IoT Token Service for Cross-Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices face limitations in accessing second cloud services due to incompatible access credentials, restricting their functionality and effectiveness.
Innovation Solution
A method and system that generate and utilize access tokens, validated by an IoT device's identity, allowing IoT devices to access second services without requiring additional authentication, by exchanging a first token for an access token with a predefined time window, and including claims to restrict access scope.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IoT devices use their native access credentials to connect to a core service, then they can access the core service, but they cannot access other cloud services due to credential incompatibility
Solution Approach 1:
The patent introduces a token service as an intermediary between IoT devices and cloud services. The token service receives the device's native credentials, validates them, and issues standardized access tokens that are compatible with multiple cloud services. This mediator enables cross-service access without compromising the reliability of the original authentication mechanism.
Solution Approach 2:
The patent transforms the authentication parameter from device-specific credentials to standardized access tokens. By changing the form and format of the credential parameter, the system maintains the security and reliability of the original authentication while enabling compatibility with multiple cloud services that accept standardized token formats.
2Adaptability or versatility
If IoT devices obtain access tokens for second services, then they can access additional cloud services, but they require a token exchange process that adds system complexity
Solution Approach 1:
The patent creates a universal token service that handles multiple authentication scenarios through a single standardized interface. This multi-functional service can validate different device credentials, issue tokens for various cloud services, and manage token lifecycles, thereby reducing overall system complexity despite enabling access to multiple services.
3Duration of action of stationary object
If IoT devices use permanent access credentials, then they can continuously access cloud services, but security is compromised if credentials are stolen or compromised
Solution Approach 1:
The patent implements periodic authentication by issuing access tokens with finite lifetimes that expire after a predetermined duration. Devices must periodically re-authenticate to obtain fresh tokens, which limits the window of opportunity for attackers and reduces the harm potential if credentials are compromised.
Solution Approach 2:
The patent treats access tokens as disposable, short-lived credentials that are generated, used, and discarded in a controlled manner. Each token is valid only for a specific duration and purpose, and once expired or used, it becomes invalid. This approach is analogous to using disposable items that eliminate long-term security risks associated with permanent credentials.
Data Source
AI summary
The present disclosure provides a system and method for delegating authority to cloud IoT devices, with such delegated authority enabling the cloud IoT devices to access second cloud services outside of a core network. The IoT device uses its IoT identity to obtain a token for accessing the second service within a predefined time window. The token may be used to access the second service without further authentication by the second service. Accordingly, the IoT device can take particular actions, such as downloading files, etc., during the predefined time window. After the predefined time window, the IoT device may no longer access the second service without obtaining another token.


