Access Point Untrusted Configurator Detection via Enrollee Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Device Provisioning Protocol (DPP) environments, unprovisioned devices can be vulnerable to connecting with untrusted configurators that may lead to data leakage, as they lack mutual authentication and can accept configuration from fake DPP service networks.

Innovation Solution

Implementing a detection scheme where an access point simulates an enrollee to broadcast configuration requests with simulated authentication information, allowing identification of untrusted configurators by responding to configuration responses and transmitting their device information to a network device for remedial action.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unprovisioned devices accept configuration requests from any configurator to enable easy network provisioning, then device provisioning simplicity is improved, but security against untrusted configurators deteriorates

Engineering Contradiction:
Improveprovisioning simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by having the access point simulate an enrollee and broadcast configuration requests with simulated authentication information before actual device provisioning. This allows the system to pre-identify potential untrusted configurators in the environment, establishing a security check mechanism before real devices connect, thus maintaining both provisioning simplicity and security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access point acts as an intermediary between unprovisioned devices and configurators. By simulating an enrollee and mediating the configuration request process, the access point can detect untrusted configurators and prevent them from directly provisioning devices, thus protecting against security threats while maintaining the DPP-based simple provisioning flow for trusted configurators

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the access point broadcasts configuration requests with simulated authentication information to detect untrusted configurators, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveuntrusted configurator detectionVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access point performs multiple functions: it serves as a network gateway, an enrollee simulator for security detection, and a mediator for configuration requests. By making the access point multi-functional, the patent avoids adding separate dedicated detection devices, thus improving untrusted configurator detection capability without significantly increasing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access point performs self-service by autonomously simulating enrollee authentication information and broadcasting configuration requests to detect untrusted configurators. This self-detected mechanism eliminates the need for external detection systems or manual security verification, improving detection capability while keeping the system simple through automated self-operation

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240284170A1Detection of untrusted configurator
Publication Date: 2024.08.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20240284170A1 patent drawing
  • US20240284170A1 patent drawing
  • US20240284170A1 patent drawing

AI summary

Implementations of the present disclosure relate to detection of an untrusted configurator. In the implementations, an access point (AP) receives enrollee authentication information simulated by the network device from a network device. Then, the AP simulates an enrollee and broadcasts a configuration request including the enrollee authentication information. When a configurator responds to the configuration request, the AP identifies the configurator as an untrusted configurator, and then the AP transmits device information of the untrusted configurator to the network device. In this way, the untrusted configurator in the serving range can be detected, thereby avoiding the devices being provisioned to connect to untrusted networks.