Bluetooth Service Access Suspension Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bluetooth security architecture does not allow administrators to temporarily deny access to services for frequent users without requiring frequent PIN code changes, as it lacks a mechanism to suspend access temporarily.

Innovation Solution

A method and device that authenticate and authorize wireless stations, allowing for suspending access to services without user confirmation, keeping authentication information in memory and renewing access authorization without requiring user interaction on the suspended station, and enabling users to manage these states through a user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the administrator changes the PIN code frequently to deny access to services, then security is improved, but user convenience deteriorates and operation complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access control mechanism is segmented into two independent parts: authentication (verified by PIN code) and authorization (managed through trusted device status). This allows the system to maintain security through authentication while providing convenience through automated authorization management, eliminating the need for frequent PIN changes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authorization by pre-establishing trusted device relationships during the pairing process. Once a device is marked as trusted, it automatically gains access rights without requiring repeated user confirmation or PIN entry, thus improving convenience while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the administrator denies access by removing authentication information, then security is improved, but loss of time occurs due to re-authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidre-authentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The invention extracts the authorization decision from the authentication process. Authentication information (PIN code verification) is separated from authorization (access rights). The system can selectively remove authorization for trusted devices without affecting authentication capabilities, allowing immediate access denial without requiring re-authentication and thus eliminating time loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the state parameter of trusted devices from 'authorized' to 'suspended' without altering authentication information. This parameter change allows the system to control access dynamically - devices remain authenticated but their authorization status is modified, enabling instant access denial while preserving the ability to restore access without re-authentication.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system requires user confirmation for each access attempt, then security is improved, but device complexity and operation difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic access control where authorization status can be changed in real-time without modifying the underlying authentication mechanism. The trusted device relationship allows the system to adapt access rights dynamically - granting or suspending access as needed - while maintaining a simple, static authentication process based on pre-shared PIN codes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables self-service access control through automated trusted device management. Once devices are paired and trusted relationships established, the system automatically manages authorization without requiring continuous user intervention or confirmation. This reduces operational complexity while maintaining security through the initial authentication process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8590015B2Method and device to suspend the access to a service
Publication Date: 2013.11.19 INTERDIGITAL CE PATENT HOLDINGS SAS
  • US8590015B2 patent drawing
  • US8590015B2 patent drawing
  • US8590015B2 patent drawing

AI summary

The present invention concerns a device and method for suspending and renewing the authorization to a wireless station to use a service on the device.The device comprises wireless communication means, a memory and at least one service for access by at least one station also comprising wireless communication means, means for authenticating the wireless station, means for authorizing the authenticated station to access one of the at least one service.The device comprises means for suspending the authorized station to access the service; and in response to a user request on the device, renewing the access authorization to the service by the suspended station, without requiring any user interaction on the station.