Bluetooth Mesh Authentication Offloading to Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Bluetooth mesh network authentication methods are resource-intensive for provisioners, limiting the deployment of Bluetooth mesh networks due to high processing demands.

Innovation Solution

A Bluetooth mesh network architecture and provisioning authentication method that globalizes authentication by using a server to conduct authentication with Bluetooth devices via gateways, reducing the processing load on gateways and simplifying network deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed by provisioners in Bluetooth mesh networks, then device security is improved, but network resource consumption increases

Engineering Contradiction:
Improvedevice securityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication function from provisioners and relocates it to a dedicated authentication server. This separation allows provisioners to focus on provisioning tasks while the server handles authentication, reducing the computational burden and resource consumption on provisioners while maintaining security through centralized authentication processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between provisioners and Bluetooth devices. This mediator handles the authentication process, offloading the computational work from provisioners and reducing network resource consumption while ensuring secure device authentication through a dedicated security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication processing is centralized on provisioners, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidprovisioner complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication processing logic from provisioners and places it in a dedicated authentication server. This reduces the complexity of provisioners by removing the need for them to perform complex authentication operations, while authentication security is maintained through the specialized server infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication server provides a universal authentication service that can handle multiple authentication requests from different provisioners and devices. This centralized approach maintains high authentication security through standardized processes while reducing individual device complexity by consolidating authentication functionality in a single multi-functional server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If gateways perform authentication in Bluetooth mesh networks, then network security is improved, but gateway processing load increases

Engineering Contradiction:
Improvenetwork securityVSAvoidgateway processing load
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts the authentication function from gateways and relocates it to a dedicated authentication server. This separation reduces the processing load on gateways by removing authentication operations, allowing them to focus on their primary function of routing mesh network traffic, while network security is maintained through centralized authentication processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11259178B2Bluetooth mesh network provisioning authentication
Publication Date: 2022.02.22 ALIBABA GROUP HOLDING LTD
  • US11259178B2 patent drawing
  • US11259178B2 patent drawing
  • US11259178B2 patent drawing

AI summary

A first set of device authentication parameters for a to-be-authenticated Bluetooth device in a Bluetooth mesh network is determined based at least in part on device identification information associated with the to-be-authenticated Bluetooth device. First authentication information is generated based at least in part on the first set of device authentication parameters and a first random number. The first authentication information and the first random number are forwarded to the to-be-authenticated Bluetooth device. Second authentication information and a second random number associated with the to-be-authenticated Bluetooth device are received, wherein the second authentication information is generated based at least in part on a second set of device authentication parameters and the second random number. The to-be-authenticated Bluetooth device is authenticated based at least in part on the second authentication information and the second random number.