Zero-Touch Network Join via Beacon-Invited Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network joining mechanisms for Low-Power and Lossy Networks (LLNs) require preconfigured default identifiers, making them susceptible to man-in-the-middle attacks and are not scalable, especially in IoT environments where devices lack user interfaces and have resource constraints.

Innovation Solution

A zero-touch network join mechanism where a device receives node information, determines network formation parameters, generates a join invitation, and sends beacons with a Bloom filter to allow selected nodes to join the network through specified access points, eliminating the need for preconfiguration and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If preconfigured default network identifiers are used for network joining, then network joining is simplified, but security is compromised due to susceptibility to man-in-the-middle attacks

Engineering Contradiction:
Improvenetwork joining simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring the network with a list of authorized node identifiers before nodes attempt to join. The network controller proactively prepares authorization data and distributes it to access points, so when a node attempts to join, the authorization check is already in place, eliminating the need for interactive security protocols while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (the network controller and access points) that mediates between joining nodes and the network. Instead of direct authentication between nodes and network, the access points act as intermediaries that verify node identifiers against the pre-configured authorized list, providing security without requiring complex user interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual button pressing is required for network joining, then security is improved, but scalability is reduced due to router accessibility and operation issues

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork joining scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by allowing nodes to automatically join the network using pre-configured authorized identifier lists. Nodes independently select access points and complete joining without human intervention, while the network automatically verifies authorization. This eliminates the need for manual button pressing while maintaining security through automated identifier verification.

Inventive Principle:
Principle #25Self-service

3Speed

If multiple nodes join the network simultaneously without coordination, then network formation speed is improved, but network stability deteriorates due to interference and conflicts

Engineering Contradiction:
Improvenetwork formation speedVSAvoidnetwork formation stability
Core Design Contradiction:
SpeedVSStability of the object's composition

Solution Approach 1:

The patent implements periodic action by having the network controller distribute authorized identifier lists to access points in scheduled intervals. Access points then periodically update their authorized lists and coordinate with other access points, creating a rhythmic, synchronized joining process that prevents simultaneous uncoordinated joins while maintaining efficient network formation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10785809B1Coordinating zero touch network joins
Publication Date: 2020.09.22 CISCO TECHNOLOGY INC
  • US10785809B1 patent drawing
  • US10785809B1 patent drawing
  • US10785809B1 patent drawing

AI summary

In one embodiment, a device in a network receives node information regarding a plurality of nodes that are to join the network. The device determines network formation parameters based on the received node information. The network formation parameters are indicative of a network join schedule and join location for a particular node from the plurality of nodes. The device generates, according to the network join schedule, a join invitation for the particular node based on the network formation parameters. The join invitation allows the particular node to attempt joining the network at the join location via a specified access point. The device causes the sending of one or more beacons via the network that include the join invitation to the particular node. The particular node attempts to join the network via the specified access point based on the one or more beacons.