Secure Thread Credential Distribution for Automated Network Joining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing commissioning techniques for wireless mesh networks, such as those using Thread technology, are cumbersome and inefficient, particularly in securely distributing credentials to devices and ensuring accurate network joining, which affects user experience and security.

Innovation Solution

A cloud-based Thread Credential Distribution Service (TCDS) is introduced to manage and distribute Thread network credentials securely, enabling flexible commissioning of devices through a secure session establishment, credential retrieval, update, and deletion, using Elliptic-Curve Diffie-Hellman key agreement and a keystore for encryption and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional commissioning techniques are used to securely distribute credentials and ensure accurate network joining, then security is improved, but device complexity and user operation burden increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcommissioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a border router as an intermediary component that mediates between the Thread network and IP network. The border router stores Thread network credentials and handles credential distribution automatically, eliminating the need for complex manual commissioning while maintaining security. The border router acts as a trusted intermediary that manages the complexity of credential management internally while presenting a simple interface to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service commissioning where devices automatically obtain credentials from the border router without user intervention. The border router automatically validates device identities, distributes appropriate credentials, and manages credential updates. This self-service mechanism eliminates manual commissioning steps while maintaining secure credential distribution.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional commissioning techniques are used to authenticate devices and encrypt communication, then security is improved, but ease of operation deteriorates due to manual configuration requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcommissioning ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The border router performs preliminary actions by pre-storing Thread network credentials and pre-configuring authentication mechanisms before devices need to join the network. When a device needs to commission, the border router already has the necessary credentials ready to distribute, eliminating manual configuration steps. The authentication and encryption settings are pre-configured in the border router, ready for automatic distribution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Devices perform self-service commissioning by automatically authenticating with the border router and receiving credentials without user intervention. The system automatically handles device identification, credential selection, and secure distribution. This self-service approach maintains security through automatic authentication while dramatically improving ease of operation by eliminating manual configuration.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If credentials are manually commissioned into devices, then accurate network joining is ensured, but loss of time increases due to manual intervention requirements

Engineering Contradiction:
Improvenetwork joining accuracyVSAvoidcommissioning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements self-service automatic credential distribution where devices automatically obtain the correct credentials from the border router without user intervention. The border router automatically validates device identities and provides appropriate credentials, ensuring accurate network joining while eliminating the time required for manual credential entry and configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical commissioning processes with automated electronic credential distribution. Instead of manual credential entry and configuration, the system uses automated authentication protocols and electronic credential transmission between the border router and Thread devices. This substitution maintains joining accuracy while dramatically reducing commissioning time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Use of energy by moving object

If battery-powered devices are used in mesh networks, then energy consumption is reduced, but available computing and radio resources are limited

Engineering Contradiction:
Improvepower consumptionVSAvoidcomputing resources
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent segments the computing workload between battery-powered Thread devices and the AC-powered border router. The border router handles computationally intensive tasks such as credential storage, validation, and distribution, while Thread devices perform only lightweight authentication and credential reception. This segmentation allows battery-powered devices to maintain low power consumption while the system as a whole provides robust security and credential management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The border router acts as an intermediary that handles complex credential management operations externally to battery-powered devices. Instead of requiring Thread devices to perform complex cryptographic operations and credential validation, the border router performs these functions and provides simplified authentication to devices. This reduces the computing and radio resources required in battery-powered devices while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The TCDS enhances the flexibility and security of commissioning Thread devices, allowing seamless integration into existing networks and reducing the burden on users by automating credential management across various devices, including battery-powered and non-mobile device setups.

Implementation Method 1

establishing a secure session with a client device and receiving, from the client device, a first message that requests Thread network credentials

Methodology Applied
Scientific EffectElliptic-Curve Diffie-Hellman key agreement:

Implementation Method 2

The TCDS encrypts the received Thread network credentials, signs the encrypted Thread network credentials, and sends the signed, encrypted Thread network credentials to the client device

Methodology Applied
Scientific EffectEncryption:

Data Source

PatentEP4618478A1Thread credentials distribution service
Publication Date: 2025.09.17 GOOGLE LLC
  • EP4618478A1 patent drawingFigure 1
  • EP4618478A1 patent drawingFigure 2
  • EP4618478A1 patent drawingFigure 3

AI summary

Techniques and devices are described for managing Thread network credentials by a Thread credential distribution service (TCDS). By establishing a secure session with a client device, the TCDS receives, from the client device, a first message that requests Thread network credentials, and based on the received first message, validates an identity of the client device. Using a Thread credential identifier, the TCDS queries a TCDS database to retrieve Thread network credentials associated with the Thread credential identifier and receives, from the TCDS database, the Thread network credentials associated with the Thread credential identifier. The TCDS encrypts the Thread network credentials, signs the encrypted Thread network credentials, and sends the signed, encrypted Thread network credentials to the client device.