IoT Authorization via Challenge-Response Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT-based systems face challenges in maintaining data integrity and privacy while ensuring secure and user-friendly access to smart devices, both locally and remotely, due to inadequate security measures and complex configurations.
Innovation Solution
A computer-implemented system and method that utilizes a client device, local network node, and remote network node to generate and validate authorization data, including an authorization code, to provide secure access to smart devices, using key exchange and encryption techniques to ensure integrity and privacy without exposing personal information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If existing IoT authorization solutions are implemented, then access to smart devices is enabled, but data integrity and privacy are compromised due to exposure of critical information
Solution Approach 1:
The patent introduces a challenge-response mechanism as an intermediary between the client device and smart devices. The challenge is generated by the client device, validated by the server, and used to authorize access without exposing personal identifiers or critical information. This mediator approach allows authorization while protecting data integrity and privacy.
Solution Approach 2:
The patent extracts and removes critical personal information from the authorization process. Instead of using personal identifiers directly for authorization, the system uses challenges and responses that do not expose user identity or sensitive data. The personal identifier is removed from the authorization code transmission, reducing exposure risk.
2Adaptability or versatility
If cloud-based storage is used for personal information, then centralized access is simplified, but security is worsened due to constant risk of password and information breaches
Solution Approach 1:
The patent extracts sensitive personal information from the cloud-based storage and transmission process. The authorization code does not contain personal identifiers, and the challenge-response mechanism does not require storing sensitive user data in the cloud. This reduces the attack surface while maintaining centralized access capability.
Solution Approach 2:
The patent uses temporary, single-use authorization codes that are valid only for specific challenges. These codes are not persistent storage targets and cannot be reused, reducing the impact of potential breaches. The challenge-response pairs are discarded after use, eliminating long-term storage risks.
3Reliability
If existing authorization solutions are used, then access control is provided, but user-friendliness is worsened due to complex configurations and expensive hardware requirements
Solution Approach 1:
The patent removes complex configuration requirements from the authorization process. The client device automatically generates challenges and the server automatically validates them without requiring user intervention in complex settings. This extraction of complexity maintains security while improving user-friendliness.
Solution Approach 2:
The client device performs self-service by automatically generating challenges and initiating the authorization process without user configuration. The system serves itself by handling authentication automatically, eliminating the need for users to configure complex security settings while maintaining reliable access control.
4Speed
If local network access is enabled, then quick access to devices is achieved, but security is worsened due to exposure to local network threats
Solution Approach 1:
The patent introduces the challenge-response mechanism as an intermediary layer between local network access and smart devices. Even when accessing locally, the challenge validation process provides an additional security layer without significantly impacting access speed. The server acts as a mediator that validates authorization before allowing device access.
Data Source
AI summary
A computer-implemented system for authorizing access to one or more smart devices provided in a local environment is disclosed herein. The system comprises a client device, a local network node, and a remote network node. The remote network node is configured generate a link and send it to an address associated with a personal identifier of the client device, and in response to the client device having executed the link, the client device being configured to receive an authorization code. The authorization code is locally or remotely validated based on a challenge previously generated by the client device. An access token is generated and sent to the client device, thereby authorizing the client device access to the one or more smart devices in the local environment.


