Method implemented by IOT services in MATTER networks
Through the IoT service implementation method in the Matter network, using the PKI architecture and ACL management, the compatibility and security issues of IoT devices are solved, user-friendly device sharing and management are achieved, and the convenience and flexibility of the smart home system are enhanced.
Patent Information
- Application Number
- CN202580001127.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-17
- Publication Date
- 2025-09-19
AI Technical Summary
Existing IoT devices face challenges in compatibility, security, and usability. In particular, devices from different manufacturers and platforms cannot work together seamlessly and interoperably, making it difficult for users to share and manage control of IoT devices in a user-friendly manner.
Adopting the IoT service implementation method in Matter Network, the public key infrastructure (PKI) architecture is used to provide secure and reliable communication, and user permissions are managed through certificate signing and access control lists (ACLs) to achieve unified management and shared control of IoT devices.
It enables user-friendly IoT device sharing and management, simplifies the access authorization process for new users, provides decentralized and secure data sharing, and enhances the convenience and flexibility of smart home systems.
Smart Images

Figure CN120677687A_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of IoT networks, and in particular, to a method implemented by an IoT service in a Matter network. Background Art
[0002] The term IoT (or Internet of Things) refers to a network of interconnected devices (such as sensors, actuators, appliances, and other smart objects), as well as the technologies that facilitate communication between these devices and the cloud, as well as between the devices themselves. Thanks to the advent of inexpensive computer chips and high-bandwidth telecommunications, billions of devices are now connected to the internet. IoT devices can provide users with a variety of services and features, such as home automation, security, energy management, health monitoring, and entertainment. However, IoT devices also face challenges in terms of compatibility, security, reliability, and usability.
[0003] One challenge is ensuring that IoT devices from different manufacturers and platforms can work together seamlessly and interoperably. Currently, there are multiple proprietary implementations of IoT ecosystems that allow users to control, operate, and share IoT devices. However, these implementations may be incompatible with each other and may require users to install multiple applications or hubs to manage their devices. Furthermore, these implementations may not provide adequate security and privacy for users and their data.
[0004] To address this challenge, the Connectivity Standards Alliance (CSA) has launched a new standard for smart home technology called "Matter." Matter is an open source connectivity standard designed to improve the compatibility and security of IoT devices. The Matter protocol is based on the Internet Protocol (IP) and works through one or more compatible border routers, avoiding the use of multiple proprietary hubs. Matter devices run locally and do not rely on an internet connection, although the standard is designed to easily communicate with the cloud.
[0005] Users of IoT devices may want to add devices to their homes or rooms, share them with other users, and control them locally or remotely. Users may also want to access the various features and services provided by their devices, such as voice control, automation rules, scenarios, notifications, and analytics. However, these features and services may vary by device manufacturer or platform and may not be consistent or compatible across different devices.
[0006] The advancement of the Matter standard has opened up new verticals for new solutions that leverage the Matter standard's PKI infrastructure to provide these services. However, the question of how to easily share control of IoT devices between various users in a user-friendly manner, allowing other users to also set up, configure, and manage IoT devices, has not yet been addressed. Summary of the Invention
[0007] In order to overcome the deficiencies in the prior art, the present invention provides a novel way of implementing a method by an IoT service in a Matter network to facilitate shared control of IoT devices by various users. The method allows users to create and manage IoT devices in a unified and intuitive manner, utilizing Matter's PKI (Public Key Infrastructure) architecture to provide secure and reliable communication in the sharing process between devices and users. The IoT ecosystem created according to the present disclosure allows users to share access rights to home or cross-room devices with another user for local or remote control. The IoT system can be hosted in the cloud, or in any machine with sufficient connectivity (such as a server). According to the present disclosure, it enables seamless access and control of IoT devices by arbitrarily assigned new users.
[0008] In one general aspect of the present disclosure, a method implemented by an IoT service in a Matter network is provided. The method may include receiving a sharing request from a first client logged in by a first user in the Matter network, wherein the sharing request may include an identification of a second user and a specified access level for the second user, and wherein the second user is logged in by the second client. The method may also include sending a sharing notification to the second client and may also include assigning an identity ID to the second user. The method may also include generating a first certificate in response to receiving a first certificate signing request from the second client, wherein the first certificate signing request may include a public key generated on the second client and a signature created using a private key corresponding to the public key, also generated on the second client, wherein the first certificate may include the identity ID of the second user and an assigned access ID associated with the specified access level. The method may also include sending the first certificate to the second client, wherein the first certificate enables the second client to access at least one IoT device in the Matter network according to the second user's specified access level. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.
[0009] Implementations may also include one or more of the following features.
[0010] Preferably, the method may include, in response to assigning the identity ID and the access ID to the second user, updating the access control list, wherein the identity ID and the access ID of the second user are added to the access control list.
[0011] Preferably, the method may comprise signing, by the IoT service, the first certificate with a private key generated at the IoT service.
[0012] Preferably, the method may include synchronizing the access control list to at least one IoT device in the Matter network.
[0013] Preferably, the method may include, in response to the assigned access level being the administrator level, the assigned access ID being the management access ID; and in response to the assigned access level being the operator level, the assigned access ID being the operation access ID.
[0014] Preferably, in response to receiving a second certificate signing request from a third client logged in by a second user, the method may include: generating a second certificate, wherein the second certificate may include the identity ID and access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and sending the second certificate to the third client; wherein the second certificate signing request may include a public key generated on the third client.
[0015] Preferably, the method may include: the IoT service, the first client and at least the IoT device in the Matter network share a security domain, and the method may include: adding the second client to the security domain based on the first certificate; and adding the third client to the security domain based on the second certificate.
[0016] Preferably, the method may include: in response to receiving a request to remove a second user from a user with an administrator access level in the Matter network: removing the identity ID and management access ID of the second user from the access control list; and synchronizing the updated access control list to at least one IoT device in the Matter network.
[0017] Preferably, the method may further comprise providing the first user with an administrator access level in the Matter level.
[0018] In another general aspect of the present disclosure, a method implemented by a second user in a Matter network is provided. The method may include the second user logging into a second client, wherein the second client communicates with the first client logged into by the first user. The method may also include, in response to receiving a sharing notification from the IoT service, sending a first certificate signing request from the second client to the IoT service in the Matter network, wherein the first certificate signing request may include a public key generated on the second client, wherein the sharing notification is sent by the IoT service in response to the IoT service receiving the sharing request from the first client. The method may also include receiving a first certificate from the IoT service, wherein the first certificate may include an identity ID assigned by the IoT service and an access ID associated with a specified access level of the second user, wherein the specified access level is defined by the first user in the sharing request. The method may also include accessing at least one IoT device in the Matter network according to the specified access level of the second user. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.
[0019] In another general aspect, a system is provided that includes an IoT service, a first client, a second client, and at least one IoT device in a Matter network. The system may include the IoT service configured to: receive a sharing request from a first client logged in by a first user in the Matter network, wherein the sharing request may include an identity of a second user and a specified access level for the second user, and wherein the second user is logged in by the second client; and send a sharing notification to the second client. The system may also include the second client configured to: send a first certificate signing request to the IoT service, wherein the first certificate signing request may include a public key generated on the second client. The system may also include the IoT service, further configured to: assign an identity ID to the second user; generate a first certificate, wherein the first certificate may include the identity ID of the second user and an assigned access ID associated with a specified access level, and the first certificate is signed by the IoT service using a private key generated on the IoT service; and send the first certificate to the second client. The system may also include the second client, further configured to: access at least one IoT device in the Matter network according to the specified access level of the second user. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the method.
[0020] Preferably, the system may further include a third terminal for logging in by a second user, wherein the third client is configured to: send a second certificate signing request to the IoT service, wherein the second certificate signing request includes a public key generated on the third client; and the IoT service is configured to: generate a second certificate, wherein the second certificate includes the identity ID and access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and send the second certificate to the third client.
[0021] In another general aspect of the present disclosure, a non-transitory computer storage medium storing a computer program is provided, wherein the computer program, when executed by a processor, causes the processor to perform the actions of a method. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of a method.
[0022] The present disclosure simplifies the setup and management of a user's smart home devices by providing a method for easily sharing control of IoT devices in the Matter network with new users, thereby allowing users to deploy the Matter ecosystem on demand. By introducing new users by authenticated users in the Matter network, the access authorization process for new users is simplified. This mechanism allows decentralized and secure data sharing without relying on a central authority or intermediary. In addition, ACL asynchrony detection is applied in the present disclosure to ensure that ACLs are synchronized and effective throughout the network. In addition, a revocation mechanism is provided that ensures that revoked users will no longer be able to access IoT devices. Another benefit of the present disclosure is the implementation of multi-terminal access. Users can log in and access IoT devices from various terminals (such as mobile phones, tablets, laptops, etc.). This enables the use of "hubs" (such as Google Home, Amazon Alex, etc.) within the venue, which function similarly to mobile phone applications, thereby providing control over IoT devices. This also allows users to remotely monitor and manage IoT devices from different locations and devices, enhancing the convenience and flexibility of smart home systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Hereinafter, the present disclosure will be further explained based on embodiments with reference to the accompanying drawings.
[0024] Figure 1 A Matter network diagram is schematically shown.
[0025] Figure 2 Matter network 1 and Matter network 2 are schematically shown, wherein a client and IoT device A are respectively configured to be connected to the two Matter networks.
[0026] Figure 3A flowchart schematically illustrates a specific implementation of the method 300 provided by the present disclosure.
[0027] Figure 4 A flowchart of another specific embodiment of the method 400 provided by the present disclosure is schematically shown.
[0028] Figure 5 A flowchart of another specific embodiment of the method 500 provided by the present disclosure is schematically shown.
[0029] Figure 6 A flowchart of another specific embodiment of the method 600 provided by the present disclosure is schematically shown.
[0030] Figure 7 An example according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0031] The method implemented in the Matter network and its system according to the present disclosure will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments shown in the drawings and described below are merely illustrative and are not intended to limit the present disclosure. In addition, it should be understood that in the present disclosure, ordinal numbers such as "first", "second", and "third" are only used to indicate different or identical elements in the technical solution, unless explicitly specified or determined by the technical context, and do not imply any limitation on the order or importance of these elements.
[0032] Matter is a new smart home standard designed to enable interoperability and compatibility between smart devices from different brands and ecosystems. Figure 1 A Matter network, also known as Matter Fabric, is shown, which includes a group of IoT devices that share the same security domain and can communicate securely with each other; and clients, which are devices that can access, control and / or monitor IoT devices and services based on the authentication and authorization level of the user logged into the client. Typically, an IoT device can be a headless physical device that has connectivity and can provide services. For example, an IoT device can be an end device, such as a light, sensor, or camera, or a router, such as a hub, bridge, or access point that relays messages between end devices. Examples of clients include smartphones, tablets, laptops, and smart speakers. Clients can also use various applications, such as the Matter app, the Alexa app, the Google Home app, and the Apple Home app, to interact with Matter devices and services using a user account.
[0033] Each Matter network includes an IoT service that acts as a root CA, generating a unique pair of private and public keys, where the root CA's private key is securely stored in the cloud. The IoT service can be implemented in a cloud-based platform or on a local server.
[0034] The IoT device sends a request to the IoT service to request a node operational certificate (NOC), which will allow it to be authenticated as a trusted device within the Matter network. After the IoT device is provisioned with a node ID and network configuration information (such as security credentials) by the IoT service, it can use the network configuration information to establish a connection to the Matter network.
[0035] A user in a Matter network is a logical entity that can control IoT devices based on the user’s access level. For example, a user in a Matter network can be a human user or a non-human user, such as a hub that acts on behalf of a human user or in collaboration with a human user.
[0036] Users' account information is typically stored in an identity database and authenticated to the IoT cloud using separate credentials such as a username and password.
[0037] By default, three home access levels are defined for users:
[0038] Administrator: Users with this access level have full access to all management functions of the Matter network and IoT devices, such as adding, removing, or setting up devices.
[0039] Operator: Users with this access level can only operate devices in the Matter network and cannot perform administrative tasks such as turning devices on, off, or adjusting them.
[0040] None: Users with this access level cannot access the entire Matter network. Instead, users can only access certain devices set up by the IoT service.
[0041] A user can be present on multiple clients at the same time. For example, Figure 1 As shown, a user logs into a mobile phone application (Client 1) and also logs into a controller device (Client 2) in the Matter network that does not have a screen. The user logged into the mobile phone application and the user logged into the controller device have the same ability to control IoT devices.
[0042] The Matter standard uses access control lists (ACLs) to manage permissions for different devices and users. An ACL is a set of rules that defines the subject (who), target (what), and permissions (how) of access control.
[0043] Each IoT device provisioned in the Matter Network will maintain two access control lists that determine which users can perform actions on the IoT device. One ACL grants administrator access to users with an administrative access ID in the settings, and the other ACL grants operator access to users with an operational access ID in the settings. In some cases, the access ID is also called a CATID, which stands for CASE Authenticated Tag. The access ID allows for a group-based permission mechanism that assigns the same access level to multiple users sharing the same CAT ID. The IoT device can check the CAT ID in the user's certificate to determine whether to grant or deny the user's access request.
[0044] The IoT service stores a copy of all ACLs for every IoT device in the Matter network. The IoT service also tracks the synchronization status of ACLs on any IoT device. For example, the IoT service will know if an IoT device has not updated its ACL after the ACL has been updated in the IoT service but not yet on the corresponding IoT device. This way, the IoT service can detect any changes to ACLs that occurred while the IoT device was offline and flush the updates to the corresponding IoT device.
[0045] One of the features of Matter is that it allows IoT devices to be networked to multiple Matter Fabrics. This means that devices can be controlled by different ecosystems, such as Amazon Alexa, Google Home, or Apple HomeKit, without having to switch between them. For example, a light bulb can be connected to Alexa, Google Home, and HomeKit at the same time and respond to commands from any of them. This provides consumers with more flexibility and choices when adding new products or brands to their smart homes. A significant advantage of the present disclosure is that by leveraging this feature of Matter, new ecosystems can be created, providing a unified and interoperable platform for smart home devices.
[0046] To achieve this, Matter uses the Internet Protocol (IP) as the common language for all devices, regardless of the underlying network protocol they use. Matter supports Wi-Fi, Ethernet, and Thread as network protocols for devices to join Matter Fabric.
[0047] The multi-management capabilities of the Matter standard allow consumers to enjoy the benefits of interoperability, security, and reliability across different ecosystems and technologies. Figure 2The diagram shows Matter Network 1 and Matter Network 2, where a client and IoT device A are provisioned to each Matter Network. IoT device A is assigned a unique node ID in Matter Network 1 and another unique node ID in Matter Network 2. IoT device A can be controlled by user 1, who is logged into a client in Matter Network 1, or by user 2, who is logged into another client in Matter Network 2.
[0048] The Matter specification is a connectivity standard that allows users to configure and operate IoT devices within the Matter network. However, it does not specifically address how to build an ecosystem based on this foundation, allowing for multiple users, sharing, creating groups for IoT devices, and so on. This is left to ecosystem developers to implement. Therefore, there is the problem of how to add new users to the Matter network and assign them a specific level of access to the entire network. In the existing technology, if a new user wants to join the Matter network, this can only be done individually for each device in the Matter network if the new user is not already part of the Matter Fabric. For example, in this case, to allow the new user to manage the device, the current user with device administrator access must reopen the device's network provisioning window. The device then provides the new user with a new network provisioning password (e.g., encoded in a new QR code) and completes the entire network provisioning process for the new user. If the new user is already part of the Matter Fabric, for example, if the new user has local network awareness, then simply updating the access control list (ACL) on the IoT device allows this user access to the IoT device. In this case, there is no need to open the network provisioning window. However, the process of allowing new users to manage devices is difficult and time-consuming because every device in the Matter network must be operated to add the new user to access all devices.
[0049] In the present disclosure, a method implemented by an IoT service in a Matter network is provided for sharing access and control of IoT devices in the Matter network with new users.
[0050] New user access to share
[0051] Figure 3 is a flow chart of an example method 300. In some embodiments, Figure 3 One or more process blocks can be executed by IoT services in the Matter Network.
[0052] Figure 3Further illustrating, method 300 may include receiving a sharing request from a first client logged in by a first user in a Matter network, wherein the sharing request may include an identification of a second user and a specified access level for the second user, and wherein the second user logs in to a second client (block 302 ).
[0053] For example, the second user's identity can be account information typically stored in an identity database within the Matter network. This identity can be a username, email address, phone number, or other unique identifier registered within the Matter network. The designated access level can dictate what permissions the second user has to access and control the device shared by the first user. For example, the access level can be "Administrator" or "Operator" as described above, or "None."
[0054] Figure 3 Further illustrating, method 300 may include sending a sharing notification to the second client (block 304). For example, the sharing notification may include the identity of the first user initiating the sharing and the first client. The sharing notification may also include a list of devices shared by the first user and the designated access levels for the shared devices. The sharing notification may also include a confirmation code or link for accepting or rejecting the sharing request.
[0055] Figure 3 It is further shown that method 300 may include assigning an identity ID to the second user (block 306). The identity ID is a unique identifier of the user in the Matter network and does not change regardless of how many terminals the user logs into in the same Matter network. However, if the user logs into another terminal in a different Matter network, the user will receive a different identity ID in that Matter network. In some embodiments, the UUID can be defined in the range of 0x0000_0000_0000_0001 to 0xFFFF_FFEF_FFFF_FFFF.
[0056] Figure 3 It is further shown that method 300 may include generating a first certificate in response to receiving a first certificate signing request from a second client, wherein the first certificate signing request may include a public key generated on the second client, and wherein the first certificate may include an identity ID of the second user and an assigned access ID associated with a specified access level (block 308).
[0057] For example, the second client may receive a sharing notification according to block 304 and choose to accept or reject the received sharing notification. If the second client accepts the sharing notification, the second terminal will send a first certificate signing request (CSR) to the IoT service. The first certificate signing request may include a public key generated by the second terminal, which will be used by the IoT service to sign a first certificate for the second terminal. The public key is part of a key pair that also includes a private key, which is generated and securely stored on the second terminal. The private key never leaves the second terminal and is used to decrypt data or messages encrypted by other parties with the public key. The public key, as the name suggests, can be shared freely and used to encrypt data or messages for the second terminal, or to verify its identity.
[0058] like Figure 3 As further shown, method 300 may include sending a first credential to a second client, wherein the first credential enables the second client to access at least one IoT device in the Matter network according to a specified access level of the second user (block 310). For example, the first credential embeds an assigned identity ID and an assigned access ID of the second user.
[0059] In a preferred embodiment, the first certificate is signed by the IoT service using a private key generated by the IoT service.
[0060] In a preferred embodiment, the first client and at least an IoT device in the Matter network share a security domain, and the method further comprises: adding the second client to the security domain based on the first certificate.
[0061] In a preferred embodiment, in response to the assigned access level being the administrator level, the assigned access ID is the management access ID; and in response to the assigned access level being the operator level, the assigned access ID is the operation access ID.
[0062] In a preferred embodiment, the Management Access ID and Operational Access ID are Management Case Authentication Tags (CATs), which are 32-bit values shared by the IoT service to the second terminal during the establishment of a Case session. These CATs act as class group tags that can be applied to multiple nodes in a Matter network (Matter device instances in the Matter fabric), making it easier to manage access control entries that use the same group of nodes as subjects.
[0063] In a preferred embodiment, the method 300 may further include updating an access control list in response to assigning an identity ID and an access ID to the second user, wherein the identity ID and the access ID of the second user are added to the access control list.
[0064] In a preferred embodiment, the method 300 may further include synchronizing the access control list to at least one IoT device in the Matter network.
[0065] The method implemented by the IoT service in the Matter network may include additional implementations, such as any single implementation or any combination of implementations described below and / or in combination with one or more other steps described elsewhere herein.
[0066] Figure 4 is a flow chart of another example method 400. In some embodiments, Figure 4 One or more process blocks can be executed by IoT services in the Matter Network.
[0067] The method 400 may include: in response to receiving a second certificate signing request from a third client logged in by a second user: generating a second certificate, wherein the second certificate may include an identity ID and an access ID of the second user, and the second certificate is signed by the IoT service using a private key generated by the IoT service ( Figure 4 402 in block); and sending a second certificate to a third client; wherein the second certificate signing request may include a public key generated on the third client ( Figure 4 404 in FIG.
[0068] In a preferred embodiment, the first client and at least an IoT device in the Matter network share a security domain, and the method further comprises: adding the third client to the security domain based on the second certificate.
[0069] The steps in method 400 may be repeated for more terminals logged in by the second user, so that the corresponding terminals can join the Matter network, and the corresponding terminals are granted access rights according to the permissions of the second user.
[0070] although Figure 3 and Figure 4 Example blocks of methods 300 and 400 are shown, but in some embodiments, methods 300 and 400 may include more Figure 3 and Figure 4 Additional blocks, fewer blocks, different blocks, or differently arranged blocks may be depicted in the method 300 or the method 400. Additionally or alternatively, two or more of the blocks of the method 300 and the method 400 may be executed in parallel.
[0071] Remove shared users
[0072] The method implemented by the IoT service in the Matter network also includes, in response to receiving a request to remove a second user from a user with an administrator access level in the Matter network: removing the identity ID and management access ID of the second user from the access control list; and synchronizing the updated access control list to at least one IoT device in the Matter network.
[0073] For example, when the IoT service receives a request from the Matter network to remove a second user, the IoT service will indicate any certificates that were issued to the second user and update the identity database accordingly. The removed second user will receive a notification that the certificate is no longer valid and should not be used for any further interactions. The second user is now excluded from the Matter network and cannot access IoT devices in the network. As a result, the access control lists on IoT devices in the Matter network will be updated accordingly, ensuring that even if the second user attempts to access the device with their old credentials, the device will deny the access request due to the updated ACLs.
[0074] Asynchronous processing
[0075] As mentioned above, the access control mechanism for devices in the Matter network is managed by ACLs, and ACLs are stored on IoT devices and clients, as well as on the IoT service that manages the Matter network. The ACLs on IoT devices and clients should be synchronized with the ACLs on the IoT service so that they have the same view of the access control state. However, sometimes an IoT device or client may go offline due to network issues, power outages, or other reasons. When this happens, the ACL on the offline device may not be updated with the latest changes made by other users or devices in the Matter network. This situation is called out-of-sync and can cause problems when the offline device comes back online.
[0076] To address this issue, the present disclosure provides a mechanism for detecting and resolving desynchronization in a Matter network.
[0077] The IoT service tracks changes to the ACL by, for example, tracking the version number of the ACL on devices and clients.
[0078] User data synchronization:
[0079] User data includes a list of certificates associated with the user. Users logged into the client can obtain new certificates when they are added to a new Matter network, lose certificates when they are removed from a Matter network they joined, or update certificates when their ACL CATID changes. Such changes to users need to be communicated to all users in the Matter network.
[0080] For users who can directly receive notifications, the IoT service will send a notification to update the user's data. When the user receives this notification, it will refresh its status and obtain a new certificate from the IoT system.
[0081] For users who cannot directly receive notifications, they need to subscribe to specific notifications using relevant transport layer protocols (such as MQTT) so that they can receive such notifications from the IoT service. When the user receives such a notification, it will refresh its status and obtain a new certificate from the IoT system.
[0082] In another preferred embodiment, the IoT service can store a list of pending updates for users, so that any user with access to the Matter network can retrieve this list and apply updates as needed.
[0083] Device data synchronization:
[0084] Device data includes ACLs. ACLs can be changed while the device is offline. This can include adding or removing ACLs, updating ACLs to add more subjects, targets, or simply changing the CAT ID version number.
[0085] The IoT service maintains a list of devices that need to have their ACL configuration updated. This list is available to any administrator device in the Matter network. The list can also be stored locally on any administrator device.
[0086] The administrator device uses mDNS / DNS-SD to find connected devices in the Matter network. When a device of interest is detected, the administrator device can send necessary updates to the device.
[0087] When multiple administrator devices on the network attempt to update the same device of interest simultaneously, conflicts or errors may result. To prevent this, each device in a Matter network has a cluster data version, a number that indicates the latest state of its ACL configuration. The cluster data version is a mechanism that helps synchronize data between devices in a Matter network. The Matter specification defines it as a 32-bit unsigned integer that increments each time a property in the cluster changes its value. Before sending any updates, the administrator device must compare the cluster data version on the device of interest with the cluster data version on the IoT service. If the cluster data version on the device is lower than the cluster data version on the IoT service, the device's ACL configuration is outdated and requires an update. If the cluster data version on the device is equal to or higher than the cluster data version on the IoT service, the device has the latest ACL configuration and no update is required. To prevent conflicts caused by concurrent updates from different administrators, in a preferred embodiment, administrators should only update the ACL on a device if the cluster data version on the device matches the version number recorded by the administrator. Otherwise, the administrator should retrieve the latest changes from the device before updating the ACL. For example, a higher version of cluster data on a device means that another administrator has made changes, so the current administrator should obtain those changes first to avoid conflicts. By using this method, the administrator device can avoid updating devices that are already synchronized or have newer changes.
[0088] Figure 5 is a flow chart of an example method 500. In some embodiments, Figure 5 One or more process blocks may be performed by a second user in the Matter network.
[0089] like Figure 5 As shown, method 500 may include a second user logging into a second client, wherein the second client communicates with a first client logged into by a first user (block 502).
[0090] like Figure 5 As shown, method 100 may include sending a first certificate signing request from the second client to the IoT service in the Matter network in response to receiving a sharing notification from the IoT service, wherein the first certificate signing request may include a public key generated on the second client, wherein the sharing notification is sent by the IoT service in response to the IoT service receiving the sharing request from the first client (block 504).
[0091] like Figure 5As further shown, method 500 may include receiving a first credential from the IoT service, wherein the first credential may include an identity ID assigned by the IoT service and an access ID associated with a specified access level of the second user, wherein the specified access level is defined by the first user in the sharing request (block 506).
[0092] Also like Figure 5 As shown, method 500 may include accessing at least one IoT device in the Matter network according to a specified access level of the second user (block 508 ).
[0093] The method implemented by the second user may include additional embodiments, such as any single embodiment or any combination of embodiments described below and / or in combination with one or more other processes described elsewhere herein.
[0094] In a preferred embodiment, in response to the assigned access level being the administrator level, the assigned access ID is the management access ID; and in response to the assigned access level being the operator level, the assigned access ID is the operation access ID.
[0095] In another preferred embodiment, alone or in combination with the above embodiments, Figure 6 As shown, the method 600 implemented by the second user also includes: logging in to a third client, wherein the third client communicates with the IoT service (block 602); sending a second certificate signing request from the third client to the IoT service, wherein the second certificate signing request may include a public key generated on the third client (block 604); receiving a second certificate from the IoT service, wherein the second certificate may include an identity ID and an access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service (block 606); and accessing at least one IoT device in the Matter network according to a specified access level of the second user (block 608).
[0096] although Figure 5 and Figure 6 Example blocks of methods 500 and 600 are shown, but in some implementations, methods 500 and 600 may include more Figure 5 and Figure 6 Additional blocks, fewer blocks, different blocks, or differently arranged blocks may be depicted in the method 500 or the method 600. Additionally or alternatively, two or more of the blocks of the method 500 and the method 600 may be executed in parallel.
[0097] As another embodiment, the present disclosure provides a system including an IoT service, a first client, a second client, and at least one IoT device in a Matter network.
[0098] The IoT service is configured to: receive a sharing request from a first client logged in by a first user in a Matter network, wherein the sharing request includes an identifier of a second user and a specified access level of the second user, and wherein the second user is logged in to a second client; and send a sharing notification to the second client.
[0099] The second client is configured to send a first certificate signing request to the IoT service, wherein the first certificate signing request includes a public key generated on the second client.
[0100] The IoT service is also configured to: assign an identity ID to the second user; generate a first certificate, wherein the first certificate includes the identity ID of the second user and the assigned access ID associated with the specified access level, and the first certificate is signed by the IoT service using a private key generated on the IoT service; and send the first certificate to the second client.
[0101] The second client is further configured to access at least one IoT device in the Matter network according to a specified access level of the second user.
[0102] In a preferred embodiment, the system further includes a third terminal for the second user to log in.
[0103] The third client is configured to send a second certificate signing request to the IoT service, where the second certificate signing request includes a public key generated on the third client.
[0104] The IoT service is configured to: generate a second certificate, wherein the second certificate includes the identity ID and access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and send the second certificate to the third client.
[0105] Example Implementations
[0106] Figure 7 An example of an embodiment according to the present disclosure is shown. Figure 7 As shown, a first user, a second user, an IoT service, and an IoT device are provided, wherein the first user logs in to a first client, and the second user logs in to a second client. The first client, the IoT service, and the IoT device are in a Matter network.
[0107] To share control of an IoT device in the Matter network with a second user, the first user may send a sharing request from the first client to the IoT service. The sharing request includes the identification of the second user and the second user's designated access level. For example, the identification of the second user may be the second user's username. The designated access level may be "Administrator" or "Operator" as determined by the first user. In some cases, the first user may send the sharing request via a user interface ("UI") in the first client.
[0108] The IoT service is configured to send a sharing notification to the second client after receiving the sharing request from the first user.
[0109] If the second user on the second client accepts the sharing request, a public and private key pair is generated on the second client. The second user also sends a first certificate signing request to the IoT service to proceed with the next steps to join the Matter network and gain access to IoT devices in the network. The first certificate signing request includes the public key generated on the second client, which will be used by the IoT service later when sending the first certificate back to the second client.
[0110] The IoT service is further configured to assign an identity ID to the second user. This step may be performed before or after receiving the first certificate signing request from the second user.
[0111] The IoT service will generate a first certificate, wherein the first certificate includes the second user's assigned identity ID and an assigned access ID associated with the specified access level, and the first certificate is signed by the IoT service using a private key generated by the IoT service. If the second user's access level is assigned to the "Administrator" level, the assigned access ID is an administrative access ID; if the second user's access level is assigned to the "Operator" level, the assigned access ID is an operational access ID.
[0112] The IoT service will send the first certificate to the second client. Preferably, the first certificate can be encrypted with a public key received from the second client, and the second client can decrypt the first certificate with a private key stored locally on the second client.
[0113] The second user on the second client can access IoT devices in the Matter network according to the second user's specified access level. The IoT device allows specific access based on the second user's access ID, such as read-only, read-write, and management.
[0114] According to the present disclosure, a user can log in to multiple clients simultaneously, and an identity ID is assigned to the user within the Matter network. However, the user will generate a unique key pair for each client they log in to. For example, if a user is logged in to an Android application, an iOS application, and a smart speaker controller at the same time, the user will have three unique key pairs for each of these three clients. The user will also obtain different certificates on each of these clients, each with the user's identity ID embedded in it.
[0115] Figure 7 An example is further shown in which a second user logs into a third client.
[0116] The third client sends a second certificate signing request to the IoT service, where the second certificate signing request includes a public key generated on the third client. In some embodiments, the third client makes this request when the first user notifies the third client of their sharing intent. For example, the first user may wish to share with the third client by sending a sharing notification, and upon receiving this notification, the third client will send the second certificate signing request to the IoT service.
[0117] In response to receiving a second certificate signing request from the third client, the IoT service generates a second certificate. The second certificate includes the second user's identity ID and access ID. The IoT service signs the second certificate using a private key generated on the IoT service, and sends the second certificate to the third client. The second certificate enables the third client to access IoT devices in the Matter network according to the second user's specified access level.
[0118] Additionally, by using ACLs, the Matter network can allow users to customize smart home settings based on their preferences and needs, such as creating scenes, schedules, or automations.
[0119] This disclosure is designed to provide a seamless and secure user experience for smart home users, where new users can be added to an existing Matter network and granted access and control of devices. By using this disclosure, administrative users can easily add new users to the Matter network, enabling different users to control and configure IoT devices.
[0120] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the embodiments to the precise forms disclosed. Modifications may be made in light of the foregoing disclosure or may arise from practice of the embodiments. As used herein, the term "component" is intended to be broadly interpreted as meaning hardware, firmware, or a combination of hardware and software. It is apparent that the systems and / or methods described herein may be implemented in various forms of hardware, firmware, and / or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods does not limit these embodiments. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code—it should be understood that both software and hardware may be used to implement the systems and / or methods described herein. As used herein, depending on the context, satisfying a threshold may refer to a value greater than a threshold, greater than or equal to a threshold, less than a threshold, less than or equal to a threshold, equal to a threshold, and so forth, depending on the context. Although specific combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of the various embodiments. In fact, many of these features may be combined in ways not specifically recited in the claims and / or disclosed in the specification.
[0121] Although each dependent claim listed below may be directly subordinate to only one claim, the disclosure of various embodiments includes the combination of each dependent claim with each other claim in the claim set. Unless explicitly described as such, any element, action or instruction used herein should not be understood as critical or essential. In addition, as used herein, the articles "a" and "an" are intended to include one or more items and can be used interchangeably with "one or more". In addition, as used herein, the article "the" is intended to include one or more items cited in conjunction with the article "the" and can be used interchangeably with "one or more". In addition, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, a combination of related items and unrelated items, etc.) and can be used interchangeably with "one or more". In the case of only one item, the phrase "only one" or similar language is used. In addition, as used herein, the terms "has", "have", "having" etc. are intended to be open terms. Furthermore, unless expressly stated otherwise, the phrase "based on" is intended to mean "based, at least in part, on." Furthermore, as used herein, the term "or" when used enumerably is intended to be inclusive and can be used interchangeably with "and / or" unless expressly stated otherwise (e.g., if used in combination with "either" or "only one of").
[0122] It should be understood that the methods and systems in the above-mentioned Matter network are provided as examples only and are not limitations of the present disclosure. Those skilled in the art should understand that the principles of the present disclosure can be applied to systems and methods other than shared control in the above-mentioned Matter network without departing from the scope of the present disclosure. Although various embodiments of various aspects of the present disclosure have been described for the purposes of the present disclosure, it should not be understood that the teachings of the present disclosure are limited to these embodiments. Therefore, the features disclosed in a particular embodiment are not limited to that embodiment, but can be combined with the features disclosed in different embodiments. For example, one or more features and / or operations of the method according to the present disclosure described in one embodiment may also be applied individually, in combination, or as a whole in another embodiment. The description of the system / device embodiment also applies to the method embodiment, and vice versa. Those skilled in the art will understand that more optional embodiments and variations are possible without departing from the scope defined by the claims of the present disclosure, and various changes and modifications may be made to the above-mentioned system.
Claims
1. A method implemented by an IoT service in a Matter network, comprising: Receiving a sharing request from a first client logged in by a first user in the Matter network, wherein the sharing request includes an identifier of a second user and a specified access level of the second user, and wherein the second user is logged in by a second client; Sending a sharing notification to the second client; assigning an identity ID to the second user; generating a first certificate in response to receiving a first certificate signing request from the second client, wherein the first certificate signing request includes a public key generated on the second client, wherein the first certificate includes the identity ID of the second user and an assigned access ID associated with the specified access level; and The first certificate is sent to the second client, wherein the first certificate enables the second client to access at least one IoT device in the Matter network according to the second user's specified access level.
2. The method according to claim 1, further comprising: In response to assigning the identity ID and the access ID to the second user, an access control list is updated, wherein the identity ID and the access ID of the second user are added to the access control list.
3. The method according to claim 1, further comprising: The access control list is synchronized to at least one IoT device in the Matter network.
4. The method according to claim 1, wherein The first certificate is signed by the IoT service using a private key generated by the IoT service.
5. The method according to claim 1, wherein In response to the assigned access level being the administrator level, the assigned access ID is an administrative access ID; In response to the assigned access level being the operator level, the assigned access ID is an operation access ID.
6. The method according to claim 1, further comprising, in response to receiving a second certificate signing request from a third client logged in by the second user: generating a second certificate, wherein the second certificate includes the identity ID and access ID of the second user, and the second certificate is signed by the IoT service using a private key generated by the IoT service; and Sending the second certificate to the third client; The second certificate signing request includes a public key generated on the third client.
7. The method of claim 1 , further comprising, in response to receiving a request to remove the second user from a user with administrator access level in the Matter network: removing the identity ID and management access ID of the second user from the access control list; The updated access control list is synchronized to at least one IoT device in the Matter network.
8. The method according to claim 1, wherein The first user is provided with an administrator access level in the Matter level.
9. The method according to claim 1, wherein: The IoT service, the first client, and at least one IoT device in the Matter network share a security domain, and the method further includes: The second client is added to the security domain based on the first certificate.
10. The method according to claim 6, wherein: The IoT service, the first client, and at least one IoT device in the Matter network share a security domain, and the method further includes: The third client is added to the security domain based on the second certificate.
11. A method implemented by a second user in a Matter network, comprising: A second user logs in to a second client, wherein the second client communicates with a first client logged in by the first user; sending a first certificate signing request from the second client to an IoT service in a Matter network in response to receiving a sharing notification from the IoT service, wherein the first certificate signing request includes a public key generated on the second client, wherein the sharing notification is sent by the IoT service in response to the IoT service receiving the sharing request from the first client; receiving a first credential from the IoT service, wherein the first credential includes an identity ID assigned by the IoT service and an access ID associated with a specified access level of the second user, wherein the specified access level is defined by the first user in the sharing request; and Access at least one IoT device in the Matter network according to the second user's specified access level.
12. The method according to claim 11, wherein In response to the assigned access level being the administrator level, the assigned access ID is an administrative access ID; In response to the assigned access level being the operator level, the assigned access ID is an operation access ID.
13. The method according to claim 11, further comprising: Logging in to a third client, wherein the third client communicates with the IoT service; Sending a second certificate signing request from the third client to the IoT service, wherein the second certificate signing request includes a public key generated on the third client; receiving a second certificate from the IoT service, wherein the second certificate includes the identity ID and access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and Access at least one IoT device in the Matter network according to the second user's specified access level.
14. A system comprising an IoT service, a first client, a second client, and at least one IoT device in a Matter network, wherein: The IoT service is configured to: Receiving a sharing request from a first client logged in by a first user in the Matter network, wherein the sharing request includes an identifier of a second user and a specified access level of the second user, and wherein the second user is logged in to the second client; and Sending a sharing notification to the second client; The second client is configured as follows: Sending a first certificate signing request to the IoT service, wherein the first certificate signing request includes a public key generated on the second client; The IoT service is further configured to: assigning an identity ID to the second user; generating a first certificate, wherein the first certificate includes the identity ID of the second user and the assigned access ID associated with the specified access level, and the first certificate is signed by the IoT service using a private key generated on the IoT service; and Sending the first certificate to the second client; The second client is further configured to: Access at least one IoT device in the Matter network according to the second user's specified access level.
15. The system according to claim 14, further comprising a third terminal for the second user to log in, wherein: The third client is configured as follows: Sending a second certificate signing request to the IoT service, wherein the second certificate signing request includes a public key generated on the third client; and The IoT service is configured to: generating a second certificate, wherein the second certificate includes the identity ID and access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and The second certificate is sent to the third client.
16. A non-transitory computer storage medium storing a computer program which, when executed by a processor, causes the processor to perform the method according to any one of claims 1 to 10.
17. A non-transitory computer storage medium storing a computer program which, when executed by a processor, causes the processor to perform the method according to any one of claims 11 to 13.
Citation Information
Patent Citations
Distributed control method for information of accessing internet of things by user
CN102404726A
Resource sharing method, server and storage medium
CN111275510A
Method and system for determining local access control authority of Matter equipment
CN115714672A
Shared device control method, device, client, server and storage medium
CN117675246A
Management method and system for sharing WLAN and WLAN sharing registration server
WO2016090927A1