Wireless Device Provisioning Using Public Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for provisioning devices in home wireless networks, such as WiFi networks, are time-consuming and inconvenient, requiring manual intervention and repeated processes for each device, especially when devices are not in close proximity or have inaccessible buttons.

Innovation Solution

A method where a first device connected to a wireless network receives a public key from a remote server corresponding to a private key in a second device, encrypts network security information, and transmits it wirelessly to the second device, allowing secure connection to the network using the corresponding private key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional provisioning methods (microAP-based or WPS) are used, then devices can be connected to the wireless network, but the process requires significant user time and effort especially when provisioning multiple devices

Engineering Contradiction:
Improveprovisioning speedVSAvoiduser time for provisioning
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-provisioning devices with cryptographic key pairs (private and public keys) during manufacturing. The private key is stored securely in the device, while the public key is registered with the network administrator before the device is even deployed. This preliminary setup eliminates the need for manual credential configuration during actual provisioning, allowing devices to automatically authenticate and join the network without user intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic keys as an intermediary mechanism between the device and the network. Instead of directly sharing network credentials (SSID, password) between user and device, the system uses public-key infrastructure where the device's public key serves as a mediator for secure authentication. The network administrator verifies the device using its public key, and secure credentials are exchanged through encrypted channels, eliminating manual credential distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual provisioning steps are required for each device, then network security credentials can be verified, but the process must be repeated for every additional device

Engineering Contradiction:
Improvesecurity credential verificationVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables self-service provisioning where devices automatically perform authentication and credential acquisition without user intervention. The device uses its pre-configured private key to authenticate with the network, automatically establishes secure connections, and retrieves network credentials on its own. This eliminates the repetitive manual steps required in conventional methods while maintaining security verification through cryptographic proof of identity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cryptographic public key acts as an intermediary that simplifies the provisioning process. Instead of manually verifying security credentials for each device, the network administrator uses the device's public key (registered in advance) to automatically verify its identity and authorize network access. This intermediary mechanism reduces provisioning complexity from multiple manual steps to a single automated authentication operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If network security information is transmitted in plain text, then devices can receive credentials quickly, but security is compromised during transmission

Engineering Contradiction:
Improvecredential transmission speedVSAvoidtransmission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by encrypting network security information specifically during transmission using the device's public key, while leaving other parts of the provisioning process in clear text. The encryption is applied locally at the point of credential transmission from the network administrator to the device, ensuring security only where needed (during wireless transmission) without adding unnecessary complexity to the overall process. This selective encryption maintains both speed and security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the cryptographic parameters dynamically based on the transmission context. During credential transmission, the system switches from plain text to encrypted text using asymmetric cryptography (public-key encryption). The encryption strength and method are adjusted according to the security requirements of the transmission channel, allowing fast unencrypted communication for non-sensitive data while applying strong encryption only to critical security credentials during transmission.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9220012B1Systems and methods for provisioning devices
Publication Date: 2015.12.22 MARVELL ASIA PTE LTD
  • US9220012B1 patent drawing
  • US9220012B1 patent drawing
  • US9220012B1 patent drawing

AI summary

In a method, implemented by a first device connected to a wireless network, for assisting in provisioning a second device for connection to the wireless network, the first device receives, via the wireless network and from a remote server, a public key corresponding to a private key stored in the second device. The first device uses the public key to encrypt network security information stored in the first device, the network security information including information that is useable to securely connect to the first wireless network. The first device wirelessly transmits, for reception by the second device, a signal carrying the encrypted network security information.