IoT Single Sign-On via Mobile Wireless Link

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices often require separate sign-on processes, leading to user inconvenience and increased security risks due to repeated usernames and passwords, which existing single sign-on (SSO) methodologies struggle to address effectively, especially given limitations in IoT device security mechanisms like keychains.

Innovation Solution

Implementing SSO methodologies that leverage local wireless communications technologies such as Bluetooth and Near Field Communication (NFC) to facilitate secure authentication by reusing authentication from a mobile device, allowing a single interaction to approve identity migration and complete IoT device authorization using a unique code and verification URL.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate sign-on processes are used for each IoT device, then device-specific security control is improved, but user convenience deteriorates and security risk increases due to password repetition

Engineering Contradiction:
Improvedevice-specific security controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into device-specific components while maintaining a unified identity framework. Each IoT device maintains its own authentication endpoint and security policies, allowing device-specific control while enabling users to leverage their existing mobile device authentication credentials across multiple devices without sharing passwords.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the mobile device acts as a trusted mediator. The mobile device's existing authentication credentials serve as an intermediary that can be leveraged to authenticate IoT devices without requiring users to create or share passwords, thus improving convenience while maintaining security through the intermediary's trusted status.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate sign-on processes are used for each IoT device, then device-specific authentication is improved, but security risk worsens due to users repeating usernames and passwords

Engineering Contradiction:
Improvedevice-specific authenticationVSAvoidsecurity breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password entry requirement from the authentication process. By allowing users to leverage their mobile device's existing authentication credentials, the system removes the need for users to input or repeat passwords across devices, thereby eliminating the security risk of password repetition while maintaining device-specific authentication through the extracted credential verification process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device's authentication system serves as a trusted intermediary that validates credentials without exposing passwords. This intermediary mechanism allows device-specific authentication to occur while the actual password remains secured within the mobile device, preventing password repetition risks while maintaining strong authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If known SSO methodologies are used, then sign-on convenience is improved, but applicability deteriorates due to IoT device limitations such as lack of keychain security mechanisms

Engineering Contradiction:
Improvesign-on convenienceVSAvoidapplicability to IoT devices
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication approach that works across diverse device types including IoT devices with limited security mechanisms. By leveraging the mobile device's existing authentication infrastructure and using it as a bridge to authenticate IoT devices, the system achieves multi-functionality that accommodates both sophisticated and basic security environments without requiring each device to have advanced security features like keychains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device serves as an intermediary that bridges the gap between SSO convenience and IoT device limitations. The mobile device's robust security mechanisms act as a mediator, providing the security functionality that IoT devices lack, while enabling SSO-style convenient authentication for IoT devices without requiring them to implement complex security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10924469B2Single sign-on (SSO) for internet of things (IoT) applications
Publication Date: 2021.02.16 VERIZON PATENT & LICENSING INC
  • US10924469B2 patent drawing
  • US10924469B2 patent drawing
  • US10924469B2 patent drawing

AI summary

Systems and methods for authorizing an Internet of Things (IoT) application of an IoT device (such as a smart TV or a set-top box microconsole). Examples can include establishing, by the IoT application, a connection with a mobile application of a mobile device. The connection can be a wireless link that has a maximum range less than or equal to 400 meters (such as a Bluetooth or a near-field communication (NFC) link). Examples can also include sending, by the IoT application, a request to a remote server to return a connector code. The request can include an identification of the wireless link. Examples can also include receiving, by the IoT application, the connector code from the remote server or a second server, and transferring, by the IoT application, the connector code to the mobile application via the wireless link.