Wireless Device Provisioning Using Public Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for provisioning devices in home wireless networks, such as WiFi networks, are time-consuming and inconvenient, requiring manual intervention and repeated processes for each device, especially when devices are not in close proximity or have inaccessible buttons.
Innovation Solution
A method where a first device connected to a wireless network receives a public key from a remote server corresponding to a private key in a second device, encrypts network security information, and transmits it wirelessly to the second device, allowing secure connection to the network using the corresponding private key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional provisioning methods (microAP-based or WPS) are used, then devices can be connected to the wireless network, but the process requires significant user time and effort especially when provisioning multiple devices
Solution Approach 1:
The patent applies preliminary action by pre-provisioning devices with cryptographic key pairs (private and public keys) during manufacturing. The private key is stored securely in the device, while the public key is registered with the network administrator before the device is even deployed. This preliminary setup eliminates the need for manual credential configuration during actual provisioning, allowing devices to automatically authenticate and join the network without user intervention.
Solution Approach 2:
The patent introduces cryptographic keys as an intermediary mechanism between the device and the network. Instead of directly sharing network credentials (SSID, password) between user and device, the system uses public-key infrastructure where the device's public key serves as a mediator for secure authentication. The network administrator verifies the device using its public key, and secure credentials are exchanged through encrypted channels, eliminating manual credential distribution.
2Reliability
If manual provisioning steps are required for each device, then network security credentials can be verified, but the process must be repeated for every additional device
Solution Approach 1:
The patent enables self-service provisioning where devices automatically perform authentication and credential acquisition without user intervention. The device uses its pre-configured private key to authenticate with the network, automatically establishes secure connections, and retrieves network credentials on its own. This eliminates the repetitive manual steps required in conventional methods while maintaining security verification through cryptographic proof of identity.
Solution Approach 2:
The cryptographic public key acts as an intermediary that simplifies the provisioning process. Instead of manually verifying security credentials for each device, the network administrator uses the device's public key (registered in advance) to automatically verify its identity and authorize network access. This intermediary mechanism reduces provisioning complexity from multiple manual steps to a single automated authentication operation.
3Productivity
If network security information is transmitted in plain text, then devices can receive credentials quickly, but security is compromised during transmission
Solution Approach 1:
The patent applies local quality by encrypting network security information specifically during transmission using the device's public key, while leaving other parts of the provisioning process in clear text. The encryption is applied locally at the point of credential transmission from the network administrator to the device, ensuring security only where needed (during wireless transmission) without adding unnecessary complexity to the overall process. This selective encryption maintains both speed and security.
Solution Approach 2:
The patent changes the cryptographic parameters dynamically based on the transmission context. During credential transmission, the system switches from plain text to encrypted text using asymmetric cryptography (public-key encryption). The encryption strength and method are adjusted according to the security requirements of the transmission channel, allowing fast unencrypted communication for non-sensitive data while applying strong encryption only to critical security credentials during transmission.
Data Source
AI summary
In a method, implemented by a first device connected to a wireless network, for assisting in provisioning a second device for connection to the wireless network, the first device receives, via the wireless network and from a remote server, a public key corresponding to a private key stored in the second device. The first device uses the public key to encrypt network security information stored in the first device, the network security information including information that is useable to securely connect to the first wireless network. The first device wirelessly transmits, for reception by the second device, a signal carrying the encrypted network security information.


