Slave Access Token Generation for IoT Device Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems lack an efficient method for authorizing temporary devices to access and utilize services provided by application servers, especially in scenarios where devices are not initially authenticated or authorized, such as in IoT services.

Innovation Solution

The system generates and manages 'slave access tokens' based on first authorization information from a proprietary device, allowing temporary use devices to access application servers without prior authentication, using a network of proprietary and temporary use devices connected through communication lines, including near field communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication methods are used for device access, then security is maintained, but temporary devices cannot access services without prior authentication

Engineering Contradiction:
Improveaccess capability for temporary devicesVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary authorization token that mediates between the authenticated first device and the unauthenticated second device. The first device generates an authorization token containing permission information, which is then transmitted to the second device. This token acts as a mediator that enables the second device to access the application server without direct authentication, while still maintaining security through the controlled permission structure embedded in the token.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and authorization actions through the first device before the second device needs to access services. The first device, which is already authenticated, pre-generates an authorization token that encapsulates the necessary permission information. This preliminary authorization action allows the second device to skip the authentication step and directly access services based on the pre-established permissions.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If prior authentication is required for device access, then security is ensured, but user experience is degraded due to complex authorization processes

Engineering Contradiction:
Improveauthorization process simplicityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication step from the access process for the second device. Instead of requiring the second device to undergo the full authentication sequence, the system extracts only the necessary permission verification by validating the authorization token. This separation allows the second device to access services through a simplified process while the first device handles the authentication burden, improving ease of operation without compromising security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates a copy of the authorization credentials in the form of an authorization token. Rather than requiring the second device to present original authentication credentials, a copied representation (the token) containing the essential permission information is used. This copy mechanism simplifies the access process for temporary devices while maintaining security through the validated token structure.

Inventive Principle:
Principle #26Copying

3Measurement precision

If authorization information is generated for each device, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveauthorization precisionVSAvoidauthorization management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authorization token serves multiple functions: it acts as a permission credential, an authentication substitute, and an access control key. This multi-functional design allows the system to maintain precise authorization control without creating separate complex mechanisms for each function. The single token structure handles permission verification, device identification, and access control, reducing overall system complexity while maintaining authorization precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10382439B2Information processing system, information processing apparatus, information processing method, and storage medium
Publication Date: 2019.08.13 FUJIFILM BUSINESS INNOVATION CORP
  • US10382439B2 patent drawing
  • US10382439B2 patent drawing
  • US10382439B2 patent drawing

AI summary

An information processing system includes a memory that stores a user and authorization information, indicative of processing permitted for the user to execute with respect to a server on a communication line, in an associated manner; a generating unit that generates second authorization information on the basis of first authorization information associated with a user who uses a first device; a transmitting unit that transmits the second authorization information to a second device located near the first device; a receiving unit that receives data and the second authorization information from the second device; and a requesting unit that requests the server to execute processing using the data, on the basis of the second authorization information.