Configurator Key Package for DPP Interoperability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device provisioning protocols face challenges in efficiently sharing and managing configurator keys across multiple devices within a network, leading to complexity and reduced interoperability.

Innovation Solution

The protocol generates a configurator key package including a private signing key and public verification key, which is encrypted and stored for backup or shared among configurator devices, allowing secure decryption and use for configuring enrollee devices, utilizing bootstrapping techniques for trust establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If configurator keys are shared across multiple devices, then interoperability and ease of adding new devices is improved, but key management complexity and security risks increase

Engineering Contradiction:
ImproveinteroperabilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a backup copy of the configurator key package and stores it in a separate location (such as a portable storage device or cloud storage). This copy can be used by additional configurator devices without requiring complex key sharing mechanisms. The backup copy serves as a simple replica that enables interoperability while avoiding the complexity of real-time key synchronization and management across multiple devices.

Inventive Principle:
Principle #26Copying

2Reliability

If configurator key package is encrypted and stored for backup, then security is improved, but ease of restoring and accessing keys is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidease of restoring
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary encryption of the configurator key package before storing it in backup locations. By pre-encrypting the key package with appropriate encryption algorithms and storing it in secure formats, the system ensures that even if the backup storage is compromised, the keys remain protected. This preliminary security measure is designed to work seamlessly with automatic decryption protocols that occur during the restore process, minimizing user burden while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If multiple configurator devices use shared keys, then device provisioning scalability is improved, but trust establishment complexity increases

Engineering Contradiction:
Improveprovisioning scalabilityVSAvoidtrust establishment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a bootstrap device as an intermediary that facilitates trust establishment between multiple configurator devices and the network. The bootstrap device generates and distributes bootstrap keys that serve as a foundation for trust. When additional configurator devices need to be trusted, they can use the established bootstrap keys as a common reference point, avoiding the need for complex pairwise trust relationships between all configurator devices. This intermediary approach enables scalable trust establishment while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3530020B1Configurator key package for device provisioning protocol (DPP)
Publication Date: 2021.08.04 QUALCOMM INC
  • EP3530020B1 patent drawingFigure 1
  • EP3530020B1 patent drawingFigure 2
  • EP3530020B1 patent drawingFigure 3

AI summary

This disclosure provides systems, methods, and apparatus, including computer programs encoded on computer storage media, for enhancing a device provisioning protocol (DPP) to support multiple configurators. In one aspect, a first configurator device can export a configurator key package. In one aspect, the configurator key package may be used for backup and restore of the configurator keys. The configurator key package may include a configurator private signing key and, optionally, a configurator public verification key. A second configurator device may obtain the configurator key package and also may obtain decryption information which can be used to decrypt the configurator key package. Thus, in another aspect, both the first configurator device and the second configurator device can use the same configurator keys with the device provisioning protocol to configure enrollees to a network.