Smart Device Access Authorization Without Cloud Identity Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT-based systems face challenges in maintaining data integrity and privacy while ensuring secure and user-friendly access, particularly for both local and remote connections, with current solutions often being insufficient in one or both aspects.

Innovation Solution

A computer-implemented system and method for authorizing access to smart devices in a local environment, utilizing a client device, local network node, and remote network node, which generates challenges and authorization codes to ensure secure access tokens are issued without exposing personal information, using asymmetric and symmetric key cryptography for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based authorization systems are used, then remote access can be provided, but personal information is exposed to data breaches

Engineering Contradiction:
Improveremote access capabilityVSAvoiddata breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personal information handling from the cloud-based authorization system and relocates it to the local environment. The personal identifier is processed locally at the client device without being transmitted to or stored in cloud databases, thereby enabling remote access capability while eliminating the data breach risk associated with cloud-based personal information storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a local network node as an intermediary between the client device and the remote network node. This local intermediary processes the personal identifier and generates authorization codes locally, acting as a mediator that prevents direct exposure of personal information to remote cloud systems while still enabling remote access functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing authorization solutions are used, then access control is provided, but user-friendliness is compromised

Engineering Contradiction:
Improveaccess control securityVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the client device to autonomously generate challenges and receive authorization codes without requiring manual intervention. The system automatically processes authorization requests, validates credentials, and issues access tokens, thereby maintaining strong access control security while significantly improving user-friendliness through automated operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by having the client device generate a challenge in advance before the actual authorization request. This pre-generated challenge is then used in the authorization protocol, allowing for streamlined authentication processes that maintain security while improving ease of operation through preparedness rather than reactive processing.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If centralized databases of personal information are used, then authorization can be managed, but data integrity is compromised

Engineering Contradiction:
Improveauthorization managementVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the personal identifier processing from centralized databases and implements it at the local client device. The personal identifier is handled locally during the authorization process without being stored in centralized databases, thereby enabling comprehensive authorization management while preserving data integrity by eliminating the single point of failure that centralized databases represent.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authorization management function across multiple distributed components rather than concentrating it in a single centralized database. The client device, local network node, and remote network node each handle specific parts of the authorization process independently, distributing the workload and data handling responsibilities to maintain data integrity while preserving authorization management capabilities.

Inventive Principle:
Principle #1Segmentation

4Object-affected harmful factors

If complex authorization systems with multiple components are used, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the authorization functionality into a streamlined process that operates primarily at the local client device with minimal involvement from remote systems. By combining the challenge generation, authorization code reception, and access token issuance into a unified local process, the system achieves enhanced security through reduced attack surfaces while minimizing device complexity by eliminating the need for complex multi-component authorization infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4515898B1System and method for authorizing access to smart devices in a local environment
Publication Date: 2026.02.04 INTER IKEA SYST
  • EP4515898B1 patent drawingFigure 1a
  • EP4515898B1 patent drawingFigure 1b
  • EP4515898B1 patent drawingFigure 2

AI summary

A computer-implemented system (100) for authorizing access to one or more smart devices (10) provided in a local environment (20) is disclosed herein. The system (100) comprises a client device (30), a local network node (40), and a remote network node (50). The remote network node (50) is configured generate a link (52) and send it to an address associated with a personal identifier (34) of the client device (30), and in response to the client device (30) having executed the link (52), the client device (30) being configured to receive an authorization code (42a). The authorization code (42a) is locally or remotely validated based on a challenge (32) previously generated by the client device (30). An access token (60) is generated and sent to the client device (30), thereby authorizing the client device (30) access to the one or more smart devices (10) in the local environment (20).