Thread Credential Distribution for Secure Device Commissioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing commissioning techniques for wireless network devices in mesh networks are limited by user experience, accuracy in joining the correct network, securely injecting credentials, and provisioning device-specific information, especially with the increasing scale and ubiquity of mesh networks.
Innovation Solution
A Thread Credential Distribution Service (TCDS) is introduced to manage and distribute Thread network credentials securely. This service establishes a secure session with client devices, validates their identities, retrieves and encrypts credentials, and signs them for secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional commissioning techniques are used to distribute Thread credentials, then devices can join mesh networks, but the security of credential injection and provisioning is compromised
Solution Approach 1:
The patent introduces a cloud-based Thread Credential Distribution Service (TCDS) as an intermediary between Thread devices and commissioning tools. The TCDS securely stores Thread credentials, validates commissioning tool identities, and distributes credentials through encrypted channels. This mediator architecture resolves the contradiction by providing both enhanced security through centralized credential management and improved ease of operation through automated commissioning workflows that guide users through simple steps.
Solution Approach 2:
The system performs preliminary actions by pre-provisioning Thread devices with unique identifiers and cryptographic keys before deployment. The TCDS pre-creates secure credential containers and prepares commissioning tool identities in advance. This preliminary setup enables secure credential distribution during commissioning without requiring manual security configurations, thus improving both security and ease of operation.
2Ease of operation
If commissioning techniques are simplified for better user experience, then commissioning becomes easier, but the accuracy of joining the correct mesh network deteriorates
Solution Approach 1:
The TCDS implements feedback mechanisms that provide real-time information to commissioning tools about available Thread networks, device states, and credential matching status. The system validates whether a commissioning tool is attempting to join the correct network by verifying credentials against the TCDS database. This feedback loop maintains high accuracy in network joining while keeping the user interface simple and intuitive.
Solution Approach 2:
The commissioning process is designed to be self-service oriented, where the TCDS automatically performs network discovery, credential verification, and device pairing without requiring manual user intervention for complex security steps. The system self-validates the correctness of network joining through automated credential checks, ensuring accuracy while maintaining simplicity for users.
3Productivity
If more Thread devices are commissioned to increase network scale, then network coverage improves, but the complexity of securely managing credentials increases
Solution Approach 1:
The TCDS is designed as a universal credential distribution service that handles multiple Thread networks, devices, and commissioning tools through a single centralized platform. It provides multi-functional capabilities including credential storage, device provisioning, commissioning tool authentication, and network management. This universal architecture enables network scaling without increasing credential management complexity, as the same system serves all Thread networks and devices.
Solution Approach 2:
The system uses cryptographic copying mechanisms where the TCDS creates secure copies of Thread credentials for distribution to multiple devices and networks. Each credential copy is uniquely bound to specific devices and networks through cryptographic binding, allowing scalable credential distribution without manual replication. This copying approach enables network scaling while maintaining security through automated credential management.
Data Source
AI summary
Techniques and devices are described for managing Thread network credentials by a Thread credential distribution service (TCDS). By establishing a secure session with a client device, the TCDS receives, from the client device, a first message that requests Thread network credentials, and based on the received first message, validates an identity of the client device. Using a Thread credential identifier, the TCDS queries a TCDS database to retrieve Thread network credentials associated with the Thread credential identifier and receives, from the TCDS database, the Thread network credentials associated with the Thread credential identifier. The TCDS encrypts the Thread network credentials, signs the encrypted Thread network credentials, and sends the signed, encrypted Thread network credentials to the client device.


