Wireless AP Provisioning via DPP Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for provisioning access points (APs) in wireless multi-hop networks are complex, time-consuming, and require significant human intervention, especially in mesh networks where APs are difficult to reach physically.

Innovation Solution

A wireless trusted provisioning method using the Device Provision Protocol (DPP) that extends configuration protocols to include mesh-specific parameters, allowing APs to join mesh networks automatically without wired connections, and enables automatic recovery of failed APs using DPP authentication and configuration protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional wired provisioning methods are used for APs in mesh networks, then network security and configuration control are improved, but deployment complexity and time consumption increase significantly

Engineering Contradiction:
Improveconfiguration controlVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical wired connection system with a wireless provisioning system using DPP protocol. The AP uses its wireless interface to communicate with the controller for authentication and configuration reception, eliminating the need for physical cable connections during deployment while maintaining secure configuration control through cryptographic authentication mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a controller as an intermediary between the AP and the network administrator. The controller receives provisioning requests, performs DPP authentication with the AP, and distributes configuration parameters wirelessly. This intermediary simplifies the deployment process by automating the provisioning workflow while maintaining security through controlled authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If wired connections are required for AP provisioning, then configuration security is improved, but deployment time and manual intervention requirements increase

Engineering Contradiction:
Improveconfiguration securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent substitutes the mechanical wired connection process with a wireless DPP-based provisioning process. The AP establishes a secure wireless connection with the controller, performs cryptographic authentication, and receives configuration parameters without requiring physical cable installation or removal, dramatically reducing deployment time while maintaining security through the DPP protocol's authentication mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements preliminary action by pre-configuring the AP with DPP credentials (such as public keys or authentication tokens) before deployment. When the AP joins the network, it automatically presents these credentials for authentication, eliminating the need for manual configuration during installation and enabling rapid secure provisioning.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If manual provisioning procedures are used for APs in difficult-to-reach locations, then configuration accuracy is improved, but operational complexity and expertise requirements increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidoperational ease
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the AP to autonomously perform provisioning operations. The AP automatically discovers the controller, initiates DPP authentication, receives configuration parameters, and applies settings without requiring manual intervention. This self-provisioning capability maintains configuration accuracy through automated validation while dramatically simplifying operations for remote or difficult-to-reach deployments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses the controller as an intermediary to manage complex provisioning tasks remotely. The controller handles authentication, configuration generation, and parameter distribution, allowing accurate configuration to be delivered wirelessly to APs in hard-to-reach locations without requiring physical access or specialized technical expertise at the deployment site.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If wireless provisioning without wired connections is implemented, then deployment speed and ease of operation are improved, but network security and authentication reliability may be compromised

Engineering Contradiction:
Improvedeployment speedVSAvoidauthentication reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces the physical wired authentication mechanism with a cryptographic wireless authentication system using DPP. The AP and controller perform mutual authentication using digital signatures and public key infrastructure over the wireless channel, providing authentication reliability comparable to or exceeding wired methods while enabling rapid wireless provisioning and deployment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11671830B2Connecting access point to wireless multi-hop network based on a network role of the access point
Publication Date: 2023.06.06 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11671830B2 patent drawing
  • US11671830B2 patent drawing
  • US11671830B2 patent drawing

AI summary

In embodiments of the present disclosure, there is provided an approach for connecting an access point (AP) to a wireless multi-hop network. An electronic device obtains device information of the AP in a wireless manner, and the electronic device and the AP can establish a wireless trusted connection based on the device information. Then, the electronic device transmits a configuration to the AP over the wireless trusted connection, wherein the configuration at least indicates an identifier of a wireless multi-hop network and a network role of the AP in the wireless multi-hop network. The AP then connects to the wireless multi-hop network according to the configuration. Embodiments of the present disclosure provide a wireless trusted way to provision an AP, which requires little manual intervention and technical expertise, while ensuring the safety of the provisioning.