Backscatter Device Onboarding via AP RF Energizing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in securely onboarding backscatter devices (BKDs) with limited power sources onto local wireless networks, particularly in providing sufficient energy for certificate enrollment processes and ensuring secure communication within these networks.
Innovation Solution
The method involves detecting BKDs at an access point, validating their identity using an initial device identifier, energizing them to complete a certificate enrollment process, and replacing the initial identifier with a local device identifier to facilitate secure communication by harnessing ambient RF energy for power.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If backscatter devices use ambient RF energy for power, then device power consumption is reduced, but insufficient energy remains for certificate enrollment processes
Solution Approach 1:
The access point performs preliminary energizing of the backscatter device before the certificate enrollment process. The AP transmits RF energy to charge the BKD's energy storage element (capacitor or battery) in advance, ensuring sufficient energy is available when the enrollment process needs to execute. This preliminary action resolves the contradiction by separating the energy accumulation phase from the energy consumption phase.
Solution Approach 2:
The access point acts as an intermediary energy source during the onboarding process. The AP provides supplemental RF energy to the BKD through dedicated energizing transmissions, mediating between the BKD's limited ambient harvesting capability and the high energy requirements of certificate enrollment. This intermediary support enables the enrollment process without requiring the BKD to independently generate all necessary energy.
2Ease of operation
If backscatter devices are onboarded with initial device identifiers, then device identification is simplified, but network security is compromised
Solution Approach 1:
The system performs preliminary validation of the initial device identifier during the onboarding process before replacing it with a secure local identifier. The AP validates the IDevID against a repository to confirm the BKD is authorized, then proceeds with certificate enrollment to issue a secure LDevID. This preliminary validation maintains security while allowing simplified initial identification.
Solution Approach 2:
The device identifier parameter transitions from an initial state (IDevID) to a final state (LDevID) through the onboarding process. The BKD starts with a simplified IDevID for easy detection and validation, then undergoes certificate enrollment that replaces it with a cryptographically secure LDevID. This parameter transformation resolves the contradiction by using different identifier types at different stages of the device lifecycle.
3Reliability
If certificate enrollment is performed during onboarding, then secure communication is enabled, but the process fails due to insufficient device energy
Solution Approach 1:
The access point performs preliminary energy provisioning before initiating certificate enrollment. The AP detects the BKD, validates its identifier, then transmits RF energy to charge the BKD's storage element. Only after confirming sufficient energy availability does the AP proceed with certificate enrollment, ensuring the process completes successfully and enables secure communication.
Solution Approach 2:
The access point serves as an intermediary energy provider during certificate enrollment. The AP transmits dedicated RF energy transmissions to the BKD, acting as a temporary power source that bridges the gap between the BKD's limited ambient harvesting and the high energy demands of cryptographic operations. This intermediary support ensures enrollment completion and secure communication establishment.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enables the secure onboarding of BKDs onto local networks, ensuring secure communication by providing sufficient energy for certificate enrollment and replacing initial device identifiers with local ones, thereby enhancing network security and device connectivity.
Implementation Method 1
Some devices such as backscatter devices (BKDs) may utilize ambient power to harvest energy from ambient sources, including radio frequency (RF) energy, to provide power for the various functions of the BKD.
Implementation Method 2
Onboarding the BKD to the local network may include energizing the BKD to provide sufficient energy for a certificate enrollment process to be completed
Data Source
AI summary
In Wi-Fi 8, backscatter devices (BKDs) may be viewed as part of the 802.11 wireless local area network (WLAN). BKDs in a WLAN have limited transmission interactions with a Wi-Fi access point (AP). Onboarding BKDs to the WLAN is described, which allows for the AP and BKD to participate as elements of the same local network, with security controls. The onboarding of the BKD to a WLAN may occur after discovery of the BKD at an AP and includes replacing an Initial Device Identifier (IDevID) on the BKD with a Local Device Identifier (LDevID) in order to provide for secure communications between the BKD and the WLAN.


