Mesh Network Provisioning With Centralized Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
HVAC systems face challenges in efficiently provisioning and servicing mesh networks, particularly in managing device keys and communication protocols across different devices within the network, which affects the reliability and scalability of the mesh network operations.
Innovation Solution
A method and system for provisioning and servicing mesh networks in HVAC systems, involving the use of computer systems to receive user instructions for initiating meshnet provisioning and servicing, where devices are connected via different communication protocols, and provisioning data including keys is transferred and stored for later use, enabling efficient management and operation of the mesh network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices are provisioned with unique keys for security, then network security is improved, but device complexity and key management burden increase
Solution Approach 1:
The patent introduces a commissioning device as an intermediary that centralizes key generation, storage, and management. This mediator handles all cryptographic operations including generating key pairs, storing private keys securely, and managing key lifecycle, thereby maintaining network security while relieving individual devices of key management complexity
Solution Approach 2:
The patent merges key generation, storage, and management functions into a single commissioning device. By combining these previously distributed functions into one centralized component, the system maintains security through unified key control while reducing overall system complexity and making key management more tractable
2Adaptability or versatility
If multiple communication protocols are supported for device compatibility, then adaptability is improved, but device complexity and protocol management overhead increase
Solution Approach 1:
The commissioning device serves as a protocol intermediary that translates between different communication protocols. It interfaces with provisioned devices using their native protocols while communicating with the network using standardized protocols, thereby achieving multi-protocol compatibility without requiring each device to support multiple protocols directly
Solution Approach 2:
The commissioning device is designed with universal multi-functionality to handle multiple communication protocols simultaneously. It can provision devices using different protocols (Thread, Wi-Fi, Ethernet) and manage them through a unified interface, making the system adaptable to diverse devices while keeping individual device complexity low
3Speed
If provisioning data is stored locally on each device, then access speed is improved, but data consistency and security management become difficult
Solution Approach 1:
The commissioning device acts as a mediator that maintains a centralized record of all provisioning data including key pairs and network credentials. While devices store necessary data locally for fast access, the commissioning device holds the master copy and can update or revoke credentials, ensuring data consistency and enabling centralized security management
Solution Approach 2:
The system performs preliminary provisioning actions through the commissioning device before devices operate independently. All key generation, distribution, and initial configuration are completed in advance through the mediator, ensuring devices have correct data for immediate operation while the commissioning device retains authority for future updates and consistency maintenance
Data Source
AI summary
In an embodiment, a method includes receiving a user instruction to initiate meshnet provisioning. The method also includes provisioning a first device to a meshnet, where the provisioning the first device yields first provisioning data that includes one or more keys. The method also includes provisioning a second device to the meshnet, where the provisioning the second device yields second provisioning data that includes include one or more keys. The method also includes transferring provisioning data that includes the first provisioning data and the second provisioning data to storage on the first device. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.


