Push-Button Protocol With Device Confirmation for Secure Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless networking protocols, such as those conforming to IEEE 802.11 standards, are vulnerable to man-in-the-middle attacks during device configuration and require lengthy waiting times, which can be exploited by attackers and are inconvenient for users.
Innovation Solution
A push-button protocol that includes an additional button press to confirm the intended device, allowing for a shortened waiting time and improved security by ensuring messages are received from a single device before proceeding to a secure phase.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a waiting time is provided for device configuration, then reliability of connection establishment is improved, but security is worsened due to extended vulnerability window for man-in-the-middle attacks
Solution Approach 1:
The patent allows the waiting time to be shortened or skipped when a second button press is detected, enabling the protocol to rush through the vulnerable period quickly once user confirmation is received, thereby reducing the attack window while maintaining reliability
2Object-affected harmful factors
If the waiting time is shortened, then security is improved by reducing the attack window, but reliability is worsened due to reduced time for proper device discovery
Solution Approach 1:
The patent introduces a second button press as an intermediary confirmation mechanism that allows the system to safely shorten the waiting time. This intermediary action serves as proof of user intent, enabling reduced waiting time without compromising reliability
3Object-affected harmful factors
If an additional button press is required, then security is improved by confirming intended device, but ease of operation is worsened due to extra user action required
Solution Approach 1:
The system uses the device's own button press detection capability to provide self-service security verification. The additional button press serves as a simple, intuitive confirmation that leverages the existing physical interface rather than requiring complex authentication mechanisms
Data Source
AI summary
Thus there is provided a method and device for performing a push-button protocol between a first and a second device. The method comprises sending, by the first device, a first message after receiving a first button press, listening for a second message until either a waiting time is over or until a third button press is received, whichever is earlier, proceeding to a secure phase of the push-button protocol if one or more second messages have been received from only one device, and aborting the push button protocol if no second messages have been received or if second messages have been received from more than one device. In another case the method comprises listening for a first messages after receiving a first button press, sending, by the first device, a second message if a first message has been received, until either a waiting time is over or until a third button press, whichever is earlier, proceeding to the secure phase if one or more first messages have been received from only one device, and aborting the push button protocol if no second messages have been received or if second messages have been received from more than one device.


