Cloud-Based Thread Credential Distribution for Userless Commissioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing commissioning techniques for wireless devices in mesh networks are limited by the need for user interaction, lack of flexibility in device compatibility, and inefficiencies in securely provisioning credentials, leading to suboptimal user experience and potential security risks.
Innovation Solution
A cloud-based Thread Credential Distribution Service (TCDS) manages network credentials, enabling flexible and secure commissioning of devices by using device identities and Universally Unique Identifiers (UUIDs) to streamline the process across various network environments, including Thread, Matter, and Weave networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional commissioning techniques are used for Thread networks, then device security is maintained through credential authentication, but user experience quality deteriorates due to manual intervention requirements and complex provisioning processes
Solution Approach 1:
The patent introduces a cloud-based Thread Credential Distribution Service (TCDS) as an intermediary between devices and the credential management system. The TCDS receives commissioning requests, retrieves credentials securely from the home graph service, and distributes them to devices without requiring direct user intervention in the credential provisioning process, thus maintaining security while improving user experience
Solution Approach 2:
Credentials are pre-provisioned into the cloud-based TCDS before devices need them. The home graph service stores credentials in advance, and when a device needs to join the Thread network, the credentials are already available for rapid distribution without manual user input, eliminating the need for users to manually configure security credentials
2Reliability
If manual credential provisioning is performed during commissioning, then security credentials are injected into devices, but commissioning time and complexity increase due to user interaction requirements
Solution Approach 1:
The commissioning process is automated through the TCDS, which autonomously retrieves credentials from the home graph service and distributes them to devices without requiring user action. The system performs self-service credential provisioning, where the cloud service automatically manages the entire credential distribution workflow, significantly reducing commissioning time while maintaining security
Solution Approach 2:
Credentials are pre-stored in the cloud-based home graph service before commissioning occurs. When commissioning is initiated, the TCDS immediately retrieves pre-prepared credentials and distributes them to devices, eliminating the time-consuming manual credential configuration process while ensuring security credentials are properly injected
3Adaptability or versatility
If cloud-based TCDS is implemented for credential distribution, then commissioning flexibility and device compatibility improve, but system complexity increases due to cloud service integration
Solution Approach 1:
The cloud-based TCDS serves as a universal credential distribution service that can handle multiple device types, network configurations, and commissioning scenarios through a single unified interface. The service is designed to work with various Thread network configurations and device profiles, providing flexible credential distribution without requiring separate provisioning systems for different device categories
Solution Approach 2:
The TCDS acts as an intermediary layer that abstracts the complexity of cloud service integration from individual devices. Rather than each device needing direct integration with cloud services, the TCDS handles all cloud communication, credential retrieval, and distribution logistics, simplifying the system architecture while enabling flexible support for diverse device types through standardized interfaces
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques and devices for maintaining network connectivity on a Thread network are described in which a Thread Credential Distribution Service (TCDS) receives a first message requesting credentials for the Thread network and based on the reception of the first message, the TCDS sends, to a home graph service, a second message that requests a structure identifier. The TCDS receives a third message that includes the structure identifier and based on the received structure identifier, sends a fourth message that directs the wireless network device to join the Thread network.