Wi-Fi Link Security via PBC and DPP Bootstrapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing a Wi-Fi link in Multi-AP communication systems require manual entry of security credentials and are not efficient for devices conforming to Release Two (R2) of the Wi-Fi Alliance Multi-AP specification, as they are not compatible with legacy devices and require changes to the onboarding protocol.

Innovation Solution

The implementation of a Push Button Configuration (PBC) method that secures both the Wi-Fi layer and the 1905 layer using the Device Provisioning Protocol (DPP), by modifying the M8 message to include encrypted backhaul credentials and adding a DPP Bootstrapping Uniform Resource Identifier (URI) in the PBC process, while maintaining compatibility with legacy devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual entry of security credentials is used for device provisioning, then security is established, but the configuration process is time-consuming and inefficient

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service provisioning where the enrollee device automatically obtains and configures security credentials through the M8 message exchange, eliminating the need for manual user intervention in credential entry while maintaining security standards

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security credentials are pre-prepared and embedded in the M8 message during the provisioning process, allowing the enrollee device to receive and configure credentials automatically without real-time manual input, thus reducing configuration time while ensuring security

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If PBC method is used for Multi-AP R1 devices, then Wi-Fi link security is established, but it is not compatible with Multi-AP R2 devices requiring DPP protocol

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity protocol compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The M8 message is designed to carry DPP bootstrapping information that can serve both R1 devices using PBC and R2 devices using DPP protocol, making the provisioning mechanism universal across different device releases while maintaining appropriate security protocols for each

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of security protocol based on device type: R1 devices receive PBC-based credentials while R2 devices receive DPP-based credentials through the same M8 message framework, enabling protocol adaptation without requiring separate provisioning paths

Inventive Principle:
Principle #35Parameter changes

3Reliability

If onboarding protocol is modified to support DPP for R2 devices, then security for both Wi-Fi and 1905 layers is achieved, but compatibility with legacy devices is lost

Engineering Contradiction:
Improvemulti-layer securityVSAvoidlegacy device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The provisioning process is segmented into different paths based on device type: R1 devices follow the traditional PBC workflow while R2 devices follow the enhanced DPP workflow, both utilizing the M8 message but with different credential types, allowing multi-layer security for R2 without breaking legacy R1 compatibility

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11490258B2Method and apparatus for securing a Wi-Fi link in a wireless communication system
Publication Date: 2022.11.01 NXP USA INC
  • US11490258B2 patent drawing
  • US11490258B2 patent drawing
  • US11490258B2 patent drawing

AI summary

A method for securing a Wi-Fi link in a wireless communication system includes configuring an existing agent with a controller, wherein the existing agent is configured as a first Basic Service Set (BSS). An enrollee agent is onboarded with a Push Button Configuration (PBC) method to establish an 1905 layer security between the existing agent and the enrollee agent. The enrollee agent is configured with the controller, including the controller transmitting a Device Provisioning Protocol (DPP) Bootstrapping Information Request to the enrollee agent and the controller receiving a DPP Bootstrapping Information Response from the enrollee agent, wherein the enrollee agent is configured as a second BSS.