Slave Access Token Generation for IoT Device Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems lack an efficient method for authorizing temporary devices to access and utilize services provided by application servers, especially in scenarios where devices are not initially authenticated or authorized, such as in IoT services.
Innovation Solution
The system generates and manages 'slave access tokens' based on first authorization information from a proprietary device, allowing temporary use devices to access application servers without prior authentication, using a network of proprietary and temporary use devices connected through communication lines, including near field communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication methods are used for device access, then security is maintained, but temporary devices cannot access services without prior authentication
Solution Approach 1:
The patent introduces an intermediary authorization token that mediates between the authenticated first device and the unauthenticated second device. The first device generates an authorization token containing permission information, which is then transmitted to the second device. This token acts as a mediator that enables the second device to access the application server without direct authentication, while still maintaining security through the controlled permission structure embedded in the token.
Solution Approach 2:
The system performs preliminary authentication and authorization actions through the first device before the second device needs to access services. The first device, which is already authenticated, pre-generates an authorization token that encapsulates the necessary permission information. This preliminary authorization action allows the second device to skip the authentication step and directly access services based on the pre-established permissions.
2Ease of operation
If prior authentication is required for device access, then security is ensured, but user experience is degraded due to complex authorization processes
Solution Approach 1:
The patent extracts the authentication step from the access process for the second device. Instead of requiring the second device to undergo the full authentication sequence, the system extracts only the necessary permission verification by validating the authorization token. This separation allows the second device to access services through a simplified process while the first device handles the authentication burden, improving ease of operation without compromising security.
Solution Approach 2:
The system creates a copy of the authorization credentials in the form of an authorization token. Rather than requiring the second device to present original authentication credentials, a copied representation (the token) containing the essential permission information is used. This copy mechanism simplifies the access process for temporary devices while maintaining security through the validated token structure.
3Measurement precision
If authorization information is generated for each device, then access control precision is improved, but system complexity increases
Solution Approach 1:
The authorization token serves multiple functions: it acts as a permission credential, an authentication substitute, and an access control key. This multi-functional design allows the system to maintain precise authorization control without creating separate complex mechanisms for each function. The single token structure handles permission verification, device identification, and access control, reducing overall system complexity while maintaining authorization precision.
Data Source
AI summary
An information processing system includes a memory that stores a user and authorization information, indicative of processing permitted for the user to execute with respect to a server on a communication line, in an associated manner; a generating unit that generates second authorization information on the basis of first authorization information associated with a user who uses a first device; a transmitting unit that transmits the second authorization information to a second device located near the first device; a receiving unit that receives data and the second authorization information from the second device; and a requesting unit that requests the server to execute processing using the data, on the basis of the second authorization information.


