Certificate-Based Access Control for Connected Building Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing home automation systems face challenges in securely controlling a large number of connected objects during installation and configuration, as using unique passwords for each object is impractical.
Innovation Solution
A method and device for controlling connected building objects in a communication network using security certificates to establish secure connections, verify authorization, and execute commands based on access rights, allowing a single certificate to manage multiple objects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unique passwords are used for each connected object, then security is improved, but device complexity and ease of operation deteriorate due to the need to manage multiple passwords
Solution Approach 1:
The patent applies universality by enabling a single remote controller with one security certificate to control multiple connected objects. Instead of requiring unique passwords for each object, the system uses a universal security certificate that can authenticate the remote controller to multiple objects, simplifying management while maintaining security.
Solution Approach 2:
The patent introduces an intermediary approach by using security certificates as a mediator between the remote controller and connected objects. The certificates act as a universal credential that facilitates authentication without requiring direct individual password management for each object, resolving the contradiction between security and ease of operation.
2Reliability
If unique passwords are used for each connected object, then security is improved, but ease of operation deteriorates during installation and configuration
Solution Approach 1:
During installation and configuration, the universal security certificate allows the installer to control multiple connected objects without switching between different passwords. The single certificate provides universal access rights that can be configured to grant appropriate permissions across multiple objects, significantly easing the installation process while maintaining security controls.
Solution Approach 2:
The system performs preliminary action by pre-configuring access rights and command authorizations in the security certificate before the actual control operations. This allows the remote controller to be ready to control multiple objects immediately upon connection, without requiring individual password setup for each object during the installation process.
3Ease of operation
If security certificates are used instead of unique passwords, then ease of operation is improved, but security may deteriorate if not properly implemented
Solution Approach 1:
The patent applies local quality by implementing fine-grained access control where different connected objects can have different sets of authorized commands associated with the same security certificate. The system evaluates access rights locally at each object based on the certificate's attributes, ensuring that while operation is simplified, security is maintained through object-specific authorization rules.
Solution Approach 2:
The system uses parameter changes by encoding access rights and authorizations as parameters within the security certificate itself. By modifying the certificate parameters to include specific command authorizations and access rights, the system maintains security while enabling easy operation - the same certificate can be used across multiple objects with different parameter sets for authorization.
Data Source
AI summary
This method comprises opening (82) a secure connection between a connected building object and a remote controller, implementing a first security certificate of the connected object and a second security certificate of the remote controller, and receiving via said secure connection (42) a command to perform at least one action issued by the remote controller, followed by the steps of:extracting (86) a value from a predetermined field of the second security certificate, referred to as the remote controller's access authorisation value;checking (90), in a structure for storing associations between access authorisation values and sets of authorised commands, that said received command belongs to a set of at least one authorised command associated with said access value; andif the check is positive, executing (92) at least one action associated with the received command.


