Method implemented by IoT service in matter network
The IoT service in the Matter network addresses interoperability and security issues by generating certificates with identity IDs and access levels, enabling secure and flexible sharing and management of IoT devices across users and platforms.
Patent Information
- Application Number
- PCT/CN2025/073021
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-17
- Publication Date
- 2025-07-24
AI Technical Summary
Existing IoT devices face challenges in seamless interoperability and compatibility across different manufacturers and platforms, lacking user-friendly methods for sharing control and management, and insufficient security and privacy in IoT ecosystems.
A method implemented by an IoT service in the Matter network for sharing control of IoT devices, using the PKI infrastructure to generate certificates with identity IDs and access levels, enabling secure and reliable communication across users and devices.
Facilitates easy and secure sharing of IoT device control among users, allowing decentralized data sharing without central authorities, and supports multi-terminal access and remote management, enhancing user convenience and flexibility.
Smart Images

Figure CN2025073021_24072025_PF_FP_ABST
Abstract
Description
METHOD IMPLEMENTED BY IOT SERVICE IN MATTER NETWORKFIELD OF THE INVENTION
[0001] The present invention relates generally to the field of IoT network, and in particular, relates to a method implemented by an IoT service in the Matter network.BACKGROUND
[0002] The term IoT (or Internet of Things) refers to a network of collections of interconnected devices (such as sensors, actuators, appliances, and other smart objects) , and the technology that facilitates communication between devices and the cloud, as well as between the devices themselves. Thanks to the advent of affordable computer chips and high-bandwidth telecommunications, there are now billions of devices connected to the Internet. IoT devices can provide various services and functionalities for users, such as home automation, security, energy management, health monitoring, and entertainment. However, IoT devices also face challenges in terms of compatibility, security, reliability, and usability.
[0003] One of the challenges is to ensure that IoT devices from different manufacturers and platforms can work together seamlessly and interoperably. Currently, there are multiple proprietary implementations of IoT ecosystems that allow users to control, operate and share IoT devices. However, these implementations may not be compatible with each other, and may require users to install multiple apps or hubs to manage their devices. Moreover, these implementations may not provide sufficient security and privacy for the users and their data.
[0004] To address this challenge, a new standard for smart home technology called Matter has been launched by the Connectivity Standards Alliance (CSA) . Matter is an open-source connectivity standard that aims to improve the compatibility and security of IoT devices. Matter protocol is based on Internet Protocol (IP) and works through one or several compatible border routers, avoiding the use of multiple proprietary hubs. Matter devices run locally and do not rely on an internet connection, although the standard is designed to talk to the cloud easily.
[0005] Users of IoT devices may want to add devices to a home or rooms, share them with other users, and control them locally or remotely. Users may also want to have access to various features and services provided by their devices, such as voice control, automation rules, scenes, notifications, and analytics. However, these features and services may vary depending on the device manufacturer or platform, and may not be consistent or compatible across different devices.
[0006] The advancement of the Matter standard opens up verticals for new solutions that leverage the PKI infrastructure of the Matter standard to provide these services. However, it remains unaddressed how to enable users to easily share control of IoT devices between various users in a user-friendly way, such that other users can also set up, configure, and manage the IoT devices.SUMMARY
[0007] In order to overcome the defects in the existing art, the present invention provides a novel way of implementing a method by an IoT service in the Matter network to facilitate sharing control of IoT devices for various users. The method allows users to create and manage IoT devices in a unified and intuitive way, where the PKI (Public Key Infrastructure) architecture of Matter is leveraged to provide secure and reliable communication during the sharing process between devices and users. The IoT ecosystem created according to the present disclosure allows a user to share access to devices in a home or across rooms with another user, so as to control them locally or remotely. The IoT system may be hosted in the cloud, or any machine such as a server with sufficient connectivity. According to the present disclosure, it enables seamless access and control over IoT devices for any assigned new users.
[0008] In one general aspect of the present disclosure, a method implemented by an IoT service in a Matter network is provided. The method may include receiving a sharing request from a first client terminal in the Matter network on which a first user is logged, where the sharing request may include an identification of a second user and a designated access level for the second user, and where the second user is logged on a second client terminal. The method may also include sending a sharing notification to the second client terminal and may furthermore include assigning an identity ID for the second user. Method may in addition include generating a first certificate in response to receiving a first certificate signing request from the second client terminal, where the first certificate signing request may include a public key generated on the second client terminal along with a signature created using a private key corresponding to the public key which is also generated on the second client terminal, where the first certificate may include the identity ID for the second user and an assigned access ID in association with the designated access level. The method may moreover include sending the first certificate to the second client terminal, where the first certificate enables the second client terminal to access at least one IoT device in the Matter network according to the designated access level for the second user. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.
[0009] Implementations may further include one or more of the following features.
[0010] Preferably, the method may include, in response to assigning the identity ID and the access ID for the second user, updating an Access Control List, where the identity ID and the access ID of the second user are added to the Access Control List.
[0011] Preferably, the method may include the first certificate being signed by the IoT service with a private key generated on the IoT service.
[0012] Preferably, the method may include synchronizing the Access Control List to the at least one IoT device in the Matter network.
[0013] Preferably, the method may include the assigned access ID being an admin access ID in response to the assigned access level being an administrator level; and the assigned access ID being an operate access ID in response to the assigned access level being an operator level.
[0014] Preferably, in response to receiving a second certificate signing request from a third client terminal on which the second user is logged, the method may include: generating a second certificate, where the second certificate may include the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and sending the second certificate to the third client terminal; where the second certificate signing request may include a public key generated on the third client terminal.
[0015] Preferably, the method may include the IoT service, the first client terminal, and at least IoT device in the Matter network sharing a security domain, and the method may include: adding the second client terminal to the security domain based on the first certificate; and adding the third client terminal to the security domain based on the second certificate.
[0016] Preferably, the method may include, in response to receiving, from an user with an administrator access level in the Matter network, a request to remove the second user: removing the identity ID and the admin access ID of the second user from the Access Control List; and synchronizing the updated Access Control List to at least one IoT device in the Matter network.
[0017] Preferably, the method may further include where the first user is provided with an administrator access level in the Matter level.
[0018] In another general aspect of the present disclosure, a method implemented by a second user in a Matter network is provided. The method may include the second user logging on a second client terminal, where the second client terminal is in communication with a first client terminal on which a first user is logged. The method may also include sending a first certificate signing request from the second client terminal to an IoT service in the Matter network in response to receiving a sharing notification from the IoT service, where the first certificate signing request may include a public key generated on the second client terminal, where the sharing notification is sent by the IoT service in response to the IoT service receiving a sharing request from the first client terminal. The method may furthermore include receiving a first certificate from the IoT service, where the first certificate may include an identity ID assigned by the IoT service and an access ID in association with a designated access level for the second user, where the designated access level is defined in the sharing request by the first user. The method may in addition include accessing at least one IoT device in the Matter network according to the designated access level for the second user. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.
[0019] In yet another general aspect, a system including an IoT service, a first client terminal, a second client terminal and at least one IoT device in a Matter network is provided. The system may include the IoT service being configured to: receive a sharing request from a first client terminal in the Matter network on which a first user is logged, where the sharing request may include an identification of a second user and a designated access level for the second user, and where the second user is logged on the second client terminal; and send a sharing notification to the second client terminal. The system may also include the second client terminal being configured to: send a first certificate signing request to the IoT service, where the first certificate signing request may include a public key generated on the second client terminal. The system may furthermore include the IoT service being further configured to: assign an identity ID for the second user; generate a first certificate, where the first certificate may include the identity ID for the second user and an assigned access ID in association with the designated access level, and the first certificate is signed by the IoT service with a private key generated on the IoT service; and send the first certificate to the second client terminal. The system may in addition include the second client terminal being further configured to: access at least one IoT device in the Matter network according to the designated access level of the second user. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.
[0020] Preferably, the system may further include a third terminal on which the second user is logged, where the third client terminal is configured to: send a second certificate signing request to the IoT service, wherein the second certificate signing request includes a public key generated on the third client terminal; and, the IoT service is configured to: generate a second certificate, wherein the second certificate includes the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and send the second certificate to the third client terminal.
[0021] In a further general aspect of the present disclosure, a non-transient computer storage medium storing a computer program is provided, where the computer program when being executed by a processor causes the processor to perform the actions of the methods. Other embodiments of this aspect include corresponding computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods.
[0022] The present disclosure simplifies the setup and management of smart home devices for users by providing a method to easily sharing control over IoT devices in a Matter network to new users, and thus allowing user to deploy Matter ecosystem as desired. Through introducing a new user by an authenticated user in the Matter network, the process of access granting for the new user is simplified. This mechanism allows for decentralized and secure data sharing without relying on a central authority or intermediary. In addition, the out of sync detection of ACLs is applied in the present disclosure to ensure that the ACLs are synchronized and valid across the network. Furthermore, a revocation mechanism is provided, which ensures that revoked user will not be able to access the IoT devices anymore. Another benefit of the present disclosure is the enablement of multi-terminal access. The users can login and access the IoT devices from various terminals (for example, phones, tablets, laptops, etc. ) . This enables the use of ‘hubs’ (such as Google Home, Amazon Alex etc. ) within the premises, which function similarly to a phone-app, thereby providing control over the IoT devices. This also allows the users to remotely monitor and manage the IoT devices from different locations and devices, enhancing the convenience and flexibility of the smart home system.BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In the following, the present disclosure will be further explained on the basis of embodiments with reference to the attached drawings.
[0024] Fig. 1 schematically illustrates a diagram of a Matter network.
[0025] Fig. 2 schematically illustrates a Matter network 1 and a Matter network 2, where a client terminal and an IoT device A are commissioned to both Matter networks respectively.
[0026] Fig. 3 schematically illustrates a flowchart of a specific implementation of a method 300 provided by the present disclosure.
[0027] Fig. 4 schematically illustrates a flowchart of another specific implementation of method 400 provided by the present disclosure.
[0028] Fig. 5 schematically illustrates a flowchart of another specific implementation of method 500 provided by the present disclosure.
[0029] Fig. 6 schematically illustrates a flowchart of another specific implementation of method 600 provided by the present disclosure.
[0030] Fig. 7 schematically illustrates an example of embodiment according to the present disclosure.DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0031] The method implemented in a Matter network and a system therefor according to the present disclosure will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments shown in the accompanying drawings and described hereinafter are merely illustrative and not intended to limit the disclosure. In addition, it should be understood that in this disclosure, ordinal words such as "first" , "second" , "third" , etc., unless explicitly specified or determined by the technical context, are used only to indicate different or identical elements in the technical solution, and do not imply any limitation on the order or importance of those elements.
[0032] Matter is a new smart home standard that aims to enable interoperability and compatibility among different brands and ecosystems of smart devices. Fig. 1 illustrates a Matter network, also called Matter Fabric, which comprises a set of IoT devices that share a same security domain and can communicate with each other securely, as well as a client terminal which is a device that can access, control and / or monitor IoT devices and services based on the authentication and authorization level of the user that is logged into the client terminal. Typically, an IoT device can be a headless physical device that has connectivity and can provide services. For instance, IoT devices can be either end devices, such as lights, sensors, or cameras, or routers, such as hubs, bridges, or access points, that relay messages between end devices. Examples of a client terminal include smartphones, tablets, laptops, and smart speakers. A client terminal can also use various applications, such as Matter app, Alexa app, Google Home app, and Apple Home app, to interact with Matter devices and services using a user account.
[0033] Each Matter network includes an IoT service that acts as a Root level CA, which generates a unique pair of private key and public key, where the private key of the Root level CA is securely stored in the cloud. An IoT service can be implemented in a cloud-based platform or can be implemented on a local server.
[0034] An IoT device sends a request to the IoT service to request a node operational certificate (NOC) , which will allow it to authenticate as a trusted device within the Matter network. After the IoT device being commissioned by an IoT service with a Node ID and network configuration information, such as security credentials, it can use the network configuration information to make a connection to the Matter network.
[0035] A user in a Matter network is a logical entity that can control IoT devices depending on the access level of the user. For example, a user in a Matter network may be a human user or a non-human user, such as a hub, which acts on behalf of or in coordination with a human user.
[0036] Account information of users is usually stored in an identity database and use separate credentials, for example username and password, to authenticate themselves with the IoT cloud.
[0037] By default, there are three levels of access to the home defined for a user:
[0038] ·Administrator: A user with this access level has full access to all administrative functions of the Matter network and the IoT devices, such as adding, removing, or setting up devices.
[0039] ·Operator: A user with this access level can only operate devices, not administrative tasks, in the Matter network, such as turning on, off, or adjusting devices.
[0040] ·None: A user with this access level has no access to the whole Matter network. Instead, the user can only access certain devices as set by the IoT service.
[0041] A user may simultaneously manifest on multiple client terminals. For instance, as depicted in Fig. 1, a user is signed into a mobile phone application (Client terminal 1) , and also logged into a controller device (Client terminal 2) without a screen in the Matter network. The user signed on to the mobile phone application and the user signed on the controller device have the same capabilities to control IoT devices.
[0042] The Matter standard uses access control lists (ACLs) to manage the permissions of different devices and users. The ACL is a set of rules that define the subjects (who) , the targets (what) , and the permissions (how) of the access control.
[0043] Each IoT device that is commissioned in a Matter network will retain two Access Control Lists that determine which users are allowed to take actions on the IoT device. One ACL grants administrator access to users who have an admin access ID in the settings, and another ACL grants operator access to users who have an operate access ID in the settings. In some cases, the access ID is also known as CAT ID, which stands for CASE Authenticated Tag. The access ID allows for a group-based permission mechanism that assigns the same access level to multiple users who share the same CAT ID. An IoT device can check the CAT ID in the user’s certificate to determine whether to grant or deny the user’s access request.
[0044] The IoT service stores a copy of all the ACLs for each IoT device in the Matter network. The IoT service also keeps track of the sync status of the ACLs on any IoT device. For example, the IoT service will know if an IoT device has not updated its ACLs after the ACLs have been updated to the IoT service, but not yet updated on the corresponding IoT device. In this manner, the IoT service can detect and flush updates of any changes on the ACLs that occur when an IoT device is offline to the corresponding IoT device.
[0045] One of the features of Matter is that it allows IoT devices to be commissioned to multiple Matter fabrics. This means that a device can be controlled by different ecosystems, such as Amazon Alexa, Google Home, or Apple HomeKit, without having to switch between them. For example, a light bulb can be connected to Alexa, Google Home, and HomeKit at the same time, and respond to commands from any of them. This gives consumers more flexibility and choice when adding new products or brands to their smart home. A significant advantage of the present disclosure is to enable the creation of a new ecosystem by leveraging this feature of Matter, thus providing a unified and interoperable platform for smart home devices.
[0046] To achieve this, Matter uses Internet Protocol (IP) as the common language for all devices, regardless of the underlying network protocol they use. Matter supports Wi-Fi, Ethernet, and Thread as the network protocols for devices to join a Matter fabric.
[0047] The multi-admin feature of the Matter standard allows consumers to enjoy the benefits of interoperability, security, and reliability across different ecosystems and technologies. Fig. 2 illustrates a Matter network 1 and a Matter network 2, where a client terminal and an IoT device A are commissioned to both Matter networks respectively. The IoT device A is assigned with a unique Node ID in the Matter network 1 and another unique Node ID in the Matter network 2. The IoT device A can be controlled by User 1 logged on a client terminal within the Matter network 1, and it can also be controlled by User 2 logged on another client terminal in the Matter network 2.
[0048] Matter specification is a connectivity standard that allows users to configure and operate IoT devices in a Matter network. However, it does not specify how to build an ecosystem on top of this, that allows multiple users, sharing, creation of groups for IoT devices, etc. This is left for ecosystem developers to implement. Therefore, there is a problem of how to add a new user to a Matter network and assign certain access level across the network for the newly added user. In existing arts, if a new user wants to join a Matter network, it can only be done for each device in the Matter network separately if the new user is not already part of the Matter Fabric. For example, in this case, to allow a new user to administer a device, the current user with an administrator access to the device has to re-open the commissioning window of the device. The device would then provide a new commissioning password (for instance, encoded in a new QR-code) to the new user and go through the whole commissioning process for the new user. If the new user is already part of the Matter Fabric, for example the new user has local network awareness, then the access control lists (ACLs) on the IoT devices can be simply updated to allow this user to access the IoT devices. In such a scenario, commissioning window need not be opened. However, the process to allow a new user to administer a device is difficult and time consuming because it has to be done for each device in the Matter network in order to add a new user to access all the devices.
[0049] In the present disclosure, a method implemented by an IoT service in a Matter network is provided to share access and control of IoT devices in the Matter network with a new user.
[0050] Access Sharing to A New User
[0051] Fig. 3 is a flowchart of an example method 300. In some implementations, one or more process blocks of Fig. 3 may be performed by an IoT service in the Matter network.
[0052] Fig. 3 further illustrates that method 300 may include receiving a sharing request from a first client terminal in the Matter network on which a first user is logged, where the sharing request may include an identification of a second user and a designated access level for the second user, and where the second user is logged on a second client terminal (block 302) .
[0053] For example, the identification of the second user may be account information usually stored in an identity database in the Matter network. The identification may be a username, an email address, a phone number, or other unique identifier that is registered with the Matter network. The designated access level may specify what kind of permissions the second user has to access and control the devices that are shared by the first user. For example, the access level may be “Administrator” or “Operator” or “None” as described above.
[0054] Fig. 3 further illustrates that method 300 may include sending a sharing notification to the second client terminal (block 304) . For example, the sharing notification may include the identification of the first user and the first client terminal that initiated the sharing. The sharing notification may further include the list of devices and the designated access level for the shared devices that are shared by the first user. The sharing notification may further include a confirmation code or link to accept or reject the sharing request.
[0055] Fig. 3 further illustrates that method 300 may include assigning an identity ID for the second user (block 306) . The identity ID is a unique identifier for a user in a Matter network, which does not change regardless of how many terminals the user logs on to within the same Matter network. However, if the user signs into another terminal in a different Matter network, the user will receive a different identity ID in that Matter network. In some embodiments, the UUID may be defined as within the range of 0x0000_0000_0000_0001 to 0xFFFF_FFEF_FFFF_FFFF.
[0056] Fig. 3 further illustrates that method 300 may include generating a first certificate in response to receiving a first certificate signing request from the second client terminal, where the first certificate signing request may include a public key generated on the second client terminal, where the first certificate may include the identity ID for the second user and an assigned access ID in association with the designated access level (block 308) .
[0057] For example, the second client terminal may receive a sharing notification according to block 304, and choose to accept or deny the received sharing notification. If the second client terminal accepts the sharing notification, the second terminal will send a first certificate singing request (CSR) to the IoT service. The first certificate signing request may include a public key generated by the second terminal, which will be used for signing the first certificate for the second terminal by the IoT service. The public key is part of a pair of keys that also includes a private key, which is generated and stored securely on the second terminal. The private key never leaves the second terminal and is used to decrypt data or messages that are encrypted with the public key by other parties. The public key, as its name implies, can be shared freely and is used to encrypt data or messages for the second terminal or verify its identity.
[0058] As further shown in Fig. 3, method 300 may include sending the first certificate to the second client terminal, where the first certificate enables the second client terminal to access at least one IoT device in the Matter network according to the designated access level for the second user (block 310) . For example, the first certificate is embedded with the assigned identity ID and the assigned access ID for the second user.
[0059] In a preferred implementation, the first certificate is signed by the IoT service with a private key generated by the IoT service.
[0060] In a preferred implementation, the first client terminal, and at least IoT device in the Matter network share a security domain, and the method further comprising: adding the second client terminal to the security domain based on the first certificate.
[0061] In a preferred implementation, the assigned access ID is an admin access ID in response to the assigned access level being an administrator level; and the assigned access ID is an operate access ID in response to the assigned access level being an operator level.
[0062] In a preferred implementation, the admin access ID and the operate access ID are admin CASE Authenticated Tags (CATs) , which are 32-bit values that are shared by the IoT service during CASE session establishment to the second terminal. These CATs act as group-like tags that can be applied to multiple Nodes (which are instances of Matter devices within a Matter fabric) in the Matter network, making it easier to manage Access Control Entries that use the same set of Nodes as subjects.
[0063] In a preferred implementation, method 300 may further include in response to assigning the identity ID and the access ID for the second user, updating an Access Control List, where the identity ID and the access ID of the second user are added to the Access Control List.
[0064] In a preferred implementation, method 300 may further include synchronizing the Access Control List to the at least one IoT device in the Matter network.
[0065] The method implemented by an IoT service in a Matter network may include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other steps described elsewhere herein.
[0066] Fig. 4 is a flowchart of another example method 400. In some implementations, one or more process blocks of Fig. 4 may be performed by an IoT service in the Matter network.
[0067] The method 400 may include, in response to receiving a second certificate signing request from a third client terminal on which the second user is logged: generating a second certificate, where the second certificate may include the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated by the IoT service (block 402 in Fig. 4) ; and sending the second certificate to the third client terminal; where the second certificate signing request may include a public key generated on the third client terminal (block 404 in Fig. 4) .
[0068] In a preferred implementation, the first client terminal, and at least IoT device in the Matter network share a security domain, and the method further comprising: adding the third client terminal to the security domain based on the second certificate.
[0069] The steps in the method 400 may be repeated for more terminals on which the second user is logged to enable the corresponding terminals to join the Matter network, and to grant access to the corresponding terminals according to the privileges of the second user.
[0070] Although Fig. 3 and Fig. 4 shows example blocks of method 300 and method 400, in some implementations, method 300 and method 400 may include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Fig. 3 and Fig. 4. Additionally, or alternatively, two or more of the blocks of method 300 and method 400 may be performed in parallel.
[0071] Removal of a shared user
[0072] The method implemented by the IoT service in a Matter network further include, in response to receiving, from a user with an administrator access level in the Matter network, a request to remove the second user: removing the identity ID and the admin access ID of the second user from the Access Control List; and synchronizing the updated Access Control List to the at least one IoT device in the Matter network.
[0073] For example, when the IoT service receives a request to remove the second user from the Matter network, the IoT service will indicate any certificates that were issued to the second user and updates the identity database accordingly. The second user that is removed will receive a notification which notifies that the certificates are no longer valid and should not be used for any further interactions. The second user is now excluded from the Matter network and cannot access the IoT devices in the network. As a result, the Access Control Lists on the IoT devices in the Matter network will be updated accordingly, thereby ensuring that even if the second user tries to access a device with its old certificate, the device will reject the access request as the ACLs have been updated.
[0074] Out of Sync Handling
[0075] As described above, the access control mechanism of devices in a Matter network is managed by ACLs, and the ACLs are stored both on the IoT devices and client terminals, and on the IoT service that manage the Matter network. The ACLs on the IoT devices and client terminals should be synchronized with the ACLs on the IoT service, so that they have the same view of the access control state. However, sometimes an IoT device or a client terminal may go offline due to network issues, power outage, or other reasons. When this happens, the ACLs on the offline device may not be updated with the latest changes made by other users or devices in the Matter network. This situation is called out-of-sync, and it can cause problems when the offline device comes back online.
[0076] To fix this problem, the present disclosure provides a mechanism to detect and resolve out-of-sync in a Matter network.
[0077] The IoT service keeps track of the changes in the ACLs, for example, by tracking the version number of the ACLs on the devices and the client terminal.
[0078] User data synchronization:
[0079] User data include a list of certificates that are associated with a user. A user logged on a client terminal may get new certificates when they are added to new Matter networks, or lose certificates when they are removed from joined Matter networks, or have the certificates updated when the ACL CAT IDs change. Such changes of a user need to be communicated to all users in the Matter network.
[0080] For a user that can receive notifications directly, the IoT service will send a notification to update the user data. When the user gets such notification, it will refresh its state and get the new certificates from the IoT system.
[0081] For a user that cannot receive notifications directly, it needs to subscribe to specific notifications using the relevant transport layer protocol (for example, MQTT) so that the user can get such notifications from the IoT service. When the user gets such notification, it will refresh its state and get the new certificates from the IoT system.
[0082] In another preferred implementation, the IoT service may store a list of pending updates for users. This way, any user who has access to the Matter network can fetch this list and apply the updates as needed.
[0083] Device data synchronization:
[0084] Device data include the ACLs. The ACLs may be changed during the period when the device is offline. This may include adding or deleting ACLs, or updating ACLs to add more subjects, targets, or just to change the version number of the CAT IDs.
[0085] The IoT service maintains a list of devices that need updates to their ACL configuration. The list can be fetched by any administrator device in the Matter network. The list can also be stored locally in any administrator device.
[0086] The administrator device looks for devices that come online in the Matter network using mDNS / DNS-SD. When a device of interest is detected, the administrator device may send the necessary updates to the device of interest.
[0087] When multiple administrator devices on the network try to update the same device of interest at the same time, they may cause conflicts or errors. To prevent this, each device in the Matter network has a cluster data version, which is a number that indicates the latest state of its ACL configuration. A cluster data version is a mechanism that helps synchronize the data among different devices in a Matter network. It is defined by the Matter specification as a 32-bit unsigned integer that increments whenever an attribute within a cluster changes its value. An administrator device needs to compare the cluster data version on the device of interest with the cluster data version on the IoT service before sending any updates. If the cluster data version on the device is lower than the cluster data version on the IoT service, it means that the device has an outdated ACL configuration and needs to be updated. If the cluster data version on the device is equal to or higher than the cluster data version on the IoT service, it means that the device has an up-to-date ACL configuration and does not need to be updated. To prevent conflicts from concurrent updates by different administrators, in a preferrable embodiment, an administrator should only update an ACL on the device when the cluster data version on the device is the same as the version number recorded by the administrator. Otherwise, the administrator should fetch the latest changes from the device before updating the ACL. For instance, a higher cluster data version on the device means that another administrator has made changes, and hence the current administrator should first fetch those changes, so as not to have a conflict. By using this method, administrator devices can avoid updating devices that are already in sync or have newer changes.
[0088] Fig. 5 is a flowchart of an example method 500. In some implementations, one or more process blocks of Fig. 5 may be performed by a second user in a Matter network.
[0089] As shown in Fig. 5, method 500 may include the second user logging on a second client terminal, where the second client terminal is in communication with a first client terminal on which a first user is logged (block 502) .
[0090] As also shown in Fig. 5, method 100 may include sending a first certificate signing request from the second client terminal to an IoT service in the Matter network in response to receiving a sharing notification from the IoT service, where the first certificate signing request may include a public key generated on the second client terminal, where the sharing notification is sent by the IoT service in response to the IoT service receiving a sharing request from the first client terminal (block 504) .
[0091] As further shown in Fig. 5, method 500 may include receiving a first certificate from the IoT service, where the first certificate may include an identity ID assigned by the IoT service and an access ID in association with a designated access level for the second user, where the designated access level is defined in the sharing request by the first user (block 506) .
[0092] As also shown in Fig. 5, method 500 may include accessing at least one IoT device in the Matter network according to the designated access level for the second user (block 508) .
[0093] The method implemented by a second user may include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other processes described elsewhere herein.
[0094] In a preferred implementation, the assigned access ID is an admin access ID in response to the assigned access level being an administrator level; and the assigned access ID is an operate access ID in response to the assigned access level being an operator level.
[0095] In another preferred implementation, alone or in combination with the above implementation, as shown in Fig. 6, method 600 implemented by a second user further includes logging on a third client terminal, where the third client terminal is in communication with the IoT service (block 602) ; sending a second certificate signing request from the third client terminal to an IoT service, where the second certificate signing request may include a public key generated on the third client terminal (block 604) ; receiving a second certificate from the IoT service, where the second certificate may include the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service (block 606) ; and accessing at least one IoT device in the Matter network according to the designated access level for the second user (block 608) .
[0096] Although Fig. 5 and Fig. 6 show example blocks of method 500 and method 600, in some implementations, method 500 and method 600 may include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Fig. 5 and Fig. 6. Additionally, or alternatively, two or more of the blocks of method 500 and method 600 may be performed in parallel.
[0097] As another embodiment, a system is provided in the present disclosure, which includes an IoT service, a first client terminal, a second client terminal and at least one IoT device in a Matter network.
[0098] The IoT service is configured to: receive a sharing request from a first client terminal in the Matter network on which a first user is logged, wherein the sharing request comprises an identification of a second user and a designated access level for the second user, and wherein the second user is logged on the second client terminal; and send a sharing notification to the second client terminal.
[0099] The second client terminal is configured to: send a first certificate signing request to the IoT service, wherein the first certificate signing request comprises a public key generated on the second client terminal.
[0100] The IoT service is further configured to: assign an identity ID for the second user; generate a first certificate, wherein the first certificate comprises the identity ID for the second user and an assigned access ID in association with the designated access level, and the first certificate is signed by the IoT service with a private key generated on the IoT service; and send the first certificate to the second client terminal.
[0101] The second client terminal is further configured to: access the at least one IoT device in the Matter network according to the designated access level of the second user.
[0102] In a preferred implementation, the system further includes a third terminal on which the second user is logged.
[0103] The third client terminal is configured to: send a second certificate signing request to the IoT service, wherein the second certificate signing request comprises a public key generated on the third client terminal.
[0104] The IoT service is configured to: generate a second certificate, wherein the second certificate comprises the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; and send the second certificate to the third client terminal.
[0105] Example Implementation
[0106] Fig. 7 illustrates an example of embodiment according to the present disclosure. As shown in Fig. 7, a first user, a second user, an IoT service, and IoT device (s) are provided, where the first user is logged on a first client terminal and the second user is logged on a second client terminal. The first client terminal, the IoT service and the IoT device (s) are in a Matter network.
[0107] In order to share control over the IoT devices in the Matter network with the second user, the first user may send a sharing request from the first client terminal to the IoT service. The sharing request includes the identification of the second user and a designated access level for the second user. For example, the identification of the second user may be the username of the second user. The designated access level may be “Administrator” or “Operator” as decided by the first user. In some cases, the first user may send the sharing request via a user interface ( “UI” ) in the first client terminal.
[0108] The IoT service is configured to send a sharing notification to the second client terminal after receiving the sharing request from the first user.
[0109] If the second user on the second client terminal accepts the sharing request, a pair of public and private keys will be generated on the second client terminal. The second user will also send a first certificate signing request to the IoT service to proceed with the subsequent steps in order to join the Matter network and obtain access to the IoT devices in the network. The first certificate signing request includes the public key generated on the second client terminal, which will be used by the IoT service later on when sending a first certificate back to the second client terminal.
[0110] The IoT service is further configured to assign an identity ID for the second user. This step can be conducted before or after receiving the first certificate signing request from the second user.
[0111] The IoT service will generate a first certificate, wherein the first certificate includes the assigned identity ID for the second user and an assigned access ID in association with the designated access level, and the first certificate is signed by the IoT service with a private key generated by the IoT service. If the access level of the second user is assigned to an “Administrator” level, the assigned access ID is an admin access ID; and if the access level of the second user is assigned to an “Operator” level, the assigned access ID is an operate access ID.
[0112] The IoT service will send the first certificate to the second client terminal. Preferably, the first certificate may be encrypted with the public key received from the second client terminal, and the second client terminal may decrypt the first certificate with the private key stored locally on the second client terminal.
[0113] The second user on the second client terminal may access the IoT devices in the Matter network according to the designated access level of the second user. The IoT devices allow specific access, such as read-only, read-write, admin etc., based on the access ID of the second user.
[0114] According to the present disclosure, a user can be logged on multiple client terminals at the same time, and the user is assigned one identity ID within a Matter network. However, the user will generate a unique pair of keys for each client terminal that the user is logged on. For example, if a user is logged on an Android app, an iOS app and a smart speaker controller simultaneously, the user will have three unique pairs of keys respectively for these three client terminals. And the user will get different certificates on each of these client terminals, each certificate being embedded with the identity ID of the user.
[0115] Fig. 7 further illustrates such an example, where the second user is logged on a third client terminal.
[0116] The third client terminal sends a second certificate signing request to the IoT service, wherein the second certificate signing request comprises a public key generated on the third client terminal. In some embodiments, the third client terminal makes such a request when the first user notifies it of a sharing intention. For example, the first user may want to share with the third client terminal by sending a sharing notification, and the third client terminal will send a second certificate signing request to the IoT service upon receiving such a notification.
[0117] The IoT service generates a second certificate in response to receiving the second certificate signing request from the third client terminal. The second certificate includes the identity ID and the access ID of the second user. The second certificate is signed by the IoT service using a private key generated on the IoT service; and send the second certificate to the third client terminal. The second certificate enables the third client terminal to access the IoT devices in the Matter network according to the designated access level for the second user.
[0118] Furthermore, by using ACLs, the Matter network can allow users to customize their smart home settings according to their preferences and needs, such as creating scenes, schedules, or automations.
[0119] The present disclosure is designed to provide a seamless and secure user experience for smart home users, where a new user can be added to an existing Matter network and granted with privileges of access and control over devices. By using the present disclosure, an admin user can easily add new users to the Matter network, thus enabling control and configuration of IoT devices by different users.
[0120] The foregoing disclosure provides illustration and description but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications may be made in light of the above disclosure or may be acquired from practice of the implementations. As used herein, the term “component” is intended to be broadly construed as hardware, firmware, or a combination of hardware and software. It will be apparent that systems and / or methods described herein may be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the implementations. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code -it being understood that software and hardware can be used to implement the systems and / or methods based on the description herein. As used herein, satisfying a threshold may, depending on the context, refer to a value being greater than the threshold, greater than or equal to the threshold, less than the threshold, less than or equal to the threshold, equal to the threshold, and / or the like, depending on the context. Although particular combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of various implementations. In fact, many of these features may be combined in ways not specifically recited in the claims and / or disclosed in the specification.
[0121] Although each dependent claim listed below may directly depend on only one claim, the disclosure of various implementations includes each dependent claim in combination with every other claim in the claim set. No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items and may be used interchangeably with “one or more. ” Further, as used herein, the article “the” is intended to include one or more items referenced in connection with the article “the” and may be used interchangeably with “the one or more. ” Furthermore, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, and / or the like) , and may be used interchangeably with “one or more. ” Where only one item is intended, the phrase “only one” or similar language is used. Also, as used herein, the terms “has, ” “have, ” “having, ” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Also, as used herein, the term “or” is intended to be inclusive when used in a series and may be used interchangeably with “and / or, ” unless explicitly stated otherwise (e.g., if used in combination with “either” or “only one of” ) .
[0122] It should be understood that the above method and system in a Matter network are provided as examples only and are not limitations of the present disclosure. Those skilled in the art should understand that the principles of the present disclosure can be applied to systems and methods other than the above-described sharing control in a Matter network without departing from the scope of the present disclosure. While various embodiments of various aspects of the disclosure have been described for the purpose of the disclosure, it shall not be understood that the teaching of the disclosure is limited to these embodiments. The features disclosed in a specific embodiment are therefore not limited to that embodiment, but can be combined with the features disclosed in different embodiments. For example, one or more features and / or operations of the method according to the present disclosure described in one embodiment can also be applied individually, in combination or as a whole in another embodiment. Descriptions of the system / device embodiments are equally applicable to method embodiments, and vice versa. It can be understood by those skilled in the art that more optional embodiments and variations are possible, and that various changes and modifications can be made to the system described above, without departing from the scope defined by the claims of the present disclosure.
Claims
1.A method implemented by an IoT service in a Matter network, comprising:receiving a sharing request from a first client terminal in the Matter network on which a first user is logged, wherein the sharing request comprises an identification of a second user and a designated access level for the second user, and wherein the second user is logged on a second client terminal;sending a sharing notification to the second client terminal;assigning an identity ID for the second user;generating a first certificate in response to receiving a first certificate signing request from the second client terminal, wherein the first certificate signing request comprises a public key generated on the second client terminal, wherein the first certificate comprises the identity ID for the second user and an assigned access ID in association with the designated access level; andsending the first certificate to the second client terminal, wherein the first certificate enables the second client terminal to access at least one IoT device in the Matter network according to the designated access level for the second user.2.The method according to claim 1, further comprising, in response to assigning the identity ID and the access ID for the second user, updating an Access Control List, where the identity ID and the access ID of the second user are added to the Access Control List.3.The method according to claim 1, further comprising:synchronizing the Access Control List to the at least one IoT device in the Matter network.4.The method according to claim 1, whereinthe first certificate is signed by the IoT service with a private key generated by the IoT service.5.The method according to claim 1, whereinthe assigned access ID is an admin access ID in response to the assigned access level being an administrator level; andthe assigned access ID is an operate access ID in response to the assigned access level being an operator level.6.The method according to claim 1, further comprising, in response to receiving a second certificate signing request from a third client terminal on which the second user is logged:generating a second certificate, wherein the second certificate comprises the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated by the IoT service; andsending the second certificate to the third client terminal;wherein the second certificate signing request comprises a public key generated on the third client terminal.7.The method according to claim 1, further comprising, in response to receiving, from a user with an administrator access level in the Matter network, a request to remove the second user:removing the identity ID and the admin access ID of the second user from the Access Control List; andsynchronizing the updated Access Control List to the at least one IoT device in the Matter network.8.The method according to claim 1, wherein the first user is provided with an administrator access level in the Matter level.9.The method according to claim 1, wherein the IoT service, the first client terminal, and at least IoT device in the Matter network share a security domain, and the method further comprising:adding the second client terminal to the security domain based on the first certificate.10.The method according to claim 6, wherein the IoT service, the first client terminal, and at least IoT device in the Matter network share a security domain, and the method further comprising:adding the third client terminal to the security domain based on the second certificate.11.A method implemented by a second user in a Matter network, comprising:the second user logging on a second client terminal, wherein the second client terminal is in communication with a first client terminal on which a first user is logged;sending a first certificate signing request from the second client terminal to an IoT service in the Matter network in response to receiving a sharing notification from the IoT service, wherein the first certificate signing request comprises a public key generated on the second client terminal, wherein the sharing notification is sent by the IoT service in response to the IoT service receiving a sharing request from the first client terminal;receiving a first certificate from the IoT service, wherein the first certificate comprises an identity ID assigned by the IoT service and an access ID in association with a designated access level for the second user, wherein the designated access level is defined in the sharing request by the first user; andaccessing at least one IoT device in the Matter network according to the designated access level for the second user.12.The method according to claim 11, whereinthe assigned access ID is an admin access ID in response to the assigned access level being an administrator level; andthe assigned access ID is an operate access ID in response to the assigned access level being an operator level.13.The method according to claim 11, further comprising:logging on a third client terminal, wherein the third client terminal is in communication with the IoT service;sending a second certificate signing request from the third client terminal to an IoT service, wherein the second certificate signing request comprises a public key generated on the third client terminal;receiving a second certificate from the IoT service, wherein the second certificate comprises the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; andaccessing at least one IoT device in the Matter network according to the designated access level for the second user.14.A system, comprising an IoT service, a first client terminal, a second client terminal and at least one IoT device in a Matter network, wherein,the IoT service is configured to:receive a sharing request from a first client terminal in the Matter network on which a first user is logged, wherein the sharing request comprises an identification of a second user and a designated access level for the second user, and wherein the second user is logged on the second client terminal; andsend a sharing notification to the second client terminal;the second client terminal is configured to:send a first certificate signing request to the IoT service, wherein the first certificate signing request comprises a public key generated on the second client terminal;the IoT service is further configured to:assign an identity ID for the second user;generate a first certificate, wherein the first certificate comprises the identity ID for the second user and an assigned access ID in association with the designated access level, and the first certificate is signed by the IoT service with a private key generated on the IoT service; andsend the first certificate to the second client terminal;and the second client terminal is further configured to:access the at least one IoT device in the Matter network according to the designated access level of the second user.15.The system according to claim 14, further comprising a third terminal on which the second user is logged, wherein:the third client terminal is configured to:send a second certificate signing request to the IoT service, wherein the second certificate signing request comprises a public key generated on the third client terminal; and,the IoT service is configured to:generate a second certificate, wherein the second certificate comprises the identity ID and the access ID of the second user, and the second certificate is signed by the IoT service using a private key generated on the IoT service; andsend the second certificate to the third client terminal.16.A non-transient computer storage medium storing a computer program that, when the computer program is executed by a processor, causes the processor to perform the method according to any one of claims 1-10.17.A non-transient computer storage medium storing a computer program that, when the computer program is executed by a processor, causes the processor to perform the method according to any one of claims 11-13.
Citation Information
Patent Citations
Leveraging pre-existing groups for IoT device access
US20180103039A1
EXTENDING MANAGEMENT CONTROL TO loT DEVICES
US20220030033A1
Method of control and management for devices on the internet of things, in particular for home automation, robotic, biomedical, monitoring, telemetry applications and the like
WO2018096566A1
Device permission control method, device, and storage medium
WO2021072749A1