IoT Service Access Using Verified User Capability Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet of Things (IoT) systems lack efficient and secure mechanisms for delegating access to connected devices, ensuring that users possess the necessary capabilities to utilize services provided by these devices, such as verifying driving licenses or insurance policies, before granting access.

Innovation Solution

A system that verifies user and device profiles through associated verification servers, using secure enclaves and public key infrastructure to validate data items, ensuring that users and devices meet predefined criteria before granting access to services, with the option for periodic validation of these criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated verification systems are implemented to validate user capabilities before granting access to connected devices, then security and reliability are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improveaccess control securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces verification servers as intermediary components that mediate between users and connected devices. These servers hold and validate capability information (such as driving licenses, insurance policies) and provide verification tokens to authorized users, thereby centralizing the complex verification logic and reducing the complexity burden on individual connected devices while maintaining high security standards

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive capability verification is performed before granting access, then access control reliability is improved, but processing time and user operation complexity increase

Engineering Contradiction:
Improvecapability verification accuracyVSAvoidaccess grant time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary verification by having users obtain verification tokens from verification servers before attempting to access connected devices. The verification servers pre-validate user capabilities and issue tokens that prove compliance with access criteria. This preliminary action eliminates the need for time-consuming verification checks at the moment of access, significantly reducing access grant time while maintaining comprehensive verification accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification servers create simplified copies of capability information in the form of verification tokens. Instead of transmitting or re-verifying complex original documents (driving licenses, insurance policies) during access, the system uses these token copies that contain essential verification data, enabling rapid authentication while maintaining verification rigor

Inventive Principle:
Principle #26Copying

3Reliability

If secure enclaves and public key infrastructure are used to protect user data and verification tokens, then information security is improved, but computational overhead and system complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the security architecture into distinct components: secure enclaves for sensitive data storage, verification servers for token issuance and validation, and connected devices for service delivery. Each component performs specific cryptographic operations appropriate to its function, distributing computational load and enabling optimized energy usage. The segmentation allows critical security functions to be performed only where absolutely necessary rather than continuously across all system components

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3649798B1A method for granting access to a service provided by a connected device
Publication Date: 2023.08.23 THALES DIS FRANCE SA
  • EP3649798B1 patent drawingFigure 1
  • EP3649798B1 patent drawingFigure 2
  • EP3649798B1 patent drawingFigure 3

AI summary

The invention relates to a method for granting access to a service provided by a connected device (202) for a user having a user's device (201) and requesting said access, the method comprising the steps of: receiving (211) by the user's device (201) from the connected device (202) a request to validate a user profile, a user profile corresponding to a list of at least one data item representing the user's capabilities to use a service provided by the given connected device; requesting by the user's device (201) to a verification server (203) associated to the at least one data item to validate said data item, and receiving (213) a digital signature of said data item generated by the verification server (203) as a proof of the validation; transmitting (214) the data item of the user profile and its digital signature to a device (200) belonging to the owner of the connected device (202) for it to be informed that said data item is validated, the user profile being considered as validated when the digital signatures of all the data items listed in the user profile are correctly verified by the owner's device; granting (230, 231) for the user access to the service provided by the connected device (202) when the user profile is validated.