IoT Token Service for Cross-Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face limitations in accessing second cloud services due to incompatible access credentials, restricting their functionality and effectiveness.

Innovation Solution

A method and system that generate and utilize access tokens, validated by an IoT device's identity, allowing IoT devices to access second services without requiring additional authentication, by exchanging a first token for an access token with a predefined time window, and including claims to restrict access scope.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices use their native access credentials to connect to a core service, then they can access the core service, but they cannot access other cloud services due to credential incompatibility

Engineering Contradiction:
Improveservice access compatibilityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a token service as an intermediary between IoT devices and cloud services. The token service receives the device's native credentials, validates them, and issues standardized access tokens that are compatible with multiple cloud services. This mediator enables cross-service access without compromising the reliability of the original authentication mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the authentication parameter from device-specific credentials to standardized access tokens. By changing the form and format of the credential parameter, the system maintains the security and reliability of the original authentication while enabling compatibility with multiple cloud services that accept standardized token formats.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If IoT devices obtain access tokens for second services, then they can access additional cloud services, but they require a token exchange process that adds system complexity

Engineering Contradiction:
Improveservice access capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal token service that handles multiple authentication scenarios through a single standardized interface. This multi-functional service can validate different device credentials, issue tokens for various cloud services, and manage token lifecycles, thereby reducing overall system complexity despite enabling access to multiple services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Duration of action of stationary object

If IoT devices use permanent access credentials, then they can continuously access cloud services, but security is compromised if credentials are stolen or compromised

Engineering Contradiction:
Improveaccess durationVSAvoidsecurity risk
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic authentication by issuing access tokens with finite lifetimes that expire after a predetermined duration. Devices must periodically re-authenticate to obtain fresh tokens, which limits the window of opportunity for attackers and reduces the harm potential if credentials are compromised.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent treats access tokens as disposable, short-lived credentials that are generated, used, and discarded in a controlled manner. Each token is valid only for a specific duration and purpose, and once expired or used, it becomes invalid. This approach is analogous to using disposable items that eliminate long-term security risks associated with permanent credentials.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12166883B2System and method for delegating authority through coupled devices
Publication Date: 2024.12.10 GOOGLE LLC
  • US12166883B2 patent drawing
  • US12166883B2 patent drawing
  • US12166883B2 patent drawing

AI summary

The present disclosure provides a system and method for delegating authority to cloud IoT devices, with such delegated authority enabling the cloud IoT devices to access second cloud services outside of a core network. The IoT device uses its IoT identity to obtain a token for accessing the second service within a predefined time window. The token may be used to access the second service without further authentication by the second service. Accordingly, the IoT device can take particular actions, such as downloading files, etc., during the predefined time window. After the predefined time window, the IoT device may no longer access the second service without obtaining another token.