IoT Device Ownership Transfer via Cloud Mediator Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IoT networks, managing ownership and control of physical devices is challenging, especially when multiple entities are involved, as existing systems lack secure methods for transferring ownership and control between entities, leading to potential rogue entity access and control issues.
Innovation Solution
A method involving a device management service that receives verifiable tokens from entities to authenticate and update ownership records, ensuring secure transfer of control from one entity to another, including updating configuration and access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If devices remain on the same network after ownership transfer, then network connectivity and operational continuity are maintained, but ownership control and security management become complex and vulnerable to rogue access
Solution Approach 1:
The patent introduces a cloud service provider as an intermediary that manages the ownership transfer process. The cloud service receives transfer requests from current owners and issues verifiable tokens to new owners, acting as a mediator that maintains network connectivity while securely managing ownership transitions without requiring direct peer-to-peer coordination between owners.
Solution Approach 2:
The patent uses verifiable tokens as digital copies that represent ownership rights. Instead of transferring physical control directly, the system creates and transfers cryptographic copies of ownership verification, allowing multiple entities to access devices while maintaining clear ownership records through these token copies.
2Reliability
If verifiable tokens are used for authentication, then security and rogue entity prevention are improved, but system complexity and authentication overhead increase
Solution Approach 1:
The patent extracts the complex cryptographic authentication logic from the device level and concentrates it at the cloud service provider level. Devices simply need to present verifiable tokens without implementing complex authentication mechanisms themselves, while the cloud service handles the cryptographic verification and token issuance.
Solution Approach 2:
The verifiable token system serves multiple functions simultaneously: it authenticates ownership, enables transfer requests, provides verification credentials, and maintains security across the network. This multi-functionality reduces overall system complexity by consolidating multiple security operations into a single token-based mechanism.
3Ease of operation
If centralized cloud service manages ownership, then control and authorization are simplified, but single point of failure and centralization risks increase
Solution Approach 1:
The system enables self-service ownership transfers where current owners can initiate transfer requests and new owners can claim devices through the cloud service interface. This automated self-service approach simplifies control management while distributing operational responsibility away from manual administrative processes.
Solution Approach 2:
The cloud service provides feedback mechanisms through verifiable tokens that confirm ownership status and transfer completion. This feedback loop allows entities to verify their standing in the system without requiring continuous centralized verification, reducing the operational burden on the central service while maintaining security.
Data Source
AI summary
Transferring control over a device. A method includes, receiving a first indication, including a first verifiable token, from a first entity that at least a portion of control of a device should be relinquished by the first entity. A second indication is received from the second entity, including a second verifiable token, that the at least a portion of control should be transferred to the second entity. The first token and the second token are verified. As a result of verifying the first token and the second token, the at least a portion of control of the device is transferred from the first entity to the second entity. Transferring the at least a portion of control of the device from the first entity to the second entity includes updating the device with configuration applicable to the second entity.


