Secure Bluetooth Peripheral Pairing via Backend Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Bluetooth pairing process for peripheral devices with information handling systems is not secure and requires user input, making it vulnerable to unauthorized access and cumbersome, as it relies on manual input of pairing credentials which can be intercepted or leaked.

Innovation Solution

An automatic peripheral device pairing management system that uses a backend management server to generate and store temporary keys and device identification data, allowing secure, out-of-band Bluetooth communication to verify and initiate pairing between peripheral devices and information handling systems without user intervention, ensuring only authorized devices can pair.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual pairing credentials are used for Bluetooth pairing, then user control and authorization are maintained, but security is compromised due to potential interception or leakage of credentials

Engineering Contradiction:
Improvepairing securityVSAvoidpairing convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the pairing credentials from the traditional manual input process and stores them securely in a credential manager. The system separates the credential storage function from the pairing process, allowing credentials to be retrieved and used automatically without user exposure, thus enhancing security while maintaining ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential manager as an intermediary component that mediates between the user's authorization and the Bluetooth pairing process. This intermediary securely stores credentials, manages their lifecycle, and provides them to the pairing process without exposing them to potential interception, resolving the contradiction between security and convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automatic pairing is implemented without user input, then ease of operation is improved, but security is worsened due to potential unauthorized access

Engineering Contradiction:
Improvepairing convenienceVSAvoidpairing security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-storing pairing credentials in the credential manager before the actual pairing process occurs. User authorization is obtained in advance, and credentials are securely saved for automatic retrieval during pairing. This eliminates the need for real-time user input while maintaining security through pre-authorized credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by enabling automatic retrieval and use of stored credentials during the Bluetooth pairing process without requiring user intervention. The credential manager autonomously manages the credentials, and the pairing process automatically uses them, providing both convenience and security through automated authenticated pairing.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If pairing credentials are stored locally for automatic pairing, then ease of operation is improved, but security is worsened due to potential exposure or theft of stored credentials

Engineering Contradiction:
Improveautomatic pairing capabilityVSAvoidcredential exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies beforehand cushioning by implementing secure storage mechanisms in the credential manager that protect credentials from exposure or theft before they are actually used. The credentials are encrypted and protected with access controls, providing a security buffer that prevents harmful factors even though credentials are stored locally for automatic pairing.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS20240259814A1Method and apparatus for cloud-based peripheral device assignment for pairing
Publication Date: 2024.08.01 DELL PROD LP
  • US20240259814A1 patent drawing
  • US20240259814A1 patent drawing
  • US20240259814A1 patent drawing

AI summary

An information handling system includes a hardware processor and a memory device, the processor executing code instructions of an automatic peripheral device (PD) pairing management system pairing agent to receive and store a temporary key and peripheral device identification data (PD ID) associated with a peripheral device assigned to the information handling system from a backend management server via secure wireless link. In response to a pairing query from the assigned peripheral device including a sent PD ID, the automatic PD pairing management system pairing agent determines that the received PD ID matches the stored PD ID and verifies BT pairing with the peripheral device is authorized by determining that the temporary key received from the backend management server matches a peripheral device temporary key stored at the peripheral device before establishing a Bluetooth® wireless link between the peripheral device and the information handling system.