IoT Account Linking Control for Secure Registered Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT systems, there is a security risk due to unauthorized control of electronic devices through wireless communication, as unregistered mobile devices can potentially control other connected apparatuses, necessitating a method to ensure only registered devices can perform operations within the network.

Innovation Solution

An electronic apparatus with a processor that registers user accounts with both a first and second server, links user accounts, and performs linkage service operations to control external devices only if they are registered, using information about the device and its manufacturer to identify and authenticate connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication is used to enable mobile devices to control electronic apparatuses, then ease of operation is improved, but security is worsened due to unauthorized access risks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A server acts as an intermediary between mobile devices and electronic apparatuses. The server receives control requests from mobile devices, verifies authorization status, and forwards legitimate requests to target apparatuses. This mediator architecture enables wireless convenience while maintaining security through centralized authentication management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Mobile devices must be pre-registered with the server before they can control electronic apparatuses. The registration process establishes authorization credentials in advance, ensuring that only authenticated devices can send control requests. This preliminary authentication prevents unauthorized access while maintaining ease of operation for registered devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a registration process is implemented to prevent unauthorized control, then security is improved, but device complexity is worsened due to additional registration steps

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server provides multiple functions including authentication, authorization, and request routing through a single platform. By consolidating these security and communication functions into one universal system, the registration process becomes more manageable and less complex than implementing separate security mechanisms at each device level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The registration process is designed to be user-friendly and automated, allowing users to register mobile devices through intuitive interfaces. The system automatically generates authentication credentials and configures access rights without requiring complex manual setup, reducing perceived complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11747779B2Electronic apparatus and control method thereof
Publication Date: 2023.09.05 SAMSUNG ELECTRONICS CO LTD
  • US11747779B2 patent drawing
  • US11747779B2 patent drawing
  • US11747779B2 patent drawing

AI summary

An electronic apparatus including at least one interface; and at least one processor configured to: register a first user account with a first server configured to provide a first service, through the at least one interface, identify a second server corresponding to an external apparatus connectable through the at least one interface, wherein the second server is configured to provide a second service different from the first service, register the first user account with the second server through the at least one interface to link the first user account to a second user account corresponding to the second service, and perform a linkage service operation based on the first service and the second service, using the first user account and the second user account.