Wireless Device Provisioning via Encrypted Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems in industrial settings face security risks due to the possibility of malicious provisioning of wireless devices, particularly with OTA symmetric methods where communication content can be intercepted, leading to potential wrongful provisioning and compromised security.

Innovation Solution

A wireless communication system that includes a setting device creating correlated information for wireless devices, including provisioning methods and operator details, and a management device using encrypted setting information to select and manage wireless devices, incorporating a security manager unit to control access and prevent wrongful provisioning by using a whitelist and blacklist.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OTA symmetric provisioning is used to provision wireless devices via the wireless communication network, then provisioning can be performed remotely without physical access, but security is compromised because communication content can be intercepted by malicious persons

Engineering Contradiction:
Improveprovisioning convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a provisioning information management device as an intermediary between the setting device and wireless devices. This intermediary stores provisioning information in an encrypted state and controls its distribution, preventing direct interception of sensitive data while enabling remote provisioning operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs encryption of provisioning information in advance before transmission or storage. By encrypting the join key and other provisioning data before they leave the setting device, the system prevents interception attacks while maintaining the convenience of remote provisioning.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If OOB provisioning is used with physical access to wireless devices, then security is maintained against remote interception, but malicious persons can still wrongly provision devices if they gain physical access to installation locations

Engineering Contradiction:
Improvesecurity against remote interceptionVSAvoidvulnerability to physical access attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The provisioning information management device acts as a centralized intermediary that controls all provisioning operations. Even when physical access is granted, the intermediary's access control mechanisms and encrypted storage prevent unauthorized provisioning, addressing both remote and physical access vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements logging and tracking of all provisioning operations through the intermediary device. This feedback mechanism records which operator performed which provisioning action, enabling detection and prevention of wrongful provisioning attempts regardless of access method.

Inventive Principle:
Principle #23Feedback

3Reliability

If provisioning information is transmitted and stored in encrypted form, then security is improved against interception, but device complexity increases due to encryption and decryption operations

Engineering Contradiction:
ImprovesecurityVSAvoidencryption overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the encryption and decryption functions into the provisioning information management device, which serves as a centralized intermediary. This consolidation reduces the encryption overhead burden on individual wireless devices while maintaining security through encrypted provisioning information storage and transmission.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2663104B1Wireless communication system
Publication Date: 2019.10.02 YOKOGAWA ELECTRIC CORP
  • EP2663104B1 patent drawingFigure 1
  • EP2663104B1 patent drawingFigure 2
  • EP2663104B1 patent drawingFigure 3

AI summary

A wireless communication system for communicating via a wireless communication network, may include: a setting device configured to create a first information needed for joining a wireless device into the wireless communication network and set the first information in the wireless device to be joined into the wireless communication network, the setting device being configured to create setting information that correlates the first information with a second information containing at least one of information indicating a method of setting the first information and information indicating an operator who performed an operation of setting the first information; and a management device configured to select the wireless device, which is to be joined into the wireless communication network, by using the setting information that has been created by the setting device.