Secure Thread Credential Distribution for Automated Network Joining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing commissioning techniques for wireless mesh networks, such as those using Thread technology, are cumbersome and inefficient, particularly in securely distributing credentials to devices and ensuring accurate network joining, which affects user experience and security.
Innovation Solution
A cloud-based Thread Credential Distribution Service (TCDS) is introduced to manage and distribute Thread network credentials securely, enabling flexible commissioning of devices through a secure session establishment, credential retrieval, update, and deletion, using Elliptic-Curve Diffie-Hellman key agreement and a keystore for encryption and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional commissioning techniques are used to securely distribute credentials and ensure accurate network joining, then security is improved, but device complexity and user operation burden increase significantly
Solution Approach 1:
The patent introduces a border router as an intermediary component that mediates between the Thread network and IP network. The border router stores Thread network credentials and handles credential distribution automatically, eliminating the need for complex manual commissioning while maintaining security. The border router acts as a trusted intermediary that manages the complexity of credential management internally while presenting a simple interface to users.
Solution Approach 2:
The system enables self-service commissioning where devices automatically obtain credentials from the border router without user intervention. The border router automatically validates device identities, distributes appropriate credentials, and manages credential updates. This self-service mechanism eliminates manual commissioning steps while maintaining secure credential distribution.
2Reliability
If traditional commissioning techniques are used to authenticate devices and encrypt communication, then security is improved, but ease of operation deteriorates due to manual configuration requirements
Solution Approach 1:
The border router performs preliminary actions by pre-storing Thread network credentials and pre-configuring authentication mechanisms before devices need to join the network. When a device needs to commission, the border router already has the necessary credentials ready to distribute, eliminating manual configuration steps. The authentication and encryption settings are pre-configured in the border router, ready for automatic distribution.
Solution Approach 2:
Devices perform self-service commissioning by automatically authenticating with the border router and receiving credentials without user intervention. The system automatically handles device identification, credential selection, and secure distribution. This self-service approach maintains security through automatic authentication while dramatically improving ease of operation by eliminating manual configuration.
3Measurement precision
If credentials are manually commissioned into devices, then accurate network joining is ensured, but loss of time increases due to manual intervention requirements
Solution Approach 1:
The system implements self-service automatic credential distribution where devices automatically obtain the correct credentials from the border router without user intervention. The border router automatically validates device identities and provides appropriate credentials, ensuring accurate network joining while eliminating the time required for manual credential entry and configuration.
Solution Approach 2:
The patent replaces manual mechanical commissioning processes with automated electronic credential distribution. Instead of manual credential entry and configuration, the system uses automated authentication protocols and electronic credential transmission between the border router and Thread devices. This substitution maintains joining accuracy while dramatically reducing commissioning time.
4Use of energy by moving object
If battery-powered devices are used in mesh networks, then energy consumption is reduced, but available computing and radio resources are limited
Solution Approach 1:
The patent segments the computing workload between battery-powered Thread devices and the AC-powered border router. The border router handles computationally intensive tasks such as credential storage, validation, and distribution, while Thread devices perform only lightweight authentication and credential reception. This segmentation allows battery-powered devices to maintain low power consumption while the system as a whole provides robust security and credential management.
Solution Approach 2:
The border router acts as an intermediary that handles complex credential management operations externally to battery-powered devices. Instead of requiring Thread devices to perform complex cryptographic operations and credential validation, the border router performs these functions and provides simplified authentication to devices. This reduces the computing and radio resources required in battery-powered devices while maintaining security.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
The TCDS enhances the flexibility and security of commissioning Thread devices, allowing seamless integration into existing networks and reducing the burden on users by automating credential management across various devices, including battery-powered and non-mobile device setups.
Implementation Method 1
establishing a secure session with a client device and receiving, from the client device, a first message that requests Thread network credentials
Implementation Method 2
The TCDS encrypts the received Thread network credentials, signs the encrypted Thread network credentials, and sends the signed, encrypted Thread network credentials to the client device
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques and devices are described for managing Thread network credentials by a Thread credential distribution service (TCDS). By establishing a secure session with a client device, the TCDS receives, from the client device, a first message that requests Thread network credentials, and based on the received first message, validates an identity of the client device. Using a Thread credential identifier, the TCDS queries a TCDS database to retrieve Thread network credentials associated with the Thread credential identifier and receives, from the TCDS database, the Thread network credentials associated with the Thread credential identifier. The TCDS encrypts the Thread network credentials, signs the encrypted Thread network credentials, and sends the signed, encrypted Thread network credentials to the client device.