Bluetooth Mesh Security Credential Recovery via Local Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for recovering security credentials in Bluetooth mesh networks are unreliable, inefficiently use network resources, and pose security risks, especially in areas with limited or no Internet connectivity.

Innovation Solution

Generating security credentials such as the network key, application key, and device key based on user login information, allowing for local recovery within the Bluetooth mesh network without relying on cloud services, and using cryptographic functions to ensure security and interoperability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud based storage service is used to save security credentials for recovery, then security credentials can be recovered, but Internet connectivity is required which consumes additional network resources and reduces reliability in remote areas

Engineering Contradiction:
Improvecredential recovery reliabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the credential recovery function from cloud-based storage and implements it locally within the Bluetooth mesh network. Security credentials are stored in local nodes (provisioning device, anchor device, or both) rather than requiring external cloud services, eliminating the need for Internet connectivity during recovery operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces local intermediary devices (provisioning device and anchor device) that mediate the credential recovery process. These devices store security credentials locally and enable recovery through direct Bluetooth mesh communication, replacing the cloud service intermediary that requires Internet connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud service is used for credential recovery, then credentials can be recovered, but additional setup steps are required which consume more network resources

Engineering Contradiction:
Improvecredential recovery reliabilityVSAvoidsetup process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-configuring security credentials in local devices (provisioning device and/or anchor device) during network setup. This preliminary local configuration eliminates the need for subsequent cloud service account creation and credential association steps, reducing overall setup complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cloud based recovery approach is used, then credentials can be recovered, but security and privacy concerns arise due to sharing personal information

Engineering Contradiction:
Improvecredential recovery reliabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personal information (email address, phone number) from the credential recovery process. By storing credentials locally in Bluetooth mesh devices, the system eliminates the need for users to share personal information with cloud services, removing the security and privacy risks associated with data sharing.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If cloud service is used for credential recovery, then credentials can be recovered, but the approach is unreliable in areas with poor or no Internet connectivity

Engineering Contradiction:
Improvecredential recovery reliabilityVSAvoidadaptability to remote areas
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements self-service capability within the Bluetooth mesh network by enabling devices to recover credentials autonomously using locally stored information. The provisioning device or anchor device can regenerate or retrieve security credentials without external cloud service assistance, making the system self-sufficient in remote areas with no Internet connectivity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11399279B2Security credentials recovery in Bluetooth mesh network
Publication Date: 2022.07.26 STMICROELECTRONICS INT NV
  • US11399279B2 patent drawing
  • US11399279B2 patent drawing
  • US11399279B2 patent drawing

AI summary

In accordance with embodiments, methods for the recovery of security credentials of a Bluetooth mesh network are disclosed. A computing device of the Bluetooth mesh network receives user login information, and generates a network key of the Bluetooth mesh network based on the user login information. The computing device generates an application key of a first node to be provisioned based on user login information. A device key is generated using the unicast address of the first node and part of user credentials. The current sequence number is recovered by one of the four techniques depending on the characteristics of the network. The unicast addresses of the nodes are assumed to be sequential and later validated by sending messages. IV index is recovered using processes defined in the Bluetooth mesh standard. After recovery of the above parameters, the mesh network can operate normally using the aforementioned computing device.