Bluetooth Low Energy Peripheral Onboarding with Hash Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing protocols for securely onboarding IoT devices to wireless networks are complex, unreliable, and susceptible to security threats, particularly 'man-in-the-middle' attacks, lacking user-friendly interfaces and sufficient reliability.
Innovation Solution
A method utilizing a private-public key pair, where the private key is stored on the peripheral device and the public key on the cloud-based network system, verifies hash values generated with the private key to ensure secure onboarding, involving a mobile device for communication and encryption/decryption processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional onboarding mechanisms are used for IoT devices, then network configuration can be conveyed, but the process becomes complex and unreliable
Solution Approach 1:
The peripheral device autonomously performs authentication by generating and transmitting hash values using its pre-stored private key, eliminating the need for user intervention in the authentication process. The device self-verifies its identity to the cloud-based processor without requiring manual configuration or user input.
Solution Approach 2:
The private key is pre-stored on the peripheral device during manufacturing, and the public key is pre-configured in the cloud-based processor. This preliminary setup eliminates the need for complex real-time key exchange during onboarding, simplifying the user experience while maintaining security.
2Reliability
If existing onboarding protocols are used, then device authentication can be achieved, but security vulnerabilities remain
Solution Approach 1:
The patent replaces traditional mechanical or manual authentication methods with cryptographic hash value verification. The peripheral device generates hash values using its private key, and the cloud-based processor verifies these hashes using the corresponding public key, providing secure authentication that resists man-in-the-middle attacks.
Solution Approach 2:
The hash value acts as an intermediary between the peripheral device and the cloud-based processor. Instead of directly transmitting sensitive information or using vulnerable authentication protocols, the system uses encrypted hash values as a secure intermediary to verify device identity without exposing private keys or susceptible data.
3Device complexity
If peripheral devices lack user interface, then device simplicity is maintained, but configuration becomes difficult
Solution Approach 1:
The peripheral device without a user interface autonomously handles authentication by automatically generating and transmitting hash values. The device self-configures its authentication credentials during manufacturing and maintains them securely, eliminating the need for user interaction while keeping the device simple.
Solution Approach 2:
The mobile device serves as an intermediary between the user and the peripheral device. Users interact with the mobile device to initiate the onboarding process, while the peripheral device without a user interface automatically responds with hash values, bridging the gap between user needs and device simplicity.
Data Source
AI summary
A method and system are provided for securely onboarding a Bluetooth Low Energy peripheral device or other peripheral device operating over a personal area network (PAN) onto a cloud-based network system. The method includes providing a private-public key pair, wherein the private key is stored on the peripheral device and the public key is stored on a database within the cloud-based network system. Upon user activation, the peripheral device begins advertising, using a PAN communications protocol, a first hash value generated with the private key, which is received at the cloud-based processor and verified with the corresponding public key. In response to verifying the first hash value, the cloud-based processor transmits a public key encrypted random code, which is received at the peripheral device and decrypted with the private key. In response, the peripheral device then transmits a second hash value generated with the private key, which is also received at the cloud-based processor and is then verified with the public key.


