BLE Mesh Provisioning With Device-Specific Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
BLE Mesh devices face security threats and privacy issues due to static Out of Band (OOB) or no-OOB verification schemes, allowing unauthorized provisioners to control devices within scanning range, compromising security and user privacy.
Innovation Solution
A method involving calculating a unique provisioning authorization value based on identification information for both BLE Mesh devices and provisioners, with bidirectional security verification to ensure proper binding and protect privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If static OOB or no-OOB verification scheme is used, then provisioning efficiency is improved, but security is compromised allowing unauthorized provisioners to control devices
Solution Approach 1:
The patent transforms the static provisioning authorization value into a dynamic one by introducing device-specific identification information. The provisioning authorization value is now generated differently for each device based on its unique identification, making the provisioning process adaptive and secure while maintaining efficiency.
Solution Approach 2:
The patent applies different verification approaches to different devices by incorporating device-specific identification information into the provisioning authorization value generation process. Each device receives a customized provisioning authorization value tailored to its unique identity, enabling selective security verification.
2Ease of operation
If any provisioner within scanning range can control the device, then ease of operation is improved, but user privacy and device security are compromised
Solution Approach 1:
The patent implements a feedback mechanism where the device verifies the provisioner's authorization value against its own identification information. This bidirectional verification ensures that only authorized provisioners can control the device, while maintaining ease of operation for legitimate users.
Solution Approach 2:
The patent creates an asymmetric relationship between provisioners and devices by binding each device to a specific provisioner through unique identification information. This asymmetry ensures that a device can be controlled by its authorized provisioner while preventing unauthorized access from other provisioners within range.
Data Source
AI summary
The present disclosure relates communication technology and provides a BLE Mesh device provisioning method, apparatus, and device. The method includes: a BLE Mesh device calculating a first provisioning authorization value based on authorization reference information; the BLE Mesh device performing security verification with a provisioner using the first provisioning authorization value; the provisioner determining a second provisioning authorization value; the provisioner performing security verification with the BLE Mesh device using the second provisioning authorization value; the provisioner transmitting provisioning data to the BLE Mesh device when the security verification succeeds; and the BLE Mesh device receiving the provisioning data from the provisioner when the security verification succeeds. The embodiment of the present disclosure ensures proper binding between the BLE Mesh device and its corresponding provisioner by strongly associating the provisioning authorization value with the BLE Mesh device.


