Mobile Device Secure Access to Hotel IoT Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT systems lack secure access mechanisms for users to control and interact with IoT devices from third-party entities, such as hotels or corporations, without compromising security and privacy.
Innovation Solution
A mobile device establishes a secure connection with a trusted server using a preconfigured private key, receives a time-bound token from a third-party server, and uses this token to obtain an IoT profile that configures the mobile device to control and interact with multiple IoT devices, ensuring secure communication and access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a mobile device directly connects to third-party IoT devices, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces a trusted server as an intermediary between the mobile device and third-party IoT devices. The trusted server establishes secure connections with both parties, allowing the mobile device to control IoT devices without direct connection. The server mediates authentication using tokens and profiles, enabling easy user operation while maintaining security through the intermediary layer.
2Reliability
If secure authentication mechanisms are implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent extracts complex security authentication logic from the mobile device and relocates it to the trusted server. The mobile device only needs to store simple tokens and profiles, while the server handles complex authentication, token generation, and profile management. This extraction reduces device complexity while maintaining strong security through centralized authentication mechanisms.
3Ease of operation
If direct access to IoT devices is allowed, then ease of operation is improved, but loss of information is worsened
Solution Approach 1:
The trusted server acts as an information intermediary that protects user privacy while enabling device access. The server stores and manages user profiles and device information, allowing the mobile device to control IoT devices without directly accessing sensitive information. All information exchange passes through the server, which filters and protects data, preventing privacy loss while maintaining operational ease.
Data Source
AI summary
A system and method for secure access to IoT devices using a mobile device. The mobile device includes a memory configured to store a private value thereon. The mobile device also includes a processor. The processor is configured establish a secure connection with the between the mobile device and a trusted server using the private value, receive a token from the a third party server via the trusted server, transmit the token to a provisioning server via the trusted server, receive an Internet of Things (IoT) profile from the provisioning server via the trusted server, and configure an IOT gateway based on the IoT profile.


