Temporary Network Pairing for Wireless Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless personal area networks, the pairing of new terminal devices with coordinating entities is prone to errors due to multiple networks in the same environment, and existing solutions require access to a central database for secure key exchange, which can compromise security and resource management.

Innovation Solution

A method where the coordinating entity creates a temporary network specific to the device to be paired, allowing secure exchange of network identifiers and encryption keys before switching to the operational network, ensuring accurate pairing and enhanced security without relying on central databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a new terminal device performs a scan of communication channels to detect coordinating entities, then the device can find available networks, but it may wrongly pair with another personal network in the same environment

Engineering Contradiction:
Improvenetwork detection capabilityVSAvoidpairing accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A temporary network acts as an intermediary between the terminal device and the target personal network. The terminal device first connects to this temporary network created by the coordinating entity, where secure key exchange occurs. Only after successful verification does the device switch to the target personal network, preventing wrong pairing while maintaining detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The coordinating entity creates a temporary network before the actual pairing process to perform preliminary key exchange and verification. This preliminary action on a dedicated temporary network ensures that the terminal device is properly authenticated and configured before joining the operational personal network, eliminating pairing errors.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the encryption key is transmitted over the common communication channel during pairing, then the device receives network configuration information, but the key can be intercepted by a third party

Engineering Contradiction:
Improvekey transmission simplicityVSAvoidkey interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The temporary network serves as a secure intermediary channel for key transmission. Instead of transmitting encryption keys over the common communication channel where they are vulnerable to interception, the key exchange occurs over the temporary network which provides dedicated secure communication between the terminal device and coordinating entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication process is segmented into two distinct phases: first, secure key exchange on a temporary dedicated network; second, operational communication on the personal network. This segmentation isolates the vulnerable key transmission phase to a controlled environment with enhanced security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a commissioning tool accesses a central database of encryption keys, then secure channel establishment is enabled, but the coordinating entity must access shared databases via communication networks

Engineering Contradiction:
Improvesecure channel establishmentVSAvoiddatabase access requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption key storage function is extracted from the central database and relocated to the coordinating entity's local memory. The coordinating entity stores encryption keys locally, eliminating the need for real-time database access during pairing operations and reducing system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The coordinating entity performs self-service by maintaining local copies of encryption keys in its memory. This eliminates dependency on external database systems for key retrieval, allowing the coordinating entity to independently manage secure pairing without requiring network access to shared databases.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If the coordinating entity opens its personal network to pairing of any new terminal device, then device association is facilitated, but unknown devices may wrongly pair with the coordinating entity

Engineering Contradiction:
Improvedevice association simplicityVSAvoiddevice authentication accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authentication and verification actions are performed preliminarily on the temporary network before the device is allowed to join the operational personal network. The coordinating entity verifies device identity and validates pairing requests during this preliminary phase, ensuring only authorized devices proceed to network association.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The temporary network acts as an intermediary authentication layer between unverified devices and the operational personal network. It provides a controlled environment where the coordinating entity can verify device credentials and establish trust before allowing access to the main network, preventing unauthorized pairing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2959656B1Technique of pairing in a wireless network
Publication Date: 2018.08.01 ORANGE SA
  • EP2959656B1 patent drawingFigure 1~4
  • EP2959656B1 patent drawingFigure 2

AI summary

The invention relates to a technique of pairing a device (10-12) with a co‑ordinating entity (20) of a private wireless network (1). The co‑ordinating entity obtains an identifier of the device to be paired and a temporary network identifier specific to the device. The co‑ordinating entity then configures itself on standby awaiting the device identified on the temporary network. The device to be paired transmits a request for association with the temporary network to the co‑ordinating entity on the temporary network. The co‑ordinating entity verifies that the device that transmitted the request for association corresponds to the device identified and then transmits to it on the temporary network an encryption key associated with the private wireless network and an identifier of the private network, then instructs a toggling of the device from the temporary network to the private wireless network. The device to be paired then restarts on the private network and transmits a request for association to the private network on the private network. The co‑ordinating entity and the device identified are then associated.