Device default wifi credentials for simplified and secure configuration of networked transducers
Abstract
A wireless device with transducers can support remote monitoring and include an 802.11 compatible radio and a set of device default credentials. The device can be installed at a physical location with service from a fixed access point operating with a different set of owner credentials. A mobile phone can (i) scan a tag for the device and download a set of configuration parameters for the device, and (ii) authenticate with a configuration system. The mobile phone can receive the set of device default credentials from the configuration system. The mobile phone can activate a mobile access point using the set of device default credentials. The device can connect with the mobile phone's access point and receive a ciphertext with the owner credentials and a configuration package. The device can apply the configuration package and load the owner credentials in order to connect with the fixed access point.
Claims
exact text as granted — not AI-modified1 . A method for a mobile handset to configure a device, the method performed by the mobile handset, the method comprising:
a) reading a tag for the device, wherein the tag includes (i) a domain name for a first server and (ii) a token for the device; b) establishing a secure session with the first server using at least the domain name and the token; c) receiving from the first server a set of configuration parameters, wherein the set of configuration parameters includes at least authentication parameters; d) authenticating with an authentication server using the authentication parameters and at least one of (i) identification information from a user and (ii) a certificate for the mobile handset; e) receiving device default credentials for the device, a uniform resource locator (URL) for a configuration system, and a digital signature of the URL; f) scanning for a list of available wireless networks and associated radio frequency (RF) channels, and sending the list to the configuration system; g) establishing a local wireless connection with the device using the device default credentials; h) sending the URL and the digital signature for the URL to the device; i) receiving an encrypted set of credentials from the configuration system, wherein the encrypted set of credentials are encrypted by the configuration system using at least a public key for the device, and wherein the encrypted set of credentials includes at least one wireless network identity and RF channel from the list; and j) sending the encrypted set of credentials to the device through the local wireless connection.
2 . The method of claim 1 , further comprising establishing the secure session through a first radio, wherein the first radio comprises a wireless wide area network (WAN) radio.
3 . The method of claim 1 , further comprising establishing the local wireless connection through a second radio, wherein the second radio comprises one of a Wi-Fi radio, a Near-Field Communications (NFC) radio, and a Bluetooth radio.
4 . The method of claim 1 , wherein the first server comprises a discovery server, and the set of configuration parameters specifies a configuration application for at least establishing the local wireless connection.
5 . The method of claim 1 , wherein the device default credentials include at least one of (i) a device public key for EAP authentication, and (ii) a pre-shared key for the local wireless connection.
6 . The method of claim 1 , wherein the encrypted set of credentials includes (i) at least one of a symmetric key and a certificate for the wireless network and (ii) a wireless network configuration.
7 . The method of claim 1 , wherein the encrypted set of credentials are encrypted with a symmetric ciphering key, wherein the configuration system asymmetrically encrypts the symmetric ciphering key with the public key for the device, wherein the device decrypts the symmetric key with a corresponding private key for the device, and wherein the device decrypts the encrypted set of credentials with the symmetric ciphering key.
8 . The method of claim 7 , wherein the configuration system digitally signs the encrypted set of credentials with a configuration system private key, and wherein the device verifies the digitally signed encrypted set of credentials using at least a certificate authority public key, and wherein the device records the certificate authority public key before the mobile handset establishes the local wireless connection.
9 . The method of claim 1 , wherein the mobile handset scans for the list before authenticating with the authentication server.
10 . The method of claim 1 , wherein the device verifies the digital signature using at least a certificate authority public key, and wherein the device records the certificate authority public key before the mobile handset establishes the local wireless connection.
11 . A mobile handset for configuring a device, the mobile handset comprising:
a camera for reading a device tag, wherein the device tag includes a first server domain name and a token for the device; a nonvolatile memory for storing a configuration application and user credentials, wherein the configuration application scans for a list of available wireless networks and associated radio frequency (RF) channels; a first radio for establishing a secure session with a first server over a wireless wide area network, for receiving authentication parameters from the first server, for receiving (i) device default credentials for the device, (ii) a uniform resource locator (URL) for a configuration system, (iii) and a digital signature of the URL, and for receiving an encrypted set of credentials for a wireless network in the list, wherein the secure session uses the first server domain name and the token; a processor for authenticating with an authentication server using the authentication parameters and at least one of (i) identification information from a user and (ii) a certificate for the mobile handset; a second radio for operating with the user credentials before the mobile handset reads the device tag, for establishing a local wireless connection with the device using the device default credentials, for transmitting to the device (i) the URL, (ii), the digital signature of the URL, and (iii) the encrypted set of credentials, and for operating with the user credentials after transmitting the encrypted set of credentials to the device; and a system bus for transferring the encrypted set of credentials from the first radio to the second radio, wherein the encrypted set of credentials are encrypted using at least a public key for the device, and wherein the encrypted set of credentials includes at least one wireless network identity and RF channel from the list.
12 . The mobile handset of claim 11 , wherein the second radio comprises one of a Wi-Fi radio, a Near-Field Communications (NFC) radio, and a Bluetooth radio.
13 . The mobile handset of claim 11 , wherein the first server comprises a discovery server, and wherein the first radio receives configuration parameters from the discovery server, and wherein the configuration parameters at least select the configuration application.
14 . The mobile handset of claim 11 , wherein the device default credentials include at least one of (i) a device public key for EAP authentication, and (ii) a pre-shared key for the local wireless connection.
15 . The mobile handset of claim 11 , wherein the device records the default credentials before the second radio establishes the local wireless connection.
16 . The mobile handset of claim 11 , wherein the encrypted set of credentials includes at least one of (i) a symmetric key and a certificate for the wireless network and (ii) a wireless network configuration.
17 . The mobile handset of claim 11 , wherein the encrypted set of credentials are encrypted with a symmetric ciphering key, wherein the configuration system asymmetrically encrypts the symmetric ciphering key with the public key for the device, wherein the device decrypts the symmetric key with a corresponding private key for the device, and wherein the device decrypts the encrypted set of credentials with the symmetric ciphering key.
18 . The mobile handset of claim 17 , wherein the configuration system digitally signs the encrypted set of credentials with a configuration system private key, and wherein the device verifies the digitally signed encrypted set of credentials using at least a certificate authority public key, and wherein the device records the certificate authority public key before the mobile handset establishes the local wireless connection.
19 . The mobile handset of claim 11 , wherein the device verifies the digital signature using at least a certificate authority public key, and wherein the device records the certificate authority public key before the mobile handset establishes the local wireless connection.
20 . The mobile handset of claim 11 , wherein the mobile handset uses the device tag to download the configuration application before the processor authenticates with the authentication server.Join the waitlist — get patent alerts
Track US2019313246A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.