URL-Based Secure Device Commissioning in Home Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing commissioning techniques for devices joining wireless networks lack efficiency in ensuring secure and accurate device authentication, especially across multi-vendor networks, leading to potential security breaches and user experience issues.

Innovation Solution

The method involves using Application Uniform Resource Locators (URLs) to secure return communication by generating an Augmented Responder Access URL, allowing an initiator device to obtain a Responder Payload from a responder device, which enables secure commissioning of a joiner device to a home area network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional commissioning techniques are used for device authentication, then the commissioning process is simpler, but security is compromised and vulnerability to man-in-the-middle attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommissioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a URL-based intermediary mechanism that mediates between the initiator and responder devices. The Responder Access URL and Initiator Response URL act as secure intermediaries, allowing authentication data to be exchanged without direct exposure of credentials. This mediator approach enhances security while maintaining a relatively simple commissioning flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-configuring devices with authentication credentials and pre-establishing the URL structure before commissioning begins. The responder publishes its Responder Access URL in advance, and the initiator prepares the authentication payload beforehand, enabling secure authentication without complex runtime negotiations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If credentials are commissioned into devices during network joining, then device identity authentication is enabled, but the accuracy of joining to the correct network and security of credential injection deteriorates

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsecurity breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The URL structure serves as a secure intermediary that protects credential injection. The Responder Access URL and Initiator Response URL encapsulate authentication data, preventing direct exposure of credentials during the commissioning process. This intermediary mechanism ensures accurate network joining while protecting against security breaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter representation of credentials from direct credential injection to URL-encoded authentication data. By transforming credentials into URL parameters within the Responder Access URL and Initiator Response URL, the system maintains authentication accuracy while improving the security of credential injection through parameter encapsulation.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If cross-vendor networking solutions are implemented, then network compatibility is improved, but the security of commissioning communications across multi-vendor networks deteriorates

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidcommissioning communication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The URL-based authentication mechanism provides universality by working across different vendor implementations. The Responder Access URL and Initiator Response URL follow a standardized structure that can be implemented by any vendor, ensuring network compatibility while maintaining consistent security requirements across all implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes to standardize authentication data representation across vendors. By encoding authentication information in URL parameters with a standardized format, the system achieves both cross-vendor compatibility and consistent security, as all vendors must adhere to the same parameter structure and authentication flow.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12328574B2Securing return communication through application uniform resource locators
Publication Date: 2025.06.10 GOOGLE LLC
  • US12328574B2 patent drawing
  • US12328574B2 patent drawing
  • US12328574B2 patent drawing

AI summary

Techniques and devices for securing return communication through application uniform resource locators are described for commissioning a joiner device to a home area network by an initiator device in which the initiator device obtains a Responder Access Uniform Resource Locator (URL) and using the obtained Responder Access URL, generates an Augmented Responder Access URL. The initiator device accesses the Augmented Responder Access URL at a responder, which causes the responder to generate a Responder Payload. The initiator device accesses an Augmented Initiator Response URL including the generated Responder Payload and recovers the Responder Payload, the recovery of the Responder Payload causing the initiator device to commission the joiner device to the home area network.