IoT Proximity Access Control for Web Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for managing access to protected web resources do not effectively utilize the physical presence of authorized individuals and lack robust security measures, particularly in scenarios requiring multiple approvals or contingencies for situations where authorized individuals are not present.

Innovation Solution

A method and system that employs IoT devices to restrict access to protected web resources based on the physical proximity of authorized individuals, utilizing a hierarchical access control scheme with multiple authorization requirements and backup mechanisms to ensure secure access, even when primary approvers are offline or unavailable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is based on traditional authentication methods, then access can be granted remotely, but security is insufficient as physical presence cannot be verified

Engineering Contradiction:
Improveaccess securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system that uses wireless communication signals (Bluetooth, Wi-Fi) as mediators to detect the physical proximity of authorized individuals. The system acts as a mediator between the resource and the requester, verifying presence through signal strength measurements before granting access, thus resolving the contradiction between security and convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical authentication methods (physical keys, cards) with electronic signal-based presence detection. By substituting physical mechanical verification with wireless signal analysis, the system maintains ease of operation while significantly improving security through accurate proximity detection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multiple approval mechanisms are implemented, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization system into distinct functional modules: presence detection module, signal strength analysis module, approval request module, and resource granting module. This segmentation allows multiple approval mechanisms to be implemented while managing complexity through modular design, where each module handles a specific aspect of the authorization process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic authorization requirements that adjust based on resource sensitivity and context. The system can require one or multiple approvals dynamically, rather than using a fixed complex process for all cases. This dynamic approach enhances security for critical resources while maintaining simplicity for less sensitive ones.

Inventive Principle:
Principle #15Dynamics

3Reliability

If primary approvers are required to be online and present, then access control is secure, but access fails when approvers are unavailable

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by establishing backup approval mechanisms in advance. Before primary approvers become unavailable, the system has pre-configured alternative approval paths including secondary approvers and automated approval rules. This ensures that when primary approvers are offline, the system can still grant access through pre-established backup mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent provides beforehand cushioning by creating redundancy in the approval system. Multiple backup approvers and automated approval rules are prepared in advance to cushion against the unavailability of primary approvers. This cushioning mechanism maintains access control reliability while ensuring system availability even when approvers are unavailable.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Reliability

If location-based authorization is implemented, then physical presence verification is achieved, but privacy concerns increase

Engineering Contradiction:
Improvepresence verification accuracyVSAvoidprivacy intrusion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by using location information only when and where needed for authorization decisions. The system does not continuously track or store location data, but rather uses local proximity detection at the moment of access request. This localized use of location data achieves presence verification while minimizing privacy intrusion by limiting data collection to what is strictly necessary.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11558390B2System to control access to web resources based on an internet of things authorization mechanism
Publication Date: 2023.01.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11558390B2 patent drawing
  • US11558390B2 patent drawing
  • US11558390B2 patent drawing

AI summary

According to one embodiment, a method, computer system, and computer program product for managing access to one or more protected web resources based on the location of an approver is provided. The present invention may include granting the requestor access to the protected web resource based on one or more access requirements being met, wherein at least one access requirement comprises a location of one or more authorization devices corresponding with one or more approvers being within a threshold distance of a computing device of a requestor requesting a protected web resource.