Proximity-Based Access Address Management for Secure Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing and sharing data stored in communication networks lack precise control, allowing unauthorized access and data misuse due to insecure URL sharing and lack of range-based access control.

Innovation Solution

A method that uses short-range communication means to create and manage temporary access addresses for data stored on a communication network, deactivating access when the terminals are out of range, ensuring secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a URL address is exchanged between terminals for data access, then data sharing is enabled, but access control is lost and security is compromised

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidaccess control security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies dynamics by making the URL address temporary and dynamically valid only within a specific time window and physical range. The URL transitions from a permanent static address to a temporary dynamic one that automatically expires, resolving the contradiction between sharing capability and security control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary action by establishing proximity verification through short-range communication before the URL becomes active. The sharing terminal must detect the guest terminal within communication range before generating and transmitting the URL, ensuring access control is predetermined and enforced before data access occurs.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If remote access to cloud storage is enabled, then data accessibility is improved, but access duration cannot be controlled

Engineering Contradiction:
Improvedata accessibilityVSAvoidaccess duration control
Core Design Contradiction:
Ease of operationVSDuration of action of moving object

Solution Approach 1:

The patent applies periodic action by implementing time-based URL expiration. Each URL is valid only for a predetermined duration and automatically becomes inactive after expiration, enabling the system to control access duration while maintaining ease of operation during the valid period.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent makes the URL lifecycle dynamic by automatically activating it upon proximity detection and automatically expiring it after a set duration or when proximity is lost. This dynamic lifecycle management resolves the contradiction between continuous accessibility and controlled access duration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If username and password protection is used, then security is improved, but identification traces are left on terminals

Engineering Contradiction:
Improveaccess securityVSAvoididentification traces
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the identification verification process from the data access process by using short-range communication proximity detection instead of traditional username/password authentication. This separates the security verification (proximity check) from the data access (URL-based), eliminating the need for persistent identification traces on terminals.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces short-range communication proximity detection as an intermediary mechanism between the sharing terminal and guest terminal. This intermediary verifies physical proximity without requiring traditional authentication credentials, thus maintaining security while avoiding the generation of identification traces like cookies or cached passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If invitations are sent to share content, then access control is established, but management complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidinvitation management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling automatic proximity-based URL generation and transmission without manual invitation management. When a guest terminal enters the sharing terminal's communication range, the system automatically detects the proximity, generates a URL, and transmits it, eliminating the need for manual invitation creation, tracking, and deletion.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the manual invitation management process from the sharing mechanism. Instead of requiring users to send, track, and revoke invitations, the system uses automatic proximity detection to trigger URL generation and transmission, significantly reducing management complexity while maintaining access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2797284B1Methods and systems for controlled access to data stored in a network
Publication Date: 2018.10.31 ORANGE SA
  • EP2797284B1 patent drawingFigure 1~2
  • EP2797284B1 patent drawingFigure 3
  • EP2797284B1 patent drawingFigure 4

AI summary

The invention relates to a method for controlling access to data stored on a communication network between a first and a second terminal, the terminals being equipped with a first short-range communication means and a second communication means to said network. The method comprises the steps implemented by the first terminal: sending (E20) to the communication network a request to create an access address to the stored data, receiving (E21) a corresponding access address, and sending (E22) the access address to the second terminal via the first short-range communication means. The method is such that it includes a step of sending (E24) a command to deactivate the access address to the communication network upon detection (E23) that at least one of the two terminals is outside the range of the first short-range communication means.The invention also relates to a method for managing access addresses to stored data implemented by a communication network access server. It also relates to the devices, terminals, and servers implementing the described methods.