IoT Device Credential Provisioning via Cloud Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in configuring new WiFi-enabled IoT devices with network credentials, especially when out of the WiFi coverage area or with multiple networks, leading to failed registration and inability for OEMs to send devices pre-connected to WiFi networks.

Innovation Solution

An IoT platform with a predefined networking protocol stack and an IoT hub that allows devices to be paired using barcodes or QR codes, enabling secure key exchange and storage of network credentials for seamless connection to WiFi networks, even when the device is not within the coverage area.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional WiFi registration process is used, then device can connect to WiFi network, but user must be physically present within WiFi coverage area and manually configure credentials

Engineering Contradiction:
ImproveDevice configuration processVSAvoidRegistration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring devices with credentials during manufacturing. The device is provisioned with network credentials before reaching the user, eliminating the need for manual configuration at setup time. This resolves the contradiction by making the device ready to connect automatically without requiring user presence or manual credential entry.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a cloud-based provisioning service that acts as a mediator between the device and WiFi network. The service securely transmits credentials to the device through intermediate communication channels (such as cellular networks or other transport mechanisms), allowing configuration without direct WiFi connection during setup.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If device is configured outside WiFi coverage area, then device can be set up remotely, but secure transmission of credentials becomes problematic

Engineering Contradiction:
ImproveConfiguration location flexibilityVSAvoidCredential security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the mechanical requirement of physical proximity for secure credential transmission with alternative communication mechanisms. Instead of requiring direct WiFi connection (mechanical constraint), the system uses cloud-based services and secure communication protocols that can transmit credentials through various networks (cellular, email, other intermediaries), enabling remote configuration while maintaining security through cryptographic methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual WiFi credential entry is required, then device can connect to network, but process fails at low signal strength or edge coverage

Engineering Contradiction:
ImproveRegistration success rateVSAvoidConfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By pre-configuring devices with credentials during manufacturing, the patent eliminates the need for real-time credential entry during device setup. This preliminary configuration ensures that devices have the necessary authentication information stored securely before deployment, guaranteeing connection success regardless of signal strength during the setup process.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If multiple WiFi networks exist in premises, then network coverage is extended, but each network requires separate registration process

Engineering Contradiction:
ImproveNetwork coverageVSAvoidRegistration process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a single, unified provisioning process that can handle multiple WiFi networks. The cloud-based service and pre-configured device approach provides a universal solution that works across different network configurations, eliminating the need for separate registration procedures for each network. The device can be provisioned once and then connect to multiple networks using the established credentials management system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11626974B2System and method for securely configuring a new device with network credentials
Publication Date: 2023.04.11 AFERO INC
  • US11626974B2 patent drawing
  • US11626974B2 patent drawing
  • US11626974B2 patent drawing

AI summary

A system, apparatus, and method for sharing network credentials. One embodiment of a method comprises: establishing a Bluetooth connection between a first Internet of Things (IoT) device and a mobile device of a first user having an IoT app installed, the mobile device to couple the first IoT device to an IoT service; receiving a request from a user from the mobile device to configure the first IoT device using network credentials from a second IoT device, the second IoT device registered with an account of the user on the IoT service and configured to connect to a secure network of the user with the network credentials; establishing a communication channel between the first IoT device and the second IoT device through the IoT service and the mobile device to obtain the network credentials; and using the network credentials at the first IoT device to securely connect to the secure network.