Out-of-band key type indication for wireless network configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network configuration protocols, such as Device Provisioning Protocol (DPP), face challenges in efficiently upgrading cryptographic security by determining the highest encryption strength supported by enrollee devices and selecting appropriate key types without resorting to trial and error.
Innovation Solution
The method involves an out-of-band (OOB) communication for an enrollee device to provide a first public key and indications of supported second public key types to a commissioning device. The commissioning device then selects appropriate key types and requests a second public key or uses a third key to sign data objects, enabling efficient configuration and connection to a wireless network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional configuration protocols are used without early key type indication, then compatibility with existing devices is maintained, but cryptographic security upgrading becomes inefficient requiring trial and error
Solution Approach 1:
The patent applies preliminary action by having the enrollee device indicate supported key types in advance during the configuration process. The enrollee provides an indication of supported second public key types before the commissioning device attempts to use them, allowing the commissioning device to select appropriate key types without trial and error, thus saving time while maintaining security upgrades.
2Reliability
If the commissioning device requests a second public key of a different type, then cryptographic strength is upgraded, but compatibility issues may arise if the enrollee does not support the requested key type
Solution Approach 1:
The patent resolves this contradiction by having the enrollee device provide an indication of supported second public key types in advance. This preliminary information allows the commissioning device to select a key type that is both stronger and compatible with the enrollee's capabilities, avoiding compatibility issues while achieving cryptographic upgrades.
Solution Approach 2:
The patent applies parameter changes by allowing the commissioning device to change the key type parameter from the first public key type to a second public key type with higher cryptographic strength. The enrollee's indication of supported key types ensures that the parameter change remains within compatible bounds, resolving the contradiction between upgrading encryption strength and maintaining compatibility.
3Adaptability or versatility
If multiple key types are supported and selectable, then cryptographic flexibility and security upgrading are enabled, but device complexity increases
Solution Approach 1:
The patent applies the taking out principle by extracting the key type indication information from the main configuration protocol flow and handling it separately through out-of-band communication. This separation reduces the complexity of the main configuration protocol while still enabling multiple key type selections and cryptographic flexibility.
Data Source
AI summary
There is provided a method, commissioning and enrollee devices and a system thereof. The method is one of configuring an enrollee device for communications in a wireless network, the method be arranged for execution by a commissioning device (9) and an enrollee device (4, 5). The commissioning and enrollee devices may be arranged to communicate using a wireless communication protocol and participate in a commissioning protocol, the commissioning protocol being arranged to configure the enrollee device to communicate in the wireless network. The method comprises executing a configuration protocol, which comprises sending by the commissioning device a message comprising an indication of a selection of a type of public key, the type of public key being selected from a plurality of types of public key obtained from the enrollee device, in an out-of-band communication wherein a key of the type of public key selected is to be used for later phases of the configuration protocol and the type of public key selected is different from the type of a public key obtained from the enrollee for bootstrapping.


