Intermediate Device Tunneling for Secure Wireless Pairing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for configuring Bluetooth or other wireless communication links between devices are cumbersome and lack security, as they rely on manual passcode entry and transmit sensitive information in cleartext, making them vulnerable to interception.

Innovation Solution

A system that uses an intermediate device to 'tunnel' commands and data between a host device and an accessory, allowing for secure configuration of wireless links through a point-to-point wired connection, using tunneling commands to repack and forward information in a format suitable for the accessory, thereby establishing and managing wireless connections without exposing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual passcode entry and cleartext transmission are used for Bluetooth configuration, then device interoperability is achieved, but security is compromised due to vulnerability to interception

Engineering Contradiction:
Improvedevice interoperabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediate device (such as a docking station or base unit) that acts as a secure mediator between the host device and accessory. This intermediary establishes a secure wired connection for configuration purposes, eliminating the need for cleartext wireless transmission of sensitive information while maintaining device interoperability. The intermediate device manages the pairing process and securely transmits configuration data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Bluetooth pairing information is transmitted wirelessly in cleartext, then configuration simplicity is maintained, but security is worsened due to interception risks

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The intermediate device serves as a secure intermediary that receives configuration information from the host device via a secure wired connection and forwards it to the accessory. This maintains configuration simplicity for the end user while eliminating security vulnerabilities associated with wireless cleartext transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the wireless electromagnetic transmission mechanism with a wired physical connection mechanism for transmitting sensitive configuration data. This substitution eliminates the security vulnerability of wireless cleartext transmission while maintaining the ease of configuration through the intermediate device's automated processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If an intermediate device is introduced to securely tunnel commands and data, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediate device is designed to perform multiple functions: it serves as a secure configuration channel, a charging station, a data synchronization point, and a Bluetooth manager. By consolidating these functions into a single device, the overall system complexity is managed despite the added security layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The intermediate device automatically manages the secure tunneling process, including establishing secure connections, encrypting/decrypting data, and coordinating communication between host and accessory. This automation eliminates the need for users to manually configure security settings, thereby improving security without significantly increasing operational complexity for end users.

Inventive Principle:
Principle #25Self-service

4Reliability

If tunneling commands are used to forward information through an intermediate device, then security is enhanced, but communication time increases due to additional processing steps

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The intermediate device establishes secure connections and pre-configures tunneling parameters before actual data transmission occurs. By preparing the secure communication channel in advance, the device minimizes the time penalty associated with security processing during active data transfer.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once the secure tunnel is established, the intermediate device maintains continuous encrypted communication channels, allowing data to flow continuously without repeated authentication handshakes. This continuity reduces the time overhead of security processing compared to establishing secure connections for each individual data transfer.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP2506536B1Communication of Information between a host device and an accessory via an intermediate device
Publication Date: 2013.09.18 APPLE INC
  • EP2506536B1 patent drawingFigure 1A~1B
  • EP2506536B1 patent drawingFigure 2
  • EP2506536B1 patent drawingFigure 3~4A

AI summary

A method for communicating information between a first electronic device and a second electronic device, the method comprising: receiving, by an intermediate device, a first tunneling command from a first electronic device, the first tunneling command conforming to a first protocol and incorporating a tunneled information item therein; converting, by the intermediate device, the first tunneling command to a second tunneling command, the second tunneling command conforming to a second protocol and incorporating the tunneled information item therein; and transmitting, by the intermediate device, the second tunneling command to a second electronic device, the second electronic device being configured to extract the tunneled information item from the second tunneling command, wherein the tunneled information item includes information usable to establish a wireless communication link between the first electronic device and the second electronic device.