Gateway-Mediated Home Automation Access for Third-Party Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The heterogeneity of home automation devices and the management of access to ensure security in home automation installations make it difficult to open the system for third-party services to exploit data or enable control.

Innovation Solution

A method for configuring remote access to home automation devices through a first remote access service, which includes receiving access requests, configuring access rights repositories, and managing authorization using identification tokens, allowing third-party services to access devices while preserving user control without setting up additional infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the system opens access to third-party services to exploit data and enable control, then service versatility and data utilization improve, but system security and access management complexity worsen

Engineering Contradiction:
Improveservice accessibilityVSAvoidaccess management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component that mediates between third-party services and home automation devices. The gateway manages access rights repositories and authentication tokens, allowing third-party services to access devices without direct connections. This intermediary approach enables service versatility while maintaining centralized security control and avoiding direct exposure of devices to external services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments access management into distinct components: authentication tokens for identity verification, access rights repositories for permission storage, and gateway-mediated communication channels. This segmentation allows independent management of security policies for different services and devices, reducing overall system complexity while enabling fine-grained access control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control measures are strengthened to ensure security, then system security improves, but ease of operation and service integration worsen

Engineering Contradiction:
Improvesystem securityVSAvoidservice integration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary authentication by issuing access tokens before services attempt to access devices. The gateway pre-configures access rights repositories with authorized service identifiers and device access permissions. This preliminary action ensures security validation occurs before any device interaction, maintaining strong security while simplifying subsequent service operations through token-based authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service authentication where services present their credentials and receive automated token issuance from the gateway. The access rights repository automatically validates service permissions without requiring manual intervention. This self-service mechanism maintains rigorous security checks while eliminating complex manual access configuration for service integrations.

Inventive Principle:
Principle #25Self-service

3Reliability

If direct access infrastructure is set up for third-party services, then access reliability improves, but device complexity and infrastructure requirements worsen

Engineering Contradiction:
Improveaccess reliabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal gateway architecture that serves multiple third-party services through a single access point. The gateway's access rights repository stores permissions for multiple services and devices, and the token-based authentication system works across all service-device interactions. This universal approach provides reliable access for all services without requiring separate infrastructure for each service, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3563557B1Method for configuring access to, remote controlling, and monitoring at least one home automation device forming part of a home automation installation
Publication Date: 2025.10.01 OVERKIZ
  • EP3563557B1 patent drawingFigure 1
  • EP3563557B1 patent drawingFigure 2
  • EP3563557B1 patent drawingFigure 3

AI summary

The present invention relates to a method of remotely configuring access to at least one home automation device (D) that is part of a home automation installation (Su), the home automation installation comprising at least one home automation device (D) and at least one central control unit (U), and the method being performed by a first remote access service (Svc1) carried out by a management unit and comprising the following steps: receiving (ECfSvc19; ECfSvc14) a remote access request (MP, Min) relating to at least one home automation device (D) linked to the profile of a user (Usr1) and intended for a second service (Svc2), the request being relative to an identifier (Usr1ID1) of the user (Usr1ID1) with the first service (Svc1); receiving (ECfSvc16, ECfSvc19) an authorization in reply to the access request by the user (Usr1); configuring (ECfSvc110) an access authorization repository so as to accept at least one control command (MCa) arriving from a second service (Svc2), or the transmission of monitoring data (MSa) to the second service (Svc2) for the home automation device (D) linked to the user profile (USr1). The invention also relates to a control and monitoring method.