Random Key Device Association via Direct Network Connection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for associating a device with a user in IoT and software fields are susceptible to unauthorized access, as they rely on codes that can be easily obtained by others, and methods requiring enrollment mode may still be vulnerable to targeted attacks.
Innovation Solution
A method involving a direct network connection between a device and a user computing device to generate and share a randomly generated key, which is then verified by a service to ensure only the intended user can associate with the device, using peer-to-peer networks and local connections to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a code-based association method is used, then the association process is simple and fast, but the system becomes vulnerable to unauthorized access
Solution Approach 1:
The system performs preliminary actions by establishing a direct network connection between the device and user computing device before generating and transmitting the association key. This ensures that the key is exchanged securely through a controlled channel, preventing unauthorized access while maintaining operational simplicity.
Solution Approach 2:
The patent introduces a random key as an intermediary element that mediates the association between device and user. The key is generated and transmitted through a direct network connection, serving as a secure intermediary that verifies authorization without exposing sensitive information, thus balancing security and ease of operation.
2Reliability
If enrollment mode is required for association, then unauthorized access is reduced, but the association process becomes more complex and time-consuming
Solution Approach 1:
The system performs preliminary actions by establishing a direct network connection before key generation, but automates the entire enrollment process. The user simply needs to initiate the association through the application, and the system automatically completes key generation, transmission, and verification, reducing perceived complexity while maintaining security.
Solution Approach 2:
The enrollment process is designed to be self-service oriented, where the system automatically generates the random key, transmits it through the direct network connection, and verifies the association without requiring manual configuration or complex user intervention. This reduces the effective complexity experienced by users while maintaining strong security.
3Reliability
If a random key is generated and transmitted through direct network connection, then security is enhanced, but the association process requires additional steps and time
Solution Approach 1:
The system performs preliminary actions by establishing the direct network connection and generating the random key in advance of the actual association request. This preparation work is done automatically and quickly, so when the user initiates association, the key is already ready for transmission, minimizing the perceived time loss while maintaining enhanced security.
Solution Approach 2:
The patent implements efficient key transmission by skipping unnecessary intermediate steps and directly transmitting the random key through the established direct network connection. The process rushes through the critical security steps quickly once the connection is established, minimizing the time penalty while ensuring security against targeted attacks.
Data Source
AI summary
A system for associating a device to a user of a service hosted at a remote location may include a device, a WAN, and equipment. The user may identify a wireless network of the device and connect to the device using equipment. An application on the equipment may generate a key and send the key to the device. The device may then connect with the service and transmit the key to the service. The application may disconnect from the device and connect with the service. The application may send a request to the service to associate with the device, sending the key with the request. The service compares the keys received from the device and the application. If the respective keys match, then the service may associate the device to the user of the service. Otherwise, the association is denied.


