Wireless Network Device Secure Provisioning via Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network device provisioning methods lack secure authentication mechanisms, making them vulnerable to unauthorized firmware installation, as they rely on physical wired connections which are not always secure and do not utilize native radio systems for provisioning due to security concerns.

Innovation Solution

Implementing a system that uses wireless communication links to authenticate a security token before allowing configuration information to be installed in the wireless network device, utilizing technologies like NFC, Bluetooth, or cellular communication to establish a secure provisioning process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wired connection is used for provisioning, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveprovisioning securityVSAvoidprovisioning convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical wired connection system with a wireless communication system. The wireless provisioning system uses radio frequency communication to transfer configuration firmware and authenticate devices, eliminating the need for physical cable connections while implementing security measures such as authentication protocols and encrypted communication channels to maintain provisioning security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If wireless communication is used for provisioning, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveprovisioning convenienceVSAvoidprovisioning security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces intermediary security mechanisms in the wireless provisioning process. These include authentication servers that verify device identities, encryption protocols that secure data transmission, and token-based authentication systems. The intermediary components act as mediators between the provisioning device and the wireless network device, ensuring secure communication without requiring physical connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical wired connection system with a wireless communication system. The wireless provisioning system uses radio frequency communication to transfer configuration firmware and authenticate devices, eliminating the need for physical cable connections while implementing security measures such as authentication protocols and encrypted communication channels to maintain provisioning security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If native radio system is used for provisioning, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveprovisioning convenienceVSAvoidprovisioning security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the radio communication functionality into two distinct modes: a secure provisioning mode using dedicated authentication protocols and encrypted channels, and a standard wireless network mode for normal operations. The native radio system is partitioned such that provisioning operations use specialized secure protocols while network communication uses standard protocols, allowing ease of wireless operation while maintaining security during provisioning.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10084765B2Secure, untethered provisioning and troubleshooting of wireless network devices
Publication Date: 2018.09.25 ADTRAN INC
  • US10084765B2 patent drawing
  • US10084765B2 patent drawing
  • US10084765B2 patent drawing

AI summary

A wireless network device only installs configuration information that is wirelessly received from a provisioning device if the wireless network device successfully authenticates a security token it receives from the provisioning device. The provisioning device can obtain the security token by scanning a label associated with the wireless network device or by other methods.