Cross-Device Authorization Token Exchange for IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user authentication techniques are challenging on IoT devices with limited display size or interface functionality, leading to difficulties in entering credentials and increased errors, which consume processing power and resources.

Innovation Solution

Implementing cross-device authorization methods that use an authorization token shared between devices, allowing IoT devices to access services without requiring users to enter credentials, leveraging wireless networks like Bluetooth Low Energy for secure and efficient access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user authentication techniques are used on IoT devices, then security authorization can be achieved, but user interface complexity and difficulty of operation increase significantly

Engineering Contradiction:
Improveauthorization securityVSAvoidcredential entry difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a second computing device as an intermediary that stores authorization tokens and provides them to the first IoT device. This mediator device handles the complex authentication credentials, allowing the IoT device to access services without directly managing sensitive authentication data, thus maintaining security while simplifying operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization token is pre-configured and stored on the second computing device before the IoT device needs to access the service. This preliminary setup eliminates the need for real-time credential entry on the IoT device, resolving the contradiction between security (pre-configured tokens) and ease of operation (no entry required).

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional authentication methods are implemented on IoT devices with limited interfaces, then security can be maintained, but computing resource consumption increases due to errors and re-attempts

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication credential management function from the IoT device itself and relocates it to a second computing device with sufficient resources. The IoT device only needs to request and use simple tokens, while the complex credential handling is performed externally, reducing energy consumption and resource usage on the constrained IoT device.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If cross-device authorization using tokens is implemented, then ease of operation improves, but device complexity increases due to additional authorization mechanisms

Engineering Contradiction:
Improveservice access simplicityVSAvoidauthorization mechanism complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authorization system is segmented into distinct functional components: the first IoT device that needs service access, the second device that manages tokens, and the service itself. This segmentation allows each component to have simplified responsibilities, with the IoT device only needing to request tokens rather than implement complex authentication logic, thus improving ease of operation without significantly increasing its complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10602359B1Short-range cross-device authorization
Publication Date: 2020.03.24 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US10602359B1 patent drawing
  • US10602359B1 patent drawing
  • US10602359B1 patent drawing

AI summary

Techniques are described for cross-device authorization using a wireless network connection. Computing device(s) may broadcast an identification signal indicating that the device is authorized to access a remote service, and is therefore available to provide an authorization token to a receiving device. The receiving device may determine one of the broadcasting device(s) to use for cross-device authorization. The receiving device may send a request, to the determined broadcasting device, for an authorization token to access the remote service. The broadcasting device may receive the request and transmit a message to a server device indicating that an authorization token is to be provided to the receiving device. Alternatively, the authorization token may be sent directly from the broadcasting device to the receiving device (e.g., over the wireless communication network). On receiving the authorization token, the receiving device may use it to access the remote service.