Cloud-Based Thread Credential Distribution for Userless Commissioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing commissioning techniques for wireless devices in mesh networks are limited by the need for user interaction, lack of flexibility in device compatibility, and inefficiencies in securely provisioning credentials, leading to suboptimal user experience and potential security risks.

Innovation Solution

A cloud-based Thread Credential Distribution Service (TCDS) manages network credentials, enabling flexible and secure commissioning of devices by using device identities and Universally Unique Identifiers (UUIDs) to streamline the process across various network environments, including Thread, Matter, and Weave networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional commissioning techniques are used for Thread networks, then device security is maintained through credential authentication, but user experience quality deteriorates due to manual intervention requirements and complex provisioning processes

Engineering Contradiction:
Improvedevice securityVSAvoiduser experience quality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based Thread Credential Distribution Service (TCDS) as an intermediary between devices and the credential management system. The TCDS receives commissioning requests, retrieves credentials securely from the home graph service, and distributes them to devices without requiring direct user intervention in the credential provisioning process, thus maintaining security while improving user experience

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Credentials are pre-provisioned into the cloud-based TCDS before devices need them. The home graph service stores credentials in advance, and when a device needs to join the Thread network, the credentials are already available for rapid distribution without manual user input, eliminating the need for users to manually configure security credentials

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual credential provisioning is performed during commissioning, then security credentials are injected into devices, but commissioning time and complexity increase due to user interaction requirements

Engineering Contradiction:
Improvecredential securityVSAvoidcommissioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The commissioning process is automated through the TCDS, which autonomously retrieves credentials from the home graph service and distributes them to devices without requiring user action. The system performs self-service credential provisioning, where the cloud service automatically manages the entire credential distribution workflow, significantly reducing commissioning time while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Credentials are pre-stored in the cloud-based home graph service before commissioning occurs. When commissioning is initiated, the TCDS immediately retrieves pre-prepared credentials and distributes them to devices, eliminating the time-consuming manual credential configuration process while ensuring security credentials are properly injected

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If cloud-based TCDS is implemented for credential distribution, then commissioning flexibility and device compatibility improve, but system complexity increases due to cloud service integration

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cloud-based TCDS serves as a universal credential distribution service that can handle multiple device types, network configurations, and commissioning scenarios through a single unified interface. The service is designed to work with various Thread network configurations and device profiles, providing flexible credential distribution without requiring separate provisioning systems for different device categories

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The TCDS acts as an intermediary layer that abstracts the complexity of cloud service integration from individual devices. Rather than each device needing direct integration with cloud services, the TCDS handles all cloud communication, credential retrieval, and distribution logistics, simplifying the system architecture while enabling flexible support for diverse device types through standardized interfaces

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4618606A1Cloud-based thread network commissioning
Publication Date: 2025.09.17 GOOGLE LLC
  • EP4618606A1 patent drawingFigure 1
  • EP4618606A1 patent drawingFigure 2
  • EP4618606A1 patent drawingFigure 3

AI summary

Techniques and devices for maintaining network connectivity on a Thread network are described in which a Thread Credential Distribution Service (TCDS) receives a first message requesting credentials for the Thread network and based on the reception of the first message, the TCDS sends, to a home graph service, a second message that requests a structure identifier. The TCDS receives a third message that includes the structure identifier and based on the received structure identifier, sends a fourth message that directs the wireless network device to join the Thread network.