Random Key Device Association via Direct Network Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for associating a device with a user in IoT and software fields are susceptible to unauthorized access, as they rely on codes that can be easily obtained by others, and methods requiring enrollment mode may still be vulnerable to targeted attacks.

Innovation Solution

A method involving a direct network connection between a device and a user computing device to generate and share a randomly generated key, which is then verified by a service to ensure only the intended user can associate with the device, using peer-to-peer networks and local connections to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a code-based association method is used, then the association process is simple and fast, but the system becomes vulnerable to unauthorized access

Engineering Contradiction:
Improveassociation process simplicityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a direct network connection between the device and user computing device before generating and transmitting the association key. This ensures that the key is exchanged securely through a controlled channel, preventing unauthorized access while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a random key as an intermediary element that mediates the association between device and user. The key is generated and transmitted through a direct network connection, serving as a secure intermediary that verifies authorization without exposing sensitive information, thus balancing security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enrollment mode is required for association, then unauthorized access is reduced, but the association process becomes more complex and time-consuming

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidassociation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing a direct network connection before key generation, but automates the entire enrollment process. The user simply needs to initiate the association through the application, and the system automatically completes key generation, transmission, and verification, reducing perceived complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The enrollment process is designed to be self-service oriented, where the system automatically generates the random key, transmits it through the direct network connection, and verifies the association without requiring manual configuration or complex user intervention. This reduces the effective complexity experienced by users while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If a random key is generated and transmitted through direct network connection, then security is enhanced, but the association process requires additional steps and time

Engineering Contradiction:
Improvesecurity against targeted attacksVSAvoidassociation setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing the direct network connection and generating the random key in advance of the actual association request. This preparation work is done automatically and quickly, so when the user initiates association, the key is already ready for transmission, minimizing the perceived time loss while maintaining enhanced security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements efficient key transmission by skipping unnecessary intermediate steps and directly transmitting the random key through the established direct network connection. The process rushes through the critical security steps quickly once the connection is established, minimizing the time penalty while ensuring security against targeted attacks.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11889314B2Apparatus, system and method for associating a device to a user of a service
Publication Date: 2024.01.30 LEVITON MFG CO INC
  • US11889314B2 patent drawing
  • US11889314B2 patent drawing
  • US11889314B2 patent drawing

AI summary

A system for associating a device to a user of a service hosted at a remote location may include a device, a WAN, and equipment. The user may identify a wireless network of the device and connect to the device using equipment. An application on the equipment may generate a key and send the key to the device. The device may then connect with the service and transmit the key to the service. The application may disconnect from the device and connect with the service. The application may send a request to the service to associate with the device, sending the key with the request. The service compares the keys received from the device and the application. If the respective keys match, then the service may associate the device to the user of the service. Otherwise, the association is denied.