Bluetooth Service Access Suspension Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bluetooth security architecture does not allow administrators to temporarily deny access to services for frequent users without requiring frequent PIN code changes, as it lacks a mechanism to suspend access temporarily.
Innovation Solution
A method and device that authenticate and authorize wireless stations, allowing for suspending access to services without user confirmation, keeping authentication information in memory and renewing access authorization without requiring user interaction on the suspended station, and enabling users to manage these states through a user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the administrator changes the PIN code frequently to deny access to services, then security is improved, but user convenience deteriorates and operation complexity increases
Solution Approach 1:
The access control mechanism is segmented into two independent parts: authentication (verified by PIN code) and authorization (managed through trusted device status). This allows the system to maintain security through authentication while providing convenience through automated authorization management, eliminating the need for frequent PIN changes.
Solution Approach 2:
The system performs preliminary authorization by pre-establishing trusted device relationships during the pairing process. Once a device is marked as trusted, it automatically gains access rights without requiring repeated user confirmation or PIN entry, thus improving convenience while maintaining security.
2Reliability
If the administrator denies access by removing authentication information, then security is improved, but loss of time occurs due to re-authentication requirements
Solution Approach 1:
The invention extracts the authorization decision from the authentication process. Authentication information (PIN code verification) is separated from authorization (access rights). The system can selectively remove authorization for trusted devices without affecting authentication capabilities, allowing immediate access denial without requiring re-authentication and thus eliminating time loss.
Solution Approach 2:
The system changes the state parameter of trusted devices from 'authorized' to 'suspended' without altering authentication information. This parameter change allows the system to control access dynamically - devices remain authenticated but their authorization status is modified, enabling instant access denial while preserving the ability to restore access without re-authentication.
3Reliability
If the system requires user confirmation for each access attempt, then security is improved, but device complexity and operation difficulty increase
Solution Approach 1:
The system implements dynamic access control where authorization status can be changed in real-time without modifying the underlying authentication mechanism. The trusted device relationship allows the system to adapt access rights dynamically - granting or suspending access as needed - while maintaining a simple, static authentication process based on pre-shared PIN codes.
Solution Approach 2:
The system enables self-service access control through automated trusted device management. Once devices are paired and trusted relationships established, the system automatically manages authorization without requiring continuous user intervention or confirmation. This reduces operational complexity while maintaining security through the initial authentication process.
Data Source
AI summary
The present invention concerns a device and method for suspending and renewing the authorization to a wireless station to use a service on the device.The device comprises wireless communication means, a memory and at least one service for access by at least one station also comprising wireless communication means, means for authenticating the wireless station, means for authorizing the authenticated station to access one of the at least one service.The device comprises means for suspending the authorized station to access the service; and in response to a user request on the device, renewing the access authorization to the service by the suspended station, without requiring any user interaction on the station.


