Wireless Device Provisioning via Encrypted Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems in industrial settings face security risks due to the possibility of malicious provisioning of wireless devices, particularly with OTA symmetric methods where communication content can be intercepted, leading to potential wrongful provisioning and compromised security.
Innovation Solution
A wireless communication system that includes a setting device creating correlated information for wireless devices, including provisioning methods and operator details, and a management device using encrypted setting information to select and manage wireless devices, incorporating a security manager unit to control access and prevent wrongful provisioning by using a whitelist and blacklist.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If OTA symmetric provisioning is used to provision wireless devices via the wireless communication network, then provisioning can be performed remotely without physical access, but security is compromised because communication content can be intercepted by malicious persons
Solution Approach 1:
The patent introduces a provisioning information management device as an intermediary between the setting device and wireless devices. This intermediary stores provisioning information in an encrypted state and controls its distribution, preventing direct interception of sensitive data while enabling remote provisioning operations.
Solution Approach 2:
The patent performs encryption of provisioning information in advance before transmission or storage. By encrypting the join key and other provisioning data before they leave the setting device, the system prevents interception attacks while maintaining the convenience of remote provisioning.
2Reliability
If OOB provisioning is used with physical access to wireless devices, then security is maintained against remote interception, but malicious persons can still wrongly provision devices if they gain physical access to installation locations
Solution Approach 1:
The provisioning information management device acts as a centralized intermediary that controls all provisioning operations. Even when physical access is granted, the intermediary's access control mechanisms and encrypted storage prevent unauthorized provisioning, addressing both remote and physical access vulnerabilities.
Solution Approach 2:
The system implements logging and tracking of all provisioning operations through the intermediary device. This feedback mechanism records which operator performed which provisioning action, enabling detection and prevention of wrongful provisioning attempts regardless of access method.
3Reliability
If provisioning information is transmitted and stored in encrypted form, then security is improved against interception, but device complexity increases due to encryption and decryption operations
Solution Approach 1:
The patent combines the encryption and decryption functions into the provisioning information management device, which serves as a centralized intermediary. This consolidation reduces the encryption overhead burden on individual wireless devices while maintaining security through encrypted provisioning information storage and transmission.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A wireless communication system for communicating via a wireless communication network, may include: a setting device configured to create a first information needed for joining a wireless device into the wireless communication network and set the first information in the wireless device to be joined into the wireless communication network, the setting device being configured to create setting information that correlates the first information with a second information containing at least one of information indicating a method of setting the first information and information indicating an operator who performed an operation of setting the first information; and a management device configured to select the wireless device, which is to be joined into the wireless communication network, by using the setting information that has been created by the setting device.