuator device. The first device may be a field tool configured to establish a wireless communication session with the second device, e.g. for troubleshooting by a field technician.

[0022] According to a second aspect of the disclosure, there is provided a utility meter comprising a means for receiving wireless communications, the utility meter configured to: receive, from an external device, a probe request, wherein the probe request comprises a first public key of a first private-public key pair and a second public key of a second private-public key pair, wherein the first public key is signed using the second private key of the second private-public key pair and the second public key is signed using a third private key of a third private-public key pair; validate the second public key using the third public key of the third private-public key pair; extract the second public key; validate the first public key using the second public key; extract the first public key; generate a secret for establishing a wireless communication session; encrypt the secret using the first public key; and transmit the encrypted secret to the external device.

[0023] The utility meter may be configured to establish a secure wireless communication session with the external device based on the secret.

[0024] In implementations, prior to receiving the probe request, the utility meter may be in a wireless communications receive only mode. Responsive to validating the probe request, the utility meter may be configured to switch to a wireless communication mode for both transmitting and receiving wireless communications.

[0025] The wireless communications may be Wi-Fi communications.

[0026] According to a third aspect of the disclosure, there is provided a field tool for establishing wireless communication with a utility meter, the field tool comprising a means for transmitting wireless communications, the field tool configured to: transmit, to the utility meter, a probe request, wherein the probe request comprises a first public key of a first private-public key pair and a second public key of a second private-public key pair, wherein the first public key is signed using the second private key of the second private-public key pair and the second public key is signed using a third private key of a third private-public key pair; receive an encrypted secret from the utility meter; decrypt the secret using the first private key; and establish a secure wireless communication session with the utility meter using the secret. In implementations, the wireless communications are Wi-Fi communications.

[0027] According to a fourth aspect of the disclosure, there may be provided a system comprising a utility meter according to the second aspect and a field tool according to the first aspect.

[0028] According to a fifth aspect of the disclosure, there is provided a computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method of the first aspect.

[0029] According to a sixth aspect of the disclosure, there is provided a computer-readable medium comprising instructions which, when executed by a computer, cause the computer to carry out the method of the first aspect.

[0030] Brief Description of the Figures

[0031] Some preferred embodiments of the invention will now be described, by way of example only and with reference to the accompanying drawings, in which:

[0032] Figure 1 illustrates a block diagram of an example system for troubleshooting a deployed cellular device.

[0033] Figure 2 illustrates a block diagram of an example system for provisioning Wi-Fi credentials to devices in field.

[0034] Figure 3 illustrates example method steps for provisioning Wi-Fi credentials to devices in field.

[0035] Detailed Description of the Preferred Embodiments

[0036] Methods and systems according to the present disclosure may remove the need for the provisioning of default passwords during manufacturing of field devices such as utility meters. Instead, methods according to the present disclosure facilitate the provisioning of wireless connection credentials such as passwords or other identifying secrets in the field. Implementations described herein may be leveraged in radiofrequency (RF) networks to thereby eliminate the need for communication adapters to connect to deployed RF devices. Thus, the present disclosure may provide a means for technicians to securely communicate with cellular devices in field for any troubleshooting or update procedures, even in the event of cellular network issues.

[0037] Figure 2 depicts an example system 200 for provisioning wireless credentials to devices in field. A first device or field tool 202 may comprise a wireless driver 204, thereby providing wireless connectivity for the field tool 202. The field tool 202 may be configured to provision the wireless credentials for the one or more deployed second device(s) 208 in field, and / or for troubleshooting or otherwise transferring data to and from the deployed second devices after the credentials have been so provisioned. It will be understood that the field tool 202 may be any system or device used for troubleshooting, updating or otherwise securely transferring data to and from a deployed second device.

[0038] The one or more deployed second devices 208 may be e.g. metering devices, sensor devices or actuator devices, or any other distributed device requiring connections to the field tool. Each second device 208 may comprise an edge card 210 for wireless communications and / or a radio transmitter / receiver 212 for communications via other communication channels. It will be understood that the edge card may be any component device suitable for receiving and / or transmitting wireless communications.

[0039] A manufacturer headend system (HES) 206 may be in communication with the field tool 202 and / or the one or more second devices 208, for example via wireless connections 214a, b or via any other connection means.

[0040] In contrast to system 100, the wireless connectivity of the second device facilitates a direct wireless connection 214c between the field tool 202 and the one or more second devices 208 in field. The wireless connections 214a, b, c may be connections utilising wireless network protocols based on the IEEE 802.1 1 family of standards, such as Wi-Fi connections.

[0041] It will be understood that the field tool, HES and second device(s) may also be provided with other connection means, e.g. cellular connections and / or physical connection such as optical cables.

[0042] In existing cellular network based systems, default passwords or device specific passwords may be provided to devices during manufacturing. However, this process has limitations in terms of the security of maintenance, particularly during downtimes for cellular networks. Figure 3 depicts an example process for provisioning wireless protocol connection credentials for a deployed device to a field tool in field, to thereby facilitate wireless (e.g. Wi-Fi) communications between the deployed device and a field tool. In particular, the method depicted in Fig. 3 facilitates the provision of generated wireless secrets by the deployed device directly to a field tool. In implementations, wireless connections and communications used in the method of Fig. 3 may utilise wireless network protocols based on the IEEE 802.1 1 family of standards, such as a Wi-Fi connection.

[0043] Initially, a manufacturer headend system (HES) may be provided with a HES public key, signed by the device manufacturer. For example, a public private key pair may be generated by the HES and sent to the manufacturer for signing using a manufacturer private key, under any protocols familiar to the skilled person. The HES public-private key pair may not have any expiry date.

[0044] Similarly, during manufacturing each device may be supplied with a manufacturer public key corresponding to the manufacturer private key. Upon deployment, the device may be configured to receive wireless communications. In implementations, the device may be in a communications receive only mode prior to receiving transmissions from a field tool.

[0045] To connect to the deployed device in field, the field tools generates a key pair, and sends a request to the HES for a token. The field tool key pair may be generated via e.g. Elliptic Curve Cryptography (ECC), or via any other suitable means, and the request may include the field tool public key. The request for a token may be a request for a wireless security token.

[0046] Following this, the HES may sign the field tool public key with the HES private key, and return the signed field tool public key to the field tool along with the HES public key. In implementations where the HES public-private key pair do not have an expiry, these steps may be skipped if the field tool already has access to the wireless security token, e.g. from a previous connection session with the deployed device. However, a non-expiring signature on the field tool public key may pose a security risk, and hence these steps may be repeated whenever the field tool public key requires a new signature.

[0047] The field tool may then transmit a probe request to the deployed device in field. The probe request may be transmitted over the wireless communication channel. The wireless security token may comprise the field tool public key (signed by the HES private key) and the HES public key (signed by the manufacturer private key). For example, the field tool may send a Wi-Fi probe request to device edge card with a Wi-Fi Token embedded as an information element. If the device is configured in a communication receive only mode, it may ignore any probe request sent without a security token.

[0048] Upon receipt of the probe request, the deployed device in field may process the request. For example, the probe request may be processed to determine the data requested in the probe, that the probe request has been received by the correct device, or for any other reasons familiar to the skilled person.

[0049] The device may then validate the wireless security token, for example by using the manufacturer public key to extract the HES public key. The device may then in turn use the extracted HES public key to extract the field tool public key, thereby provisioning the device with the field tool’s public key.

[0050] If a valid token is received, the device may generate a secret for encrypting wireless communications, using any secret generation technique. For example, the device may generate a new random secret for every communication session, to thereby enhance the security of in field wireless communications. The generated secret may be encrypted with the field tool public key. The secret may be any confidential code, sign or data for use in confirming an identity of the device. For example, the secret may comprise a password, passcode, PIN, or any other identifier. A generated password may, for example, comprise a text password comprising a string of letters, numbers and / or other symbols.

[0051] Following this, the device may provide a probe response to the field tool. The probe response may comprise the encrypted secret. Once received, the field tool may decrypt the secret using the field tool private key, and extract the secret.

[0052] Once the secret has been extracted, the field tool may use the secret to establish a wireless connection with the device. For example, the field tool may establish a Wi-Fi communication session via an Extensible Authentication Protocol (EAP) using a pre-shared key (PSK), e.g. using an EAP-PSK authentication procedure. More generally, it will be understood that any other secret based authentication procedures may be used to establish the wireless communication session.

[0053] After the secure wireless communication session is established, the field tool and device may securely transfer data, facilitating e.g. troubleshooting of the deployed device in field by the field tool, and / or any procedures requiring secure data transfer such as device updates. Various methods and apparatus are described herein with reference to block diagrams and sequence diagrams of apparatus (systems and / or devices) and methods which may be implemented as computer-implemented methods and / or computer program products. It is understood that a block of the block diagrams and / or sequence diagrams and combinations of blocks in the block diagrams, communications in the sequence diagrams can be implemented by computer program instructions that are performed by one or more computer circuits associated with the entities of the system. These computer program instructions may be provided to a processor circuit of a general purpose computer circuit, special purpose computer circuit, and / or other programmable data processing circuit to produce a machine, such that the instructions, which execute via the processor of the computer and / or other programmable data processing apparatus, transform and control transistors, values stored in memory locations, and other hardware components within such circuitry to implement the functions / acts specified in the block diagrams and / or sequence diagrams, and thereby create means (functionality) and / or structure for implementing the functions / acts specified in the block diagrams and / or sequence diagrams.

[0054] Computer program instructions may also be stored in a computer-readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable medium produce an article of manufacture including instructions which implement the functions / acts specified in the block diagrams and / or flowchart block or blocks.

[0055] A tangible, non-transitory computer-readable medium may include an electronic, magnetic, optical, electromagnetic, or semiconductor data storage system, apparatus, or device. More specific examples of the computer-readable medium would include the following: a portable computer diskette, a random access memory (RAM) circuit, a read-only memory (ROM) circuit, an erasable programmable read-only memory (EPROM or Flash memory) circuit, a portable compact disc read-only memory (CD-ROM), and a portable digital video disc readonly memory (DVD / Blu-ray).

[0056] The computer program instructions may also be loaded onto a computer and / or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer and / or other programmable apparatus to produce a computer- implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions / acts specified in the block diagrams and / or sequence diagrams. Accordingly, the invention may be embodied in hardware and / or in software (including firmware, resident software, micro-code, etc.) that runs on a processor, which may collectively be referred to as "circuitry," "a module" or variants thereof.

[0057] It should also be noted that in some alternate implementations, the functions / acts noted in the blocks or sequence diagram stages may occur out of the order noted in the sequence diagrams. For example, two blocks shown in succession, or two sequence communications shown in succession in a sequence diagram, may in fact be executed substantially concurrently or the blocks / sequence communications may sometimes be executed in the reverse order, depending upon the functionality / acts involved. Moreover, the functionality of a given block of the flowcharts and / or block diagrams, or sequence communication of the sequence diagrams, may be separated into multiple blocks or communications, and / or the functionality of two or more blocks of the flowcharts and / or block diagrams may be at least partially integrated. Finally, other blocks or sequence communications may be added / inserted between the blocks / sequence communications that are illustrated.

[0058] Although the disclosure has been described in terms of preferred embodiments as set forth above, it should be understood that these embodiments are illustrative only and that the claims are not limited to those embodiments. Those skilled in the art will be able to make modifications and alternatives in view of the disclosure, which are contemplated as falling within the scope of the appended claims. Each feature disclosed or illustrated in the present specification may be incorporated in the disclosure, whether alone or in any appropriate combination with any other feature disclosed or illustrated herein.

Claims

CLAIMS:1 . A method of provisioning a first device with a secret for establishing a wireless communication session with a second device, wherein the second device is a deployed field device, the method comprising: receiving, by the second device, a probe request, wherein the probe request comprises a first public key of a first private-public key pair and a second public key of a second private-public key pair, wherein the first public key is signed using the second private key of the second private-public key pair and the second public key is signed using a third private key of a third private-public key pair; validating the second public key using a third public key of the third private-public key pair; extracting the second public key; validating the first public key using the second public key; extracting the first public key; generating a secret for establishing a wireless communication session; encrypting the secret using the first public key; and transmitting the encrypted secret to the first device.

2. The method of claim 1 , wherein the wireless communication session utilises wireless network protocols based on the IEEE 802.1 1 family of standards.

3. The method of claim 2, wherein the wireless communication session is a Wi-Fi communication session.

4. The method of claim 1 , comprising: generating, by the first device, the first private-public key pair; transmitting the first public key to a headend system; receiving, by the first device, the first public key signed using the second private key.

5. The method of claim 1 , comprising: establishing a secure wireless communication session between the first device and the second device.

6. The method of claim 6, wherein establishing the secure wireless communication session comprises authenticating the communication session using the secret.

7. The method of claim 1 , wherein generating the secret comprising generating a random secret.

8. The method of claim 1 , wherein the second device is a utility meter.

9. The method of claim 1 , comprising processing the probe request.

10. A utility meter comprising a means for receiving wireless communications, the utility meter configured to: receive, from an external device, a probe request, wherein the probe request comprises a first public key of a first private-public key pair and a second public key of a second private-public key pair, wherein the first public key is signed using the second private key of the second private-public key pair and the second public key is signed using a third private key of a third private-public key pair; validate the second public key using the third public key of the third private-public key pair; extract the second public key; validate the first public key using the second public key; extract the first public key; generate a secret for establishing a wireless communication session; encrypt the secret using the first public key; and transmit the encrypted secret to the external device.1 1 . The utility meter of claim 10, configured to establish a secure wireless communication session with the external device based on the secret.

12. The utility meter of claim 10, wherein prior to receiving the probe request, the utility meter is configured in a wireless communications receive only mode.

13. The utility meter of claim 12, wherein responsive to validating the probe request, the utility meter is configured to switch to a wireless communication transmission mode.

14. The utility meter of claim 10, wherein the wireless communications are Wi-Fi communications.

15. The utility meter of claim 10, wherein the utility meter is configured to process the probe request.

16. A field tool for establishing wireless communication with a utility meter, the field tool comprising a means for transmitting wireless communications, the field tool configured to: transmit, to the utility meter, a probe request, wherein the probe request comprises a first public key of a first private-public key pair and a second public key of a second privatepublic key pair, wherein the first public key is signed using the second private key of the second private-public key pair and the second public key is signed using a third private key of a third private-public key pair; receive an encrypted secret from the utility meter; decrypt the secret using the first private key; and establish a secure wireless communication session with the utility meter using the secret.

17. The field tool of claim 16, wherein the wireless communications are Wi-Fi communications.

18. A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method of claim 1 .

19. A computer-readable medium comprising instructions which, when executed by a computer, cause the computer to carry out the method of claim 1 .

Citation Information

Patent Citations

  • Intelligent electric meter control module and method based on CCKS (Combined Credit Key System)

    CN107508842A

  • Utility meter supporting a remote display

    US20200380619A1

  • Information processing system and information processing method

    US20240096150A1

  • Distributed access control

    WO2020239179A1