Automatic Wireless Device Pairing via Provisioning Server Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless LAN pairing methods, such as Wi-Fi Protected Setup (WPS), are cumbersome and often impractical for devices that cannot be moved or are used by individuals with restricted mobility, as they require physical proximity to the access point and a limited time window for button presses, making it difficult to connect new devices to a secure wireless network.

Innovation Solution

A method for automatic pairing of a device with a secure wireless LAN using stored security credentials, which establishes a connection through an available access point, creates a tunnel, and requests credentials from a provisioning server to configure the device for secure connection, allowing pairing without user intervention beyond powering on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If WPS button press method is used for device pairing, then security credentials can be transferred without manual password entry, but the method becomes impractical when devices cannot be physically proximate to the access point or when users have restricted mobility

Engineering Contradiction:
Improveease of pairing operationVSAvoidadaptability to remote pairing scenarios
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a provisioning server as an intermediary component that mediates the pairing process between the device and access point. The server receives a pairing request from the device, retrieves security credentials, and delivers them to the device, eliminating the need for physical proximity or button pressing. This intermediary architecture enables remote pairing while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-storing security credentials on a provisioning server before the pairing process begins. When a device needs to pair, the credentials are already prepared and can be rapidly delivered without requiring manual entry or physical interaction with the access point, thus enabling automatic pairing from any location.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual password entry is required for device pairing, then security credentials can be securely provided, but the process becomes cumbersome and difficult to remember

Engineering Contradiction:
Improvesecurity of credential provisionVSAvoidease of pairing operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device performs self-service by automatically requesting and receiving security credentials from the provisioning server without requiring user intervention for password entry. The system autonomously completes the pairing process by handling credential retrieval and configuration, maintaining security while eliminating the burden of manual password management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The provisioning server acts as a secure intermediary that manages credential storage and distribution. It securely provides credentials to authorized devices automatically, eliminating the need for users to manually handle or remember complex passwords while maintaining strong security through controlled credential delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure WLAN requires password protection, then network security is improved, but new devices cannot be easily connected without manual password entry

Engineering Contradiction:
Improvesecurity of wireless networkVSAvoidspeed of device connection
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security credentials are prepared in advance on the provisioning server, allowing rapid automatic delivery to new devices without interrupting network security. When a device needs to connect, the pre-prepared credentials enable immediate pairing, maintaining both security and high connection speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning server intermediary enables fast credential delivery while maintaining security by controlling and authenticating the credential distribution process. It acts as a secure gateway that rapidly provides credentials to authorized devices without compromising network security or requiring slow manual processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If WPS two-minute time window is enforced, then security against unauthorized pairing is improved, but the method becomes impossible to use when devices are in different locations

Engineering Contradiction:
Improvesecurity against unauthorized pairingVSAvoidadaptability to distributed device scenarios
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The provisioning server intermediary enables secure pairing without time constraints by mediating the credential delivery process. The server authenticates the pairing request, retrieves credentials, and delivers them securely regardless of the time elapsed or physical distance between devices, maintaining security while enabling distributed pairing scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Credentials are pre-prepared on the provisioning server before the pairing request arrives, allowing immediate secure delivery without requiring the device to be physically present within a time window. This preliminary preparation enables pairing from any location at any time while maintaining security through controlled credential distribution.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11418959B2Automatic pairing of devices to wireless networks
Publication Date: 2022.08.16 BRITISH TELECOM PLC
  • US11418959B2 patent drawing
  • US11418959B2 patent drawing
  • US11418959B2 patent drawing

AI summary

A method for the automatic pairing of a device wirelessly with a first secure WLAN provided by a pairing access point using first set of security credentials, involving: establishing automatically a connection between the device and a second WLAN provided by an available access point, and authenticating the device with the second WLAN using a second set of security credentials stored on the device; identifying the pairing access point using the second set of security credentials; creating a tunnel between the device and the pairing access point over the second WLAN; making a request from the device, via the tunnel, to a provisioning server on the pairing access point for transfer of the second set of security credentials, being the security credentials needed to pair with the first secure WLAN, from the pairing access point to the device; and using the second set of security credentials to configure the security settings for the first secure WLAN in the device.