IoT Device Authorization via Location Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices often lack robust security mechanisms, making them vulnerable to malicious attacks, and existing solutions like proprietary interfaces and certificates are inflexible or susceptible to theft, posing risks to users and infrastructure.

Innovation Solution

A method and system that authorizes communication between IoT devices and certified mobile devices only when their geographic positions match within a defined distance, utilizing a combination of geographic verification, user identification, and additional authorization methods, such as PKI or access control systems, to ensure secure access and data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary interfaces and certificates are used for device access, then secure data transmission is achieved, but the system becomes inflexible and vulnerable to certificate theft

Engineering Contradiction:
Improvesecure data transmissionVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the authorization parameter from certificate-based to location-based. Instead of relying on static certificates that can be stolen, the system uses dynamic geographic location data (GPS coordinates, IP address, user profile information) to determine whether to grant access. This resolves the contradiction by maintaining security through parameter verification while enabling flexible access for different users in different locations without requiring certificate management.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If location-based authorization is implemented, then system security is improved, but the complexity of the authorization process increases

Engineering Contradiction:
Improvesystem securityVSAvoidauthorization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the server perform multiple functions: it stores user profiles, determines geographic location, verifies authorization credentials, and manages device access. By consolidating these functions in a single server, the system improves security through comprehensive verification while avoiding the complexity of multiple distributed authorization systems. The server acts as a universal authorization hub that handles all location-based access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple authorization factors are required, then unauthorized access is prevented, but the ease of operation decreases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiduser operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-storing user profile information, device identifiers, and authorized location data in the server before access is needed. When a user attempts to access a device, the server quickly retrieves pre-stored information and performs verification without requiring the user to manually provide multiple credentials. This resolves the contradiction by maintaining strong multi-factor authorization while making the user experience simple and convenient.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3769553B1Method and system for authorising the communication of a network node
Publication Date: 2023.05.24 SIEMENS SCHWEIZ AG
  • EP3769553B1 patent drawingFigure 1
  • EP3769553B1 patent drawingFigure 2
  • EP3769553B1 patent drawingFigure 3

AI summary

The invention relates to a method and system for authorizing the communication (e.g data connection) of a network node (e.g IoT device) of a communication network (e.g IP network), wherein the authorization for the communication of the network node only takes place if the geographical position of the network node and the position of a defined (certified) mobile communication terminal (e.g smart phone) essentially match.