IoT Authorization via Challenge-Response Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT-based systems face challenges in maintaining data integrity and privacy while ensuring secure and user-friendly access to smart devices, both locally and remotely, due to inadequate security measures and complex configurations.

Innovation Solution

A computer-implemented system and method that utilizes a client device, local network node, and remote network node to generate and validate authorization data, including an authorization code, to provide secure access to smart devices, using key exchange and encryption techniques to ensure integrity and privacy without exposing personal information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing IoT authorization solutions are implemented, then access to smart devices is enabled, but data integrity and privacy are compromised due to exposure of critical information

Engineering Contradiction:
Improveaccess to smart devicesVSAvoiddata integrity and privacy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a challenge-response mechanism as an intermediary between the client device and smart devices. The challenge is generated by the client device, validated by the server, and used to authorize access without exposing personal identifiers or critical information. This mediator approach allows authorization while protecting data integrity and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts and removes critical personal information from the authorization process. Instead of using personal identifiers directly for authorization, the system uses challenges and responses that do not expose user identity or sensitive data. The personal identifier is removed from the authorization code transmission, reducing exposure risk.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If cloud-based storage is used for personal information, then centralized access is simplified, but security is worsened due to constant risk of password and information breaches

Engineering Contradiction:
Improvecentralized accessVSAvoidsecurity risk from breaches
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive personal information from the cloud-based storage and transmission process. The authorization code does not contain personal identifiers, and the challenge-response mechanism does not require storing sensitive user data in the cloud. This reduces the attack surface while maintaining centralized access capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses temporary, single-use authorization codes that are valid only for specific challenges. These codes are not persistent storage targets and cannot be reused, reducing the impact of potential breaches. The challenge-response pairs are discarded after use, eliminating long-term storage risks.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If existing authorization solutions are used, then access control is provided, but user-friendliness is worsened due to complex configurations and expensive hardware requirements

Engineering Contradiction:
Improveaccess controlVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent removes complex configuration requirements from the authorization process. The client device automatically generates challenges and the server automatically validates them without requiring user intervention in complex settings. This extraction of complexity maintains security while improving user-friendliness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The client device performs self-service by automatically generating challenges and initiating the authorization process without user configuration. The system serves itself by handling authentication automatically, eliminating the need for users to configure complex security settings while maintaining reliable access control.

Inventive Principle:
Principle #25Self-service

4Speed

If local network access is enabled, then quick access to devices is achieved, but security is worsened due to exposure to local network threats

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity exposure
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the challenge-response mechanism as an intermediary layer between local network access and smart devices. Even when accessing locally, the challenge validation process provides an additional security layer without significantly impacting access speed. The server acts as a mediator that validates authorization before allowing device access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12028456B2System and method for authorizing access of local and remote client devices to smart devices in a local environment
Publication Date: 2024.07.02 INTER IKEA SYST
  • US12028456B2 patent drawing
  • US12028456B2 patent drawing
  • US12028456B2 patent drawing

AI summary

A computer-implemented system for authorizing access to one or more smart devices provided in a local environment is disclosed herein. The system comprises a client device, a local network node, and a remote network node. The remote network node is configured generate a link and send it to an address associated with a personal identifier of the client device, and in response to the client device having executed the link, the client device being configured to receive an authorization code. The authorization code is locally or remotely validated based on a challenge previously generated by the client device. An access token is generated and sent to the client device, thereby authorizing the client device access to the one or more smart devices in the local environment.