IoT Control via Connection Code Secure Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT systems lack the ability to grant temporary control authority over IoT devices without the need for onboarding, making it difficult for users to conveniently control devices in shared environments such as homes or hotels.

Innovation Solution

An electronic device equipped with a communication circuit and processor that obtains a connection code to establish a secure channel with a hub device, allowing it to transmit control commands to IoT devices for designated actions without prior onboarding, using a connection code that includes user information, random PIN, and control authority details.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional onboarding procedures are used to control IoT devices, then control authority is granted, but the process becomes complex and time-consuming for temporary users

Engineering Contradiction:
Improveease of device controlVSAvoidtime for onboarding procedure
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The hub device pre-generates connection codes that contain embedded authentication information and control authority permissions. This preliminary preparation eliminates the need for real-time onboarding procedures, allowing temporary users to quickly connect and control IoT devices by simply scanning or entering the pre-prepared connection code.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The connection code serves as an intermediary that carries authentication credentials and control permissions between the hub device and temporary users. Instead of direct complex authentication protocols, the connection code mediates the authorization process, enabling quick and secure device control for visitors and guests.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If onboarding is required for control authority, then security is maintained, but user convenience deteriorates in shared environments

Engineering Contradiction:
Improvecontrol authority securityVSAvoidconvenience for temporary users
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The hub device performs preliminary security configuration by generating connection codes with embedded authentication credentials and control permissions before users arrive. This advance preparation maintains security requirements while eliminating the need for temporary users to go through complex onboarding procedures, thus preserving both security and convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The connection code creates a simplified copy or representation of the full authentication and authorization process. Instead of requiring users to complete lengthy onboarding procedures, the connection code encapsulates the essential security verification and control permissions in a compact, easily accessible format that maintains security while improving convenience.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If full onboarding is performed for each user, then complete control access is granted, but device complexity increases

Engineering Contradiction:
Improvecontrol access capabilityVSAvoidonboarding process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The control authority and authentication process are segmented into discrete connection codes, each representing a specific set of permissions and control capabilities. Instead of implementing a single complex onboarding system that manages all user access centrally, the system divides access control into multiple independent, pre-configured connection codes that can be distributed and used independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hub device performs preliminary segmentation of control permissions by generating multiple connection codes with different authentication credentials and control authorities in advance. This pre-segmentation eliminates the need for complex real-time authorization management during user onboarding, reducing device complexity while maintaining adaptability for various user scenarios.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12126686B2Electronic device for controlling internet of things device and method of operating the same
Publication Date: 2024.10.22 SAMSUNG ELECTRONICS CO LTD
  • US12126686B2 patent drawing
  • US12126686B2 patent drawing
  • US12126686B2 patent drawing

AI summary

An electronic device includes a communication circuit and a processor, The processor is configured to obtain a connection code related to an external electronic device through the communication circuit, discover the external electronic device through the communication circuit based on the connection code, establish a first secure channel with the external electronic device, based on the connection code, through the communication circuit, and transmit a control command for an internet-of-things (IoT) device to perform a designated action to the external electronic device through the first secure channel using the connection code.