IoT Device Authentication via Account-Based Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT networks lack effective security mechanisms for device management and interconnectivity, often isolating devices from social networks and lacking centralized login systems, which complicates communication and management between devices.

Innovation Solution

A method and system for authenticating devices within an IoT network using account names and device identifiers, allowing devices to connect and exchange information based on group associations, with optional policies for interconnectivity and social networking integration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are isolated without centralized authentication, then device independence is maintained, but security and management control deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary authentication authority that manages device identities and group memberships. This server mediates between devices, providing centralized security control without requiring complex peer-to-peer authentication mechanisms between each device pair, thus improving security while maintaining manageable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized authentication system is implemented, then security and management are improved, but system complexity increases

Engineering Contradiction:
Improvemanagement controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server implements universal authentication functionality that handles multiple devices and groups through a single unified system. Rather than creating separate authentication mechanisms for each device or group, the server provides multi-functional authentication services that work across the entire IoT network, reducing overall system complexity while maintaining strong management control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If devices can connect freely, then connectivity and information exchange are enhanced, but security and unauthorized access increase

Engineering Contradiction:
Improveinformation exchangeVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality control by assigning different security attributes and group memberships to different devices and device groups. Rather than applying a uniform security policy across all devices, the system allows selective connectivity based on local device properties and group affiliations, enabling legitimate information exchange while preventing unauthorized access through differentiated access controls.

Inventive Principle:
Principle #3Local quality

4Reliability

If group-based connection rules are implemented, then unauthorized connections are prevented, but connection establishment time increases

Engineering Contradiction:
Improveaccess controlVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and group verification actions before actual device connection is attempted. By pre-establishing authentication credentials and group memberships in the server, the system can quickly verify connection eligibility without time-consuming runtime checks, thus maintaining strict access control while reducing connection establishment time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10182043B2Methods and system for user and device management of an IoT network
Publication Date: 2019.01.15 CYBROOK INC
  • US10182043B2 patent drawing
  • US10182043B2 patent drawing
  • US10182043B2 patent drawing

AI summary

Method for connecting multiple devices associated with an Internet of Things (IoT) network is provided. The method includes the steps of associating a first device identifier of a first device with a first account name and a second device identifier of at least a second device with a second account name, where each device is associated with at least one device identifier for each account name, authenticating each device with a server associated with the IoT network using the corresponding account name and the associated device identifier, determining whether the first account name and the second account name belong to the same group in response to authenticating the first device and the second device and connecting the first device and the second device for management and information exchange based on the determination whether the first and second account names belong to the same group.