Access Control Object Instance Generation for Wireless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In M2M communication systems, there is a need for an efficient method to authenticate access rights for resource-constrained devices and to manage access control in multi-server environments, where existing protocols struggle to ensure secure and reliable access to resources across diverse hardware specifications.

Innovation Solution

A method for authenticating access rights in a wireless communication system involves receiving operations from a server, checking access rights based on associated information, determining supported operations, and transmitting responses to indicate granted or rejected access, with the ability to generate access control object instances for managing access rights across multiple servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access right authentication is implemented for M2M devices, then security and reliability are improved, but device complexity and overhead increase

Engineering Contradiction:
Improveaccess right authentication reliabilityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple components: access right information stored in access control object instances, operation type identification, and resource type identification. Each component handles a specific aspect of authentication, dividing the complex authentication process into manageable segments that reduce overall system complexity while maintaining reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Access control object instances are generated in advance and stored in the M2M device, containing pre-configured access right information for different servers and resources. This preliminary preparation eliminates the need for complex real-time authentication calculations, reducing processing overhead while ensuring reliable authentication when operations are received

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If access control object instances are generated for each server, then multi-server environment support is improved, but memory usage and device complexity increase

Engineering Contradiction:
Improvemulti-server environment supportVSAvoidmemory usage for access control objects
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

Access control object instances are designed with a universal structure that can accommodate multiple servers through server identification fields. Each object instance can represent different servers while following the same format, allowing the system to support multi-server environments without creating entirely separate data structures for each server, thus optimizing memory usage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access control system uses a nested structure where access control object instances contain server-specific information within a standardized framework. The objects are organized hierarchically with general access control parameters at higher levels and server-specific parameters nested within, allowing efficient memory utilization while supporting multiple servers

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If detailed access right checking is performed for each operation, then security is improved, but processing time and productivity decrease

Engineering Contradiction:
Improveaccess right verification securityVSAvoidoperation processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different levels of access right checking based on the specific operation type and resource type. Common operations with well-defined access patterns use simplified verification, while sensitive operations undergo more detailed checking. This localized quality approach ensures security for critical operations while maintaining high processing speed for routine operations

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication system performs partial access right verification by checking only the necessary parameters based on operation type. For operations with straightforward access requirements, minimal checking is performed, while operations requiring stricter security receive more comprehensive verification, optimizing the balance between security and processing efficiency

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10506432B2Method and apparatus for authenticating access authority for specific resource in wireless communication system
Publication Date: 2019.12.10 LG ELECTRONICS INC
  • US10506432B2 patent drawing
  • US10506432B2 patent drawing
  • US10506432B2 patent drawing

AI summary

A method for creating, by a terminal, an access control object instance in a wireless communication system, the method includes receiving from a server, an operation for adding an account of a specific server; adding the account of the specific server; and creating an access control object instance for an object instance having no access control object instance from among object instances stored in the terminal if the account of the specific server is added when the terminal has only one existing server account, wherein the server corresponding to the existing server account is set to be an access control owner of the created access control object instance.