Device-to-Device Network Profile Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing onboarding process for electronic devices in restricted access networks, such as enterprise wireless networks, is cumbersome and time-consuming, requiring repeated authentication and provisioning procedures for multiple devices.
Innovation Solution
A method where a first user device performs a full onboarding procedure with a provisioning server, and subsequent user devices can obtain provisioning information from the first device, allowing them to skip authentication and obtain a network profile, thereby streamlining the onboarding process for multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a full onboarding procedure is performed for each electronic device, then network security and proper provisioning are ensured, but the onboarding process becomes time-consuming and cumbersome
Solution Approach 1:
The patent implements device-to-device provisioning where a first electronic device that has completed onboarding acts as a provisioning source for subsequent devices. The provisioning information (including network credentials and configuration) is copied from the first device to additional devices, eliminating the need for repeated full onboarding procedures while maintaining security through the use of encrypted provisioning data and authentication mechanisms.
Solution Approach 2:
The first electronic device performs the complete onboarding procedure in advance, including authentication with the provisioning server and retrieval of provisioning information. This preliminary action allows subsequent devices to skip the authentication step and directly receive provisioning data from the first device, significantly reducing onboarding time for multiple devices.
2Reliability
If authentication procedures are repeated for each device, then security is maintained, but user convenience and efficiency are reduced
Solution Approach 1:
The patent enables provisioning information to be copied from a first electronic device to additional devices without requiring repeated authentication. The provisioning data includes authentication credentials that were obtained in the initial onboarding, allowing subsequent devices to be provisioned securely through data copying rather than repeated authentication ceremonies.
Solution Approach 2:
The first electronic device acts as an intermediary between the provisioning server and subsequent devices. It stores and transmits provisioning information to other devices, serving as a secure mediator that eliminates the need for direct authentication interactions between the provisioning server and each individual device.
3Manufacturing precision
If multiple devices are onboarded sequentially through full procedures, then each device is properly configured, but the overall provisioning efficiency decreases
Solution Approach 1:
The patent implements a provisioning copy mechanism where the first electronic device transmits provisioning information to additional devices. This copying approach ensures that each device receives identical, properly configured provisioning data (network credentials, security parameters, etc.), maintaining provisioning accuracy while dramatically increasing provisioning speed for multiple devices.
Solution Approach 2:
The patent merges the provisioning operations for multiple devices into a single initial authentication event. The first device performs the complete provisioning procedure once, and this single provisioning action is then replicated across multiple devices through direct device-to-device data transfer, combining what would otherwise be separate sequential operations into one efficient process.
Data Source
AI summary
In some examples, a first user device receives, from a second user device, a provisioning reference and an access token, the provisioning reference and the access token obtained by the second user device as part of a provisioning procedure performed by the second user device with a server. The first user device accesses the server using the provisioning reference and the access token to provision the first user device. The first user device receives, from the server, a network profile in response to the access token. The first user device connects to a network using the network profile.


