Server-Mediated Group Verification for Secure IoT Device Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems face challenges in allowing new terminals to easily and safely control devices or obtain device information, lacking robust security measures to prevent unauthorized access.

Innovation Solution

A network system that utilizes a server to manage group information, where requests from terminals to control or access devices are accepted or rejected based on the user's membership in the same group, ensuring secure and easy access for authorized users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a network system allows new terminals to control devices without strict authentication, then ease of operation is improved, but security is worsened due to unauthorized access risks

Engineering Contradiction:
Improveease of terminal connectionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary that manages group information and authentication. When a terminal wants to control a device, it requests group information from the server, which verifies the terminal's membership in the device's group. This mediator approach allows easy connection for authorized users while maintaining security through server-mediated verification, resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a network system implements strict authentication for device control, then security is improved, but ease of operation is worsened due to complex pairing processes

Engineering Contradiction:
ImprovesecurityVSAvoidpairing process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-establishing group information on the server that defines which terminals can control which devices. This group information is prepared in advance, so when a terminal needs to control a device, it simply requests and verifies against the pre-configured group information, rather than undergoing complex real-time authentication. This resolves the contradiction by maintaining security through pre-configured authorization while simplifying the operational process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a network system requires group verification for each device control request, then security is improved, but device complexity is worsened due to additional verification steps

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication and authorization functions into a single group information verification process. Instead of implementing separate authentication mechanisms for each device control request, the system combines these functions by verifying the terminal's group membership once, which then authorizes control of all devices within that group. This merging approach maintains high security through centralized group verification while reducing device complexity by eliminating the need for individual device-level authentication mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9998891B2Network system, server, terminal, and information processing method
Publication Date: 2018.06.12 SHARP KK

AI summary

A network system includes a plurality of terminals including at least a first terminal and a second terminal, one or more devices including at least a first device, and a server adapted to refer to group information. The server refers to the group information and determines whether to accept a request for the first device from the second terminal, when in a state of accepting a request for the first device from the first terminal.