IoT Device Control Permission Revocation via Blockchain Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing blockchain-based device control methods in IoT environments cannot revoke control permissions once granted, leading to irreversible device control.

Innovation Solution

A method using second transaction information on a blockchain to revoke control permissions by generating and sending second transaction data that corresponds to first transaction information, allowing target devices to reject control attempts by users who no longer have authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blockchain-based bitcoin technology is used for device control authorization, then transaction immutability and security are improved, but control permission revocation capability deteriorates

Engineering Contradiction:
Improvetransaction immutabilityVSAvoidcontrol permission revocation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the control permission into two independent components: first transaction information for authorization and second transaction information for revocation. These are stored separately in the blockchain, allowing independent verification of authorization status without compromising the immutability of either transaction type.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-storing both authorization (first transaction) and revocation (second transaction) information in the blockchain before actual device control operations occur. This allows the target device to proactively check the blockchain for both types of transactions and determine the current authorization status without needing real-time communication with the authorization server.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If first transaction information is stored in blockchain for authorization, then authorization security is improved, but the ability to dynamically manage control permissions deteriorates

Engineering Contradiction:
Improveauthorization securityVSAvoiddynamic control permission management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides control permission management into two separate transaction types stored in the blockchain: first transaction information for granting authorization and second transaction information for revoking authorization. This segmentation maintains the security benefits of blockchain storage while enabling dynamic permission management through the addition of revocation transactions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The target device continuously monitors the blockchain for second transaction information that corresponds to first transaction information. When a revocation transaction is detected, the target device immediately updates its authorization status and rejects subsequent control requests, providing real-time feedback and dynamic control without compromising the immutable authorization record.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If control permission is granted through first transaction information, then user access control is improved, but prevention of unauthorized access after revocation deteriorates

Engineering Contradiction:
Improveuser access controlVSAvoidunauthorized access after revocation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary action by pre-storing both authorization and revocation transactions in the blockchain before they are needed. The target device proactively checks for the existence of corresponding second transaction information before processing any control requests, ensuring that unauthorized access attempts are rejected immediately without requiring real-time communication with the authorization server.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The target device continuously monitors the blockchain for revocation transactions and immediately updates its authorization status when second transaction information is detected. This feedback mechanism ensures that the device maintains an up-to-date understanding of its authorization status and automatically rejects control requests from revoked users, preventing unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3686829B1Device control method, and related device for same
Publication Date: 2025.03.26 HUAWEI TECH CO LTD
  • EP3686829B1 patent drawingFigure 1
  • EP3686829B1 patent drawingFigure 2
  • EP3686829B1 patent drawingFigure 3

AI summary

Embodiments of this application provide a device control method and a related device, so that a target device rejects, based on second transaction information including second data, control by a first participant. The method in the embodiments of this application includes: generating, by a server, first transaction information, where the first transaction information is used to indicate that a first participant has obtained control permission, the first transaction information includes information about the first participant and first data that includes information about a second participant, and the control permission is permission to control a target device; sending, by the server, the first transaction information to a blockchain; when the control permission is revoked, generating, by the server, second transaction information, where the second transaction information includes second data, and there is a correspondence between the second data and the first data; and sending, by the server, the second transaction information to the blockchain, where the second transaction information is used to indicate that the control permission on the target device has been revoked, and that the control permission has been revoked is used to instruct the target device to reject control over the target device by the first participant.