Method and system for onboarding wireless-enabled products in a network
15 claims: 4 independent, 11 dependent
- 1ワイヤレス対応製品をプライベート通信ネットワークに接続することを容易にする方法であって、 サーバにおいて、顧客の識別子 (顧 客I D) および前記顧客の前記プライベート通信ネットワークにアクセスするためのネットワーク資格証明を記憶するステップと、 前記サーバにおいて、前記顧客が前記ワイヤレス対応製品を購入する購入トランザクションを可能にするコンピューティングデバイスから、前記ワイヤレス対応製品に関連付けられたデバイスIDおよび前記ワイヤレス対応製品を購入する前記顧客の前記顧客IDを受信するステップと、 前記顧客IDと前記デバイスIDとの関連付けを前記サーバに記憶するステップと、 前記サーバにおいて、前記ワイヤレス対応製品によって開始されたネットワーク接続を介して、前記ワイヤレス対応製品から前記デバイスIDおよびセキュリティトークンを受信するステップと、 前記サーバによって、前記受信されたデバイスIDおよびセキュリティトークンに基づいて前記ワイヤレス対応製品を認証するステップと、 前記ワイヤレス対応製品の認証に応答して、前記サーバによって、前記顧客の前記プライベート通信ネットワークにアクセスするための前記ネットワーク資格証明を前記ワイヤレス対応製品に提供するステップとを含む方法。
- 2前記顧客IDおよび前記顧客のプライベート通信ネットワークにアクセスするための前記ネットワーク資格証明が、顧客情報が入力される顧客登録プロセスの間に、前記サーバによって取得される、請求項1に記載の方法。
- 3前記顧客登録プロセスが、顧客ロイヤルティプログラム用の契約手順を含む、請求項2に記載の方法。
- 4前記サーバによって、前記デバイスIDおよび前記ワイヤレス対応製品の製造業者からのデバイスセキュリティキーを受信するステップと、 前記デバイスセキュリティキーを前記デバイスIDにリンクされた前記サーバによってアクセス可能なメモリに記憶するステップとをさらに含み、 前記サーバによって、前記受信されたデバイスIDおよびセキュリティトークンに基づいて前記ワイヤレス対応製品を認証するステップが、 メモリから前記デバイスセキュリティキーにアクセスするために、前記受信されたデバイスIDを使用するステップと、 前記受信されたセキュリティトークンを認証するために、前記記憶されたデバイスセキュリティキーを使用するステップと、 前記受信されたデバイスIDが、前記受信されたセキュリティトークンを認証するデバイスセキュリティキーに前記サーバがアクセスすることを可能にする場合、前記ワイヤレス対応製品を認証するステップとを含む、請求項1に記載の方法。
- 5前記ワイヤレス対応製品の前記製造業者から受信された前記デバイスセキュリティキーが、セキュリティトークンを生成するために前記サーバが使用することができる情報を含み、 前記受信されたセキュリティトークンを認証するために、前記記憶されたデバイスセキュリティキーを使用するステップが、 生成されたセキュリティトークンを取得するために、前記ワイヤレス対応製品の前記製造業者から受信された前記デバイスセキュリティキーを使用するステップと、 前記生成されたセキュリティトークンを前記受信されたセキュリティトークンと比較するステップとを含む、請求項4に記載の方法。
- 6前記ワイヤレス対応製品の前記製造業者から受信された前記デバイスセキュリティキーが、製造業者が提供したセキュリティトークンを含み、 前記受信されたセキュリティトークンを認証するために、前記記憶されたデバイスセキュリティキーを使用するステップが、前記製造業者が提供したセキュリティトークンを前記受信されたセキュリティトークンと比較するステップを含む、請求項4に記載の方法。
- 7前記ワイヤレス対応製品によって開始された前記ネットワーク接続が、前記顧客のプライベート通信ネットワーク用のアクセスデバイスのゲストアクセス機構を介した前記サーバへの接続である、請求項1に記載の方法。
- 8前記ワイヤレス対応製品によって開始された前記ネットワーク接続が、パブリックネットワークを介した接続である、請求項1に記載の方法。
- 9ワイヤレス対応製品をプライベート通信ネットワークに接続することを容易にするように構成されたサーバであって、 動作を実行するためのプロセッサ実行可能命令で構成されたサーバプロセッサを備え、前記動作が、 顧客の識別子 (顧 客I D) および前記顧客の前記プライベート通信ネットワークにアクセスするためのネットワーク資格証明を記憶するステップと、 前記顧客による前記ワイヤレス対応製品の購入に関与するコンピューティングデバイスから、前記ワイヤレス対応製品の前記顧客IDおよびデバイスIDを受信するステップと、 前記顧客IDと前記デバイスIDとの関連付けを記憶するステップと、 前記ワイヤレス対応製品によって確立されたネットワーク接続を介して、前記ワイヤレス対応製品から前記デバイスIDおよびセキュリティトークンを受信するステップと、 前記受信されたデバイスIDおよびセキュリティトークンに基づいて前記ワイヤレス対応製品を認証するステップと、 前記ワイヤレス対応製品の認証に応答して、前記顧客の前記プライベート通信ネットワークにアクセスするための前記ネットワーク資格証明を前記ワイヤレス対応製品に提供するステップと を含む、サーバ。
- 10前記サーバプロセッサが、前記顧客IDと、顧客情報が入力される顧客登録プロセスの間に前記顧客のプライベート通信ネットワークにアクセスするための前記ネットワーク資格証明とを取得するためのプロセッサ実行可能命令で構成される、請求項9に記載のサーバ。
- 11前記顧客登録プロセスが、顧客ロイヤルティプログラム用の契約手順を含む、請求項10に記載のサーバ。
- 12前記サーバプロセッサが、 前記デバイスIDおよび前記ワイヤレス対応製品の製造業者からのデバイスセキュリティキーを受信するステップと、 前記デバイスセキュリティキーを前記デバイスIDにリンクされた前記サーバによってアクセス可能なメモリに記憶するステップとをさらに含む動作を実行するためのプロセッサ実行可能命令で構成され、 前記サーバプロセッサが、前記受信されたデバイスIDおよびセキュリティトークンに基づいて前記ワイヤレス対応製品を認証するステップが、 メモリから前記デバイスセキュリティキーにアクセスするために、前記受信されたデバイスIDを使用するステップと、 前記受信されたセキュリティトークンを認証するために、前記記憶されたデバイスセキュリティキーを使用するステップと、 前記受信されたデバイスIDが、前記受信されたセキュリティトークンを認証するデバイスセキュリティキーに前記サーバがアクセスすることを可能にする場合、前記ワイヤレス対応製品を認証するステップと を含むように動作を実行するためのプロセッサ実行可能命令で構成される、請求項9に記載のサーバ。
- 13前記サーバプロセッサが、 前記ワイヤレス対応製品の前記製造業者から受信された前記デバイスセキュリティキーが、セキュリティトークンを生成するために前記サーバが使用することができる情報を含み、 前記受信されたセキュリティトークンを認証するために、前記記憶されたデバイスセキュリティキーを使用するステップが、 生成されたセキュリティトークンを取得するために、前記ワイヤレス対応製品の前記製造業者から受信された前記デバイスセキュリティキーを使用するステップと、 前記生成されたセキュリティトークンを前記受信されたセキュリティトークンと比較するステップと を含むように動作を実行するためのプロセッサ実行可能命令で構成される、請求項12に記載のサーバ。
- 14ワイヤレス対応 装置 であって、 ワイヤレストランシーバと、 メモリと、 前記ワイヤレストランシーバおよび前記メモリに結合され、動作を実行するためのプロセッサ実行可能命令で構成されたプロセッサとを備え、前記動作が、 パブリックアクセスネットワークを介してサーバへの接続を確立するステップと、 前記メモリに記憶されたデバイス識別子およびセキュリティトークンを前記確立された接続を介して前記サーバに送信するステップと、 前記サーバから、プライベート通信ネットワークにアクセスするためのネットワーク資格証明を受信するステップと、 前記サーバへの前記確立された接続を切断するステップと、 前記プライベート通信ネットワーク用のアクセスデバイスの範囲に入ると、前記プライベート通信ネットワークにアクセスするために前記サーバによって提供された前記ネットワーク資格証明を使用して、前記プライベート通信ネットワークとの接続を確立するステップとを含む、ワイヤレス対応 装置 。
- 15プライベート通信ネットワークへのワイヤレス対応製品の接続を容易にするためのシステムであって、 パブリックネットワークを介してアクセス可能であるように構成されたサーバと、 ワイヤレス対応製品と、 顧客のプライベート通信ネットワークを提供するアクセスデバイスと、 前記パブリックネットワークに結合され、前記顧客による前記ワイヤレス対応製品の購入トランザクションをサポートするように構成されたコンピューティングデバイスとを備え、 前記サーバが、前記顧客の識別子 (顧 客I D) および前記顧客の前記プライベート通信ネットワークにアクセスするためのネットワーク資格証明を記憶するステップを含む動作を実行するように構成され、 前記コンピューティングデバイスが、 前記ワイヤレス対応製品に関連付けられたデバイスIDおよび前記ワイヤレス対応製品を購入する前記顧客の前記顧客IDを取得するステップと、 前記顧客IDおよび前記デバイスIDを前記サーバに提供するステップとを含む動作を実行するように構成され、 前記サーバが、前記顧客IDと前記デバイスIDとの関連付けを記憶するステップをさらに含む動作を実行するように構成され、 前記ワイヤレス対応製品が、 前記サーバへの接続を確立するステップと、 前記デバイスIDおよびセキュリティトークンを前記確立された接続を介して前記サーバに送信するステップとを含む動作を実行するように構成され、 前記サーバが、 前記デバイスIDおよびセキュリティトークンに基づいて前記ワイヤレス対応製品を認証するステップと、 前記ワイヤレス対応製品の前記認証に応答して、前記顧客の前記プライベート通信ネットワークにアクセスするための前記ネットワーク資格証明を前記確立された接続を介して前記ワイヤレス対応製品に提供するステップと をさらに含む動作を実行するように構成され、 前記ワイヤレス対応製品が、 前記サーバへの前記確立された接続を切断するステップと、 前記プライベート通信ネットワーク用の前記アクセスデバイスの範囲に入ると、前記サーバによって提供された前記顧客のプライベート通信ネットワークにアクセスするための前記ネットワーク資格証明を使用して、前記プライベート通信ネットワークとの接続を確立するステップとをさらに含む動作を実行するように構成される、システム。
Independent claims15
63 paragraphs, as filed
The present invention relates to methods and systems for onboarding wireless-enabled products in networks.
Typical customer appliances and electrical devices are equipped to connect to wireless networks and provide smart home lighting systems controlled by smartphones. Networking common electrical components and appliances is sometimes referred to as the Internet of Things (IoT) or the Internet of Everything (IoE).
Integrating such smart appliances in wireless networks, including wireless connectivity in regular appliances, provides convenience and new services to customers, but the widespread deployment of such technologies allows customers to do so. Need to learn how to implement and use various devices. One reason customers may refuse to implement networked devices is that it seems difficult to install smart appliances in their private networks. The process of configuring a smart appliance to communicate with a private wireless network involves exchanging credentials so that a secure communication link can be established between the appliance and the network. This process is sometimes referred to as "Onboarding."
Customers are becoming increasingly accustomed to connecting their computers or smartphones to private wireless networks (eg WiFi networks), but the onboarding process is more difficult for appliances that do not have a display and user interface (eg keyboard). Devices that do not have a display and a convenient user interface are sometimes referred to as "headless devices." Headless devices typically require the use of another computing device to complete the onboarding process, and onboard applications where the customer must acquire another device or learn how to use it. You need to configure your own smartphone or other device with it. Therefore, onboarding of headless devices can be threatening or frustrating for customers who are not good at technology. Therefore, a simple and convenient installation procedure is desirable to enable the widespread deployment of Internet of Things devices.
<p> Various embodiments include methods, devices and systems configured to facilitate the connection of wireless-enabled products to private communication networks. Various embodiments may include storing the customer's identifier (customer ID) and network credentials to access the customer's private communication network on the server prior to the purchase transaction. While enabling a purchase transaction for a customer to purchase a wireless-enabled product, the computing device that enables the purchase transaction gets the customer's ID and the device ID associated with the wireless-enabled product, and the customer ID and device ID. Can be provided to the server. Upon receiving this information, the server may remember the association of the customer ID with the device ID by the server. At some point after or during the purchase transaction, wireless-enabled products establish a connection to the server, such as through a public network, and the device ID and security stored in memory over the established connection. Tokens and can be sent to the server. Upon receiving this information, the server authenticates the wireless-enabled product based on the device ID and security token, and in response to the wireless-enabled product's authentication, wirelessly enables network credentials to access the customer's private communication network. Can be provided to the product. The wireless-enabled product then disconnects from the established connection to the server and enters the range of access devices for the private communication network, and the network credentials provided by the server to access the customer's private communication network. Can be used to establish a connection with a private communication network.</p><p> In some embodiments, the customer ID and network credentials for accessing the customer's private communication network can be obtained by the server during the customer registration process where the customer information is entered. In some embodiments, the customer registration process can be a contract procedure for a customer loyalty program. In some embodiments, a computing device that allows a purchase transaction may obtain a customer ID from a customer loyalty database associated with a retailer.</p><p> In some embodiments, the wireless capable product may establish a connection to the server through the guest access mechanism of the access device for the customer's private communication network. In some embodiments, the wireless capable product may establish a connection to the server over a public network.</p><p> Some embodiments may include methods implemented in a server to facilitate the connection of wireless-enabled products to private communication networks. In such an embodiment, the server may store the customer's identifier (customer ID) and network credentials for accessing the customer's private communication network. The server may receive the device ID associated with the wireless-enabled product and the customer ID of the customer purchasing the wireless-enabled product from the computing device that enables the purchase transaction for the customer to purchase the wireless-enabled product. The server may remember the association between the customer ID and the device ID. Later, the server may receive the device ID and security token from the wireless-enabled product over the network connection initiated by the wireless-enabled product. The network connection can be through the guest access mechanism of the access device for the customer's private communication network, or through the public network. The server authenticates the wireless-enabled product based on the device ID and security token received, and in response to the wireless-enabled product's authentication, provides the wireless-enabled product with network credentials to access the customer's private communication network. Can be done. In some embodiments, the customer ID and network credentials for accessing the customer's private communication network are provided during the customer registration process, where customer information is entered, such as during the contract procedure for a customer loyalty program. Can be obtained by the server.</p><p> In some embodiments, the server may receive the device ID and device security key from the manufacturer of the wireless capable product and store the device security key in memory accessible by the server linked to the device ID. In such an embodiment, the server uses the received device ID to access the device security key from memory and uses the stored device security key to authenticate the received security token. The device ID received by using and authenticating the wireless-enabled product if the received device ID allows the server to access the device security key that authenticates the received security token. And can authenticate wireless-enabled products based on security tokens. In some embodiments, the device security key received from the manufacturer of the wireless-enabled product may be information that the server can use to generate a security token, authenticating the received security token. To use the stored device security key to obtain the generated security token is to use the device security key received from the manufacturer of the wireless enabled product and to use the generated security token. It may include comparing with the received security token. In some embodiments, the device security key received from the manufacturer of the wireless capable product may be a manufacturer-provided security token, which is the device security stored to authenticate the received security token. Using the key may include comparing the security token provided by the manufacturer with the security token received.</p><p> Some embodiments include servers configured to perform server operations in the manner described above. Some embodiments include wireless-enabled devices configured to perform the wireless-enabled device operations of the methods described above. In some embodiments, a server, a wireless-capable device, an access device that supports a customer's private communication network, and each of the system components are configured to perform their respective actions in the manner described above. Includes a system consisting of computing devices configured to be able to support purchase transactions.</p><p> The accompanying drawings, which are incorporated herein and constitute a portion of this specification, illustrate exemplary embodiments and describe the features of the invention, along with the general description above and the detailed description below. Useful for.</p>
<figref num="1A">FIG. 5 is a communication network diagram showing exemplary components and communication paths for implementing various embodiments.</figref><figref num="1B">FIG. 5 is a communication network diagram showing different communication paths between different devices for implementing different embodiments.</figref><figref num="2">FIG. 6 is a block diagram showing components of an exemplary wireless-enabled product or appliance suitable for use with various embodiments.</figref><figref num="3A">FIG. 5 is a message flow diagram showing a message flow associated with assigning a device ID to a wireless-enabled product according to various embodiments.</figref><figref num="3B">It is a message flow diagram which shows the message flow associated with the registration of the customer information by various embodiments.</figref><figref num="3C">It is a message flow diagram which shows the message flow associated with providing the device ID and the customer ID acquired during a transaction by various embodiments.</figref><figref num="3D">FIG. 5 is a message flow diagram illustrating a message flow associated with authenticating a wireless-enabled product and obtaining information for accessing a private network by the wireless-enabled product, according to various embodiments.</figref><figref num="3E">FIG. 6 is a message flow diagram illustrating a message flow associated with accessing a private network by a wireless-enabled product using information for accessing the private network, according to various embodiments.</figref><figref num="4">FIG. 5 is a process flow diagram illustrating an embodiment method for a system that provides access to a private communication network to a wireless-enabled product according to various embodiments.</figref><figref num="5">It is a process flow diagram which shows the embodiment method for accessing a private network by a wireless-enabled product by various embodiments.</figref><figref num="6">It is a process flow diagram which shows the method which can be implemented in the point-of-sale device during the transaction of purchasing a wireless-enabled product by various embodiments.</figref><figref num="7">It is a process flow diagram which shows the method for supporting the automatic onboarding of a wireless-enabled product implemented in a server by various embodiments.</figref><figref num="8">It is a component diagram which shows the exemplary server suitable for use by various embodiments.</figref>
Various embodiments will be described in detail with reference to the accompanying drawings. Whenever possible, the same reference number is used throughout the drawing to refer to the same or similar parts. References made to specific examples and embodiments are for illustration purposes only and are not intended to limit the scope of the invention or claims.
Various embodiments provide systems and methods for facilitating onboarding wireless-enabled products and appliances so that such smart devices connect to the customer's wireless network after the customer purchases the device. , Allows you to basically configure the smart device itself. Various embodiments utilize a database maintained on the server that allows the server to correlate the headless device with the customer network credentials and authenticate the headless device before downloading the customer's network credentials. To. The customer only needs to register once on the server and provides the customer identifier (customer ID) and credentials to access the customer's wireless network. When a customer purchases a wireless-enabled product or appliance, the product identifier (Product ID) and the customer's ID are transferred to the server. The server uses this information to correlate the product ID with the customer ID in the appropriate database. Later, when a wireless-enabled product or appliance accesses the server over an open internet connection, the product or appliance sends its product ID and unique token to the server. The server uses the product ID to search for the corresponding token or authentication credentials for the product and authenticates the product based on the received token. Once authenticated, the server uses the correlated customer ID to search for network credentials for the customer's private network and download the credentials to a wireless-enabled product or appliance. The wireless-enabled product or appliance then uses the downloaded credentials to access the customer's private network.
The term "exemplary" is used herein to mean "act as an example, case, or example." Any implementation described herein as "exemplary" should not necessarily be construed as preferred or advantageous over other implementations.
The term "computer device" is used herein to refer to Internet of Things (IoT) devices, smart home devices, smart appliances, smart utility meters (gas, electricity, etc.), smart parking meters, cellular phones, smartphones, personal or Mobile multimedia players, mobile information terminals (PDAs), laptop computers, desktop computers, tablet computers, smart books, palmtop computers, wireless email receivers, multimedia internet-enabled cellular phones, televisions, smart TVs, smart TVs Setup Buddy Boxes, Integrated Smart TVs, Streaming Media Players, Smart Cable Boxes, Set Top Boxes, Digital Video Recorders (DVRs), Digital Media Players, and Similar Personal Electronic Devices Including Programmable Processors, Especially Personal Electronics Including SoCs Used to refer to any one or all of the devices.
The inability of wireless-enabled products to easily connect to the intended network results in returns or a poor out-of-box experience for the customer. Given a typical retail purchase regime, manufacturers and retailers, whether over-the-counter or online / delivery, will have Wi-Fi when the device is purchased, taken home or delivered, and opened. It addresses reliability and / or complexity issues centered around onboarding Fi devices into the customer's network. Retailers and manufacturers, at least initially, have a limited level of customer relationships and interactions, which may be necessary to ensure that a customer's initial product experience is consistently good. It is difficult to provide such kind of technical support.
There is no way to guarantee that a customer will be able to successfully launch and install a product when the box is opened and an attempt is made to launch it upon face-to-face purchase or receipt of shipment of a wireless-enabled product or appliance. In addition, device boots are often successful and often the least dissatisfied, if done correctly first. Even if the customer has internet access at home, the initial boot of the device can be a hassle and may require several permissions and on / off cycles to complete the boot, but it succeeds and the device There is no guarantee that it will work. This can lead to customer dissatisfaction and an overall poor customer experience.
Various embodiments address the shortcomings of current onboarding mechanisms by providing an automated process for configuring purchased devices to connect to private wireless networks (eg, home or commercial WiFi networks). Overcome. In various embodiments, the wireless-enabled product can be associated with the customer at the time of purchase or shipment, so that the customer onboards the device to the customer's private network (ie, connects to the customer's private network and connects to the customer's private network. No further interaction with the device is required to integrate with).
FIG. 1A shows various computing devices and networks that can serve as system 100 for implementing various embodiments. Various embodiments facilitate onboarding of wireless-enabled products 120a-120d to the private wireless network 130. The private wireless network 130 can be built around the access point 140, which establishes a wireless connection 121 with some wireless-enabled products 120b-120d, or can be facilitated by the access point 140. Wireless-enabled products 120b-120d may be IoT devices such as smart light bulbs, network-enabled appliances, and networked home or office systems. The access point 140 may provide a connection to a public network 151, such as the Internet, via a connection 141, which may be a wired or wireless connection.
In various embodiments, the product manufacturer 157, the server 150, and the retailer point-of-sale device 155 may work together over network 151 to enable automatic onboarding of wireless-enabled products 120a-120d. .. Manufacturer 157 of wireless-enabled product 120a may configure the product with product IDs and security tokens stored in memory during product manufacturing, such as during final testing and configuration or while preparing the product for shipment. The product ID may be unique within a similar population of products, or the product serial number, MAC. It may be globally unique, such as an ID or other unique identifier. In addition to storing the product ID in non-volatile memory, the product ID may be printed on the product label and / or on the packaging, encoded in the barcode, and stored in the RFID tag. Alternatively, it may be provided on the packaged product in a manner that can be read at the time of sale. The security token stored in memory can be a unique value with enough digits to reduce the likelihood of being inferred or endangered. In addition to configuring the wireless-enabled product 120a, the manufacturer 157 may communicate the device ID and security token (message 158) to the server 150, such as via the Internet 151.
The server 150 provides a service that automatically provides network credentials to wireless-enabled products and may therefore consist of sufficient database and network capabilities to perform such functions. Server 150 may be associated with manufacturer 157, may be provided by a retailer, or may be provided as an independent service by a third party. Server 150 receives the device ID and security token provided by manufacturer 157 for each wireless enabled product. This information may be stored in the database, which can be of any type that allows the server to find the corresponding security token when providing the device ID.
The retail point-of-sale (POS) device 155 may be any of a variety of point-of-sale computing systems that can be used to support purchase transactions for wireless-enabled products. For example, the retailer point-of-sale device 155 may be a server at an online retailer, or a computer at a traditional retailer checkout counter, a portable transaction terminal carried by an individual, and the like. The retailer POS device 155 includes a connection 156 to a network 151 (eg, the Internet) through which information can be passed to the server 150 during a purchase transaction. As described in more detail below, the information that can be retrieved during a transaction and passed to server 150 typically includes the device ID as well as the customer ID of the wireless-enabled product being purchased.
The process of onboarding wireless-enabled products 120a-120d, according to various embodiments, is such that the wireless-enabled products 120a-120d receive network credentials before connecting to the private network 130 on a public network (eg, the Internet). Includes accessing server 150 via 151). Access to the Internet 151 can be achieved via a wireless connection 162 to a public network access point 160 that provides access to the Internet 151. Access to the server 150 can also be achieved via the guest network provided by the access point 140 within the customer's own network 130.
In addition, the customer may use any of the various computers 165 to register himself with the server 150. As described below, this registration is to provide or receive a customer ID and to provide the network credentials and other information required by wireless-enabled products to connect to the customer's private network 130. Can be accompanied by. Customer registration is done on the customer's own computer, such as during a customer loyalty program contract or during the purchase of an access point device before first setting up a private network, using a retailer computer (for example, a POS device). Can be achieved through website registration using 165. In some embodiments, access points and wireless-enabled products from the same manufacturer may be purchased together at the retailer. In such an example, the access point's network credentials may be pre-programmed into a wireless-enabled product or pre-stored on the server 150 without the customer having to provide network access information.
FIG. 1B shows the dialogue of the system 100 elements between the various actions that complete the onboarding process, according to various embodiments.
During manufacturing, product manufacturer 157 may store the security token and device ID in the non-volatile memory of the wireless-enabled product or appliance 120. In addition, product manufacturer 157 will provide the server 150 with a security token and device ID to be maintained on the server or recorded in a database accessible to the server to later authenticate the wireless capable product or appliance. Can be made possible.
At some point before or between purchases, customer 140 registers with server 150 for automatic onboarding (communication 1). During this one-time registration, the customer has credentials and configuration information to access the customer's private wireless network onboard various wireless-enabled products or appliances (commonly referred to herein as "network credentials". (Called) to the server. As part of the registration process, customer 140 may enter or be given a customer ID, and the server may store network credentials in a database linked to the customer ID. The registration process may be accomplished at the point of sale, either through website registration or by performing other registrations, as part of the loyalty program contract procedure of the retailer, manufacturer, or other entity. In some cases, registration can be accomplished during the purchase of a wireless access point that provides the basis for a customer's private wireless network. Therefore, customer 140 provides the server with the information needed by a wireless-enabled product or appliance that will be integrated into the customer's private network.
At the time of purchase, the retailer can scan the barcode, type what is printed on the label into the point-of-sale computer, or wirelessly receive the device ID from Near Field Communication (NFC) or RFID (Radio Frequency Identification). You can get the device ID of an appliance, device or other wireless-enabled product 120, for example. Also at the time of purchase, the retailer may obtain a customer ID of 140 customers. Customer ID is wireless by scanning the retailer's loyalty card (or other identification mechanism), allowing the customer to type the identifier into the keypad, or via NFC communication with the customer's smartphone. Can be obtained in. During an online purchase, the customer may be required to enter their customer ID as part of completing the transaction. As part of completing the purchase transaction, the retailer sends the retrieved device ID and customer ID to the server (communication 2). The server then correlates the device ID with the customer ID in the database (for example, linking two identifiers, creating a new database, or adding one of the identifiers to a database linked to the other).
When a purchased wireless-enabled product or appliance is received by customer 140, the customer powers on the wireless-enabled product and the wireless-enabled product connects to the Internet over an open network (for example, a guest network or public WiFi access point). Make it possible. When connected to the Internet, wireless-enabled products access the server, register with the server (communication 3), and provide the device ID and security token that was loaded into memory at the time of manufacture. The server uses one of a variety of authentication mechanisms, such as using the device ID to find the corresponding record in the database and comparing the received security token with the security token stored in the database. Authenticate wireless-enabled products based on device ID and security token. In some embodiments, the security token may include a shared key that allows wireless-enabled products and servers to communicate over an encrypted communication protocol. Without the proper key, wireless-enabled products will not be able to communicate with the server.
Once the wireless-enabled product is authenticated by the server, the server can use the customer ID, which correlates with the device ID, to access the customer's network credentials stored during the customer registration process. The server can use the established internet connection to download the customer's network credentials and other information (such as the access point SSID) or otherwise provide them to wireless-enabled products (communication 4). ). Wireless-enabled products may store that information in memory (eg, non-volatile memory). During the download process, the server verifies that the credentials have been downloaded and recorded correctly, instructs the product to configure various communication parameters, and in some cases connects the product to the customer's private network. Commands can also be sent to wireless-enabled products to facilitate onboarding processes such as enabling.
Once the network credentials are downloaded and the wireless enabled product is configured for the customer's private network, the wireless enabled product disconnects from the public network and connects to the customer's private network 130 using the received network credentials. You can try to (communication 5). The wireless-enabled product 120 and the access point 140 of the private network 130 can automatically complete the onboarding process using the network credentials received from the server. Therefore, various embodiments, apart from prior one-time registration to the server (communication 1), onboard the wireless-enabled product on the customer's private wireless network 130 without any effort on the part of the customer 140. To enable.
FIG. 2 shows various components of a typical wireless capable product 120 suitable for use with various embodiments. Any of a variety of electrical devices (eg, light bulbs) and appliances (eg, toasters, refrigerators, etc.) can be equipped with wireless capabilities by including a wireless interface 210 within the device. Such a wireless interface 210 may include a power supply 211 such as a circuit configured to convert the power supply of the device into a form and voltage suitable for the wireless interface 210. The wireless interface 210 is a central processor unit (CPU) that can be coupled to memory 213, digital signal processor (DSP) 214, modem 215 and transceiver 216, control interface 218, and other components (not shown) via bus 219. ) 212 may be included. The CPU 212 may control the overall operation and communication. Modem 215 and transceiver 216 may communicate with the customer's private network 130 via wireless transmission from antenna 217. The control interface 218 may include circuits for controlling the device or appliance 120, such as a control resistor or switch for controlling the amount of light produced by the smart light bulb. In some implementations, the wireless interface 210 may be implemented as a system on chip (SoC).
3A-3E show the various communications exchanged between the components and the computing device with the system 100 for implementing the various embodiments. With reference to Figure 3A, a device ID and security token can be generated and uploaded to the wireless-enabled product 120 via several different processes or otherwise provided. For example, the manufacturer 157 may provide the device ID and security token in communication 311 to the server 150, and the server may provide the device ID and security token in communication 313 to the wireless capable product 120. As another example, the manufacturer 157 may store the device ID and security token in the wireless capable product 120 in communication 315, and may notify the server 150 of the device ID and security token in communication 311. In a further example, manufacturer 157 may store the device ID and security token in communication 315 in the wireless capable product 120, which provides the device ID and security token to server 150 in communication 317. May be good.
FIG. 3B shows an exemplary communication involved in registering customer 140 with server 150. In some cases, customer 140 may access server 150 via website 318 accessed by a computing device (eg, customer's computer 165). By interacting with website 318, customer 140 may initiate registration with the server over communication 319. This registration process can also be accomplished as part of enrolling in a retailer's or manufacturer's customer loyalty program. The server 150 may generate a customer ID and provide the customer ID to the customer 140 in communication 321. The server may also store the customer ID in the database in operation 323.
As part of the registration process, customer 140 may provide the network credentials and other information needed to access the customer's private network in communications 325. Providing information to access a private network may include providing the name of the private network and / or SSID, and a password or encryption key (collectively referred to herein as network credentials). In cases where customer registration is achieved as part of purchasing a network access point, generating a private network name and password / encryption key can be achieved as part of a point-of-sale purchase transaction. The server may store information for accessing the private network in operation 327. When the registration process is complete, the server may send a message 329 confirming that the registration was successful. In cases where registration with Server 150 is part of the Customer Loyalty Program, further communications associated with the Loyalty Program may follow.
Figure 3C shows communication from a point-of-sale computing device, such as retailer point-of-sale device 155, to server 150 during a purchase transaction for wireless-enabled product 120. During the transaction, the retailer obtains the device ID and customer ID and sends this information to server 150 over communication 333, such as over the Internet, via a private connection with the manufacturer or another connection. As mentioned above, the retail point-of-sale device 155 scans the bar code on the product package and enters the code printed on the product package into the point-of-sale computing device, the retail point-of-sale device 155. By reading an RFID tag or scanning an NFC device embedded in a product package using a point-of-sale computing device, retailer point-of-sale device 155, or an RFID or NFC reader included in another mechanism. You can get the device ID. Retailers can scan customer loyalty cards, search for customers in databases by customer number, phone number or other information, have customers enter their ID in the keypad, or by other mechanisms, customer ID. Can be obtained.
Figure 3D shows the communications and processes involved in authenticating the wireless-enabled product 120 and providing network access information. When the wireless-capable product 120 is powered on within the customer's private network access point 140, the product may attempt to find an open network connection or request a guest login in communication 341. The access point 140 can allow login requests in communication 343, the wireless capable product 120 uses the access point 140 to access the server 150, and in communication 345 the product device ID and security token is sent to the server 150. provide. Server 150 may use the device ID and security token to determine if the product is authenticated in operation 347. If the server 150 determines that the wireless-enabled product 120 is not authenticated, the server 150 may send access denied communication 348 to the wireless-enabled product 120. If the server 150 authenticates the wireless-enabled product 120, the server 150 may send network credentials and other information to the wireless-enabled product to access the customer's private network in communication 349.
Figure 3E shows the communications involved in the wireless enabled product 120 accessing the private network 130. In communication 351 the wireless capable product 120 may send a login request to the private network access point 140 using the information provided by the server 150 to access the network (network credentials). In decision block 352, the processor at the private network access point 140 may determine if the information for accessing the network is correct. In response to determining that the information to access the private network is correct (ie, decision block 352 = "Yes"), the processor on the private network access point 140 allows the private network login request in communication 353. , Can establish a secure communication link with wireless compatible product 120. Using this established communication link, wireless-enabled products 120 and access points 140 can exchange communications 355 such as control commands, operational status, etc. as part of the Internet of Things network. In response to determining that the information to access the private network is incorrect (ie, decision block 352 = "No"), the processor on the private network access point 140 denies access to the private network in communication 357. Can be done.
FIG. 4 shows method 401 for automating onboarding of wireless-enabled products according to various embodiments. With reference to FIGS. 1A-4, the operation of Method 401 may be performed by a wireless-enabled product 120, a server 150, and a point-of-sale computing device, a retailer point-of-sale device 155, as described above.
At block 409, the customer may register with the server, provide the server with network access credentials and related information, and receive the customer ID. As explained above, this registration of the customer on the server is part of the customer loyalty registration process, as part of the purchase of the network access point, that the customer visits the website and fills out the registration form. Or it can be achieved by other processes. As part of this registration, the customer may provide network access credentials and related information, and the server may store the network access credentials and related information in a database linked to the customer ID in block 409. When a customer purchases an access point with a wireless-enabled device, the server may already remember the network access credentials.
At block 411, the retailer point-of-sale device may obtain the device ID of the wireless-enabled product during the transaction in which the customer purchases the product. At block 413, the retailer point-of-sale device may acquire a customer ID as part of a transaction. At block 415, the point-of-sale device may provide the customer ID and device ID to the server.
At block 417, the server receives a customer, such as by storing the customer ID and device ID in a transactional database, or by updating either the customer ID database or the device ID database to show the correlation. IDs and device IDs can be associated in the database.
Shortly after the transaction is completed, at block 419, the wireless capable product is powered on and the connection between the product and the server can be established over the public network. At block 421, wireless-enabled products can register with a server over an established internet connection by providing a device ID and security token stored in memory when the product is manufactured.
At block 423, the server can authenticate wireless-enabled products based on device ID and security token. This authentication can use any form of authentication process based on two or more unique identifiers and security information. For example, the server searches the database record where the corresponding security token is stored and then compares the received security token with the token stored in the database to determine if the security tokens are the same. , Device ID can be used. As another example, the server searches for a corresponding record in which a hash algorithm or encryption key is stored that can be used by the server to generate a value compared to a received security token. You can use the device ID.
If the server authenticates the wireless-enabled product in block 423, the server sends information to the wireless-enabled product in block 425 to access the customer's private network over the open communication link over the public network (eg,). You can send network credentials). As part of the operation at block 425, wireless enabled products may store network credentials and other information for accessing private networks.
At block 427, the wireless-enabled product can terminate the public connection to the server, and at block 429, the wireless-enabled product uses the network credentials and other access information provided by the server to be private to the customer. You can connect to the network.
The customer registration process in block 409 needs to be performed only once, but the operation in blocks 411-429 of method 401 is that the customer purchases another wireless-enabled product to connect to the customer's private network. Can be executed every time.
FIG. 5 shows a method 501 that can be implemented in a wireless capable product according to various embodiments. At block 511, the product may receive a security token and a unique device ID during manufacturing or product testing / configuration. At block 513, the wireless capable product may store the received security token and device ID in memory.
At block 517, the wireless capable product may connect to the public network to access the server when the product is connected to power. Therefore, when a customer takes the product home (or elsewhere) and connects the product to a power source, the wireless-enabled product can begin searching the wireless network. When the product finds an open (ie, public) network, the wireless-enabled product uses that network to communicate with the server. Until a connection to the server is established, wireless-enabled products can continue to search for public networks and complete such communications.
Once the connection to the server is established, the wireless capable product can register with the server in block 519 by providing the device ID and security token stored in memory. At block 521, wireless-enabled products can receive network credentials and other information to access the customer's private network, such as in response to a successful registration / authentication by the server.
At block 523, the wireless capable product can store the received network credentials and information received from the server associated with accessing the private network. At block 525, the wireless capable product can disconnect from the public network and at block 527, connect to the private network using the received network credentials and information.
FIG. 6 shows method 601 that can be implemented in point-of-sale computing devices (eg, retailer point-of-sale device 155). At block 611, the point-of-sale device may obtain the device ID of the wireless-enabled product in connection with the purchase transaction. At block 613, the point-of-sale device may obtain an individual customer ID to purchase a wireless-enabled product. At block 615, the point-of-sale device may send the acquired device ID and customer ID to the server.
FIG. 7 shows a method 701 that can be implemented in a server to support automatic onboarding of wireless-enabled products according to various embodiments.
At block 711, the server may perform a customer registration process in which a customer account is created for a customer associated with a customer identifier (eg, customer ID). The server may generate a customer ID on behalf of the customer or receive a customer ID (eg, email address) from the customer.
At block 713, the server may receive from the customer customer network credentials and other information to access the customer's private network, which may be entered by the customer as part of the customer registration process. At block 715, the server may store the customer's identifier (eg, customer ID) in the database along with the network credentials to access the customer's private communication network. In some embodiments, the network credentials may be linked to the customer ID in the database.
At block 717, the server may receive the device ID and device security key of the wireless capable product (eg, a device security token, or information that can be used to generate or authenticate a device security token). For example, in some implementations, in block 717, the server may receive a device ID and security token from the product manufacturer and store the device security key. In another implementation, in block 717, the server receives device IDs and information (eg, seed tokens for algorithms or shared algorithms) that the server can use to generate security tokens from the product manufacturer. Can be received. In a further implementation, the server may generate a device ID and security token and provide that information to the device manufacturer for storage in wireless-enabled products. At block 719, the server stores the device ID and security key of the wireless-enabled product in memory accessible by the server linked (for example, indexed to the product ID) to the device ID in the searchable database. obtain.
The server may then receive the device ID and customer ID at block 721 from a computing device (eg, a point-of-sale computing device) that allows the customer to make a purchase transaction for a wireless-enabled product. At block 723, the server may store the association between the received customer ID and the received device ID in the database. This association may allow the server to identify the associated customer ID given the device ID. This behavior correlates the two databases, such as linking the customer ID to the device ID or creating a new database, such as a database containing the customer ID and device ID, such as the one indexed on the device ID. It can be accompanied by that.
The server may then receive the device ID and security token from the wireless-enabled product in block 731 over the public network connection initiated by the wireless-enabled product. This happens when the wireless-enabled product is powered on and has access to the public network.
At block 733, the server can authenticate wireless-enabled products based on the device ID and security token received. For example, the server authenticates database records that store device security keys (for example, device security tokens, or information that the server can use to generate or validate device security tokens) and wireless-enabled products. The device ID can be used to access other credentials that the server can use.
If the server authenticates the wireless-enabled product based on the security token received, at block 735, the server may use the customer ID to retrieve information from the database to access the customer's private network. The information retrieval includes the device ID and customer ID previously stored in block 723 to identify the database record containing the network credentials and information for accessing the customer's private network stored in block 715. It can be achieved by using the association between. At block 737, the server may use an open connection over a public network to provide network credentials and information to wireless-enabled products to access a customer's private communication network.
Various embodiments, including the embodiments shown in FIGS. 5-7, may be implemented in a point-of-sale device that uses any of a server and a variety of commercially available server devices, such as the server 800 shown in FIG. .. Such a server 800 typically includes a processor 801 coupled with a volatile memory 802 and a large capacity non-volatile memory such as a disk drive 803. The server 800 may also include a floppy disk drive, compact disk (CD) or digital versatile disk (DVD) disk drive 804 coupled to the processor 801. The server 800 may also include network access port 806 coupled to processor 801 to establish a network interface connection with network 807, such as other broadcast system computers and local area networks coupled to the server.
Processor 801 may be any programmable microprocessor, microcomputer or one or more multis, which may consist of software instructions (applications) for performing various functions, including the functions of the various embodiments described above. It can be a processor chip. Some devices may have multiple processors, such as one processor dedicated to wireless communication and one processor dedicated to running other applications. Normally, software applications may be stored in internal memory 802, or 803, before being accessed and loaded into processor 801. Processor 801 may include sufficient internal memory to store application software instructions. In many devices, the internal memory can be volatile memory, non-volatile memory such as flash memory, or a mixture of both. As used herein, a general reference to memory refers to memory accessible by processor 801 including internal memory or removable memory plugged into a device and memory within processor 801 itself.
The above method description and process flow diagram are given by way of example only and do not require or imply that the steps of the various embodiments must be performed in the order presented. As will be appreciated by those skilled in the art, the order of the steps in the above embodiments may be performed in any order. Words such as "after", "next", and "next" do not limit the order of the steps, and these words are simply used to guide the reader through a description of the method. Furthermore, any reference to a claim element in the singular, for example using the articles "a", "an" or "the", should not be construed as limiting that element to the singular.
The various exemplary logical blocks, modules, circuits, and algorithm steps described with respect to the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To articulate this compatibility of hardware and software, various exemplary components, blocks, modules, circuits, and steps have been generally described above with respect to their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but decisions on such implementation should not be construed as causing a deviation from the scope of the invention.
The hardware used to implement various exemplary logics, logic blocks, modules, and circuits described with respect to the embodiments disclosed herein are general purpose processors, digital signal processors (DSPs), and application specific integrated circuits. Integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, individual gate or transistor logic, individual hardware components, or those designed to perform the functions described herein. It can be implemented or implemented using any combination. The general purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. Processors can also be implemented as a combination of computing devices, such as a DSP and microprocessor combination, multiple microprocessors, one or more microprocessors working with a DSP core, or any other such configuration. .. Alternatively, some steps or methods may be performed by a circuit specific to a given function.
In one or more exemplary embodiments, the features described may be implemented in hardware, software, firmware, or any combination thereof. When implemented in software, features may be stored on or transmitted on a computer-readable medium as one or more instructions or codes. The steps of methods or algorithms disclosed herein can be embodied in processor executable software modules that can reside on tangible non-transient computer readable storage media. The tangible non-temporary computer-readable storage medium can be any available medium that can be accessed by the computer. By way of example, but not by limitation, such non-temporary computer-readable media are in the form of RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or instructions or data structures. It may include any other medium that can be used to store the desired program code and can be accessed by a computer. The discs and discs used herein are compact discs (CDs), laser discs (registered trademarks) (discs), optical discs, DVDs, floppy discs, and discs. Including Blu-ray discs, discs typically reproduce data magnetically, and discs use lasers to optically reproduce data. The above combinations should also be included within the scope of non-transitory computer-readable media. In addition, the behavior of the method or algorithm may be one or any combination of code and / or instructions on a tangible non-transitory machine-readable medium and / or computer-readable medium, or a set thereof, which may be incorporated into a computer program product. Can exist as.
The above description of the disclosed embodiments is provided so that any person skilled in the art can create or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art and the general principles defined herein can be applied to other embodiments without departing from the spirit or scope of the invention. Accordingly, the invention is not limited to the embodiments presented herein, but should be given the broadest scope of claims, as well as the broadest scope consistent with the principles and novel features disclosed herein. Is.
100 System 120 Appliance, Wireless Compatible Product 120a ~ 120d Wireless Compatible Product 121 Wireless Connection 130 Private Network, Customer's Own Network, Customer's Private Network, Customer's Private Wireless Network 140 Access Point, Customer, Customer's Private Network Access Point, Private Network Access Point 141 Connection 150 Server 151 Public Network, Network, Internet 155 Retailer Point of Sale (POS) Device, Retailer Point of Sale (POS) Device, Retailer POS Device 156 Connection 157 Product Manufacturer, Manufacturer 158 Message 160 Public Network Access Point 162 Wireless connection 165 Computer, customer's own computer, customer's computer 210 Wireless interface 211 Power supply 212 Central Processor Unit (CPU), CPU 213 Memory 214 Digital Signal Processor (DSP) 215 Modem 216 Transceiver 217 Antenna 218 Control Interface 219 Bus 318 Website 401, 501, 601, 701 Method 800 Server 801 Processor 802 Volatile Memory, Internal Memory 803 disk drive, internal memory 804 floppy disk drive, compact disk (CD) or digital versatile disk (DVD) disk drive 806 network access port 807 network
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2013211647A | Cites | Japan |
| JP2009182863A | Cites | Japan |
| JP2005142792A | Cites | Japan |
| WO2015167789A1 | Cites | World Intellectual Property Organization (WIPO) |
| US20030005088A1 | Cites | United States of America |
| US20140181521A1 | Cites | United States of America |
11 members in 8 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 15000105 | United States of America | – | |
| 201615000105 | United States of America | A | |
| 2016063349 | United States of America | W |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| US2017208070A1 | United States of America | A1 | |
| CA3008231A1 | Canada | A1 | |
| WO2017127156A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US9935962B2 | United States of America | B2 | |
| CN108464026A | China | A | |
| KR20180103892A | Republic of Korea | A | |
| EP3406092A1 | European Patent Office (EPO) | A1 | |
| BR112018014510A2 | Brazil | A2 | |
| JP2019510286A | Japan | A | |
| CN108464026B | China | B | |
| JP6901488B2This record | Japan | B2 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 6901488
- Application
- 2018536734
Titles2
- Japanese
- ネットワークにおいてワイヤレス対応製品をオンボードするための方法およびシステム
- English
- Methods and systems for onboarding wireless-enabled products in your network
Classification
- CPC, 16
- G06Q10/00
- H04W12/04
- G06Q30/0236
- G06Q10/08
- G06Q10/083
- G06Q30/0229
- G06Q30/0267
- H04W4/70
- H04W4/80
- H04L67/12
- H04W12/069
- H04L63/0876
- H04L63/102
- H04W12/06
- G06Q30/00
- H04W88/08
- IPC, 6
- G06F21 33
- G06F21 44
- H04W12 08
- H04W76 10
- H04W4 70
- H04W4 80
