US2019289003A1PendingUtilityA1

Access Control for Internet of Things Devices

Assignee: GOOGLE LLCPriority: Aug 9, 2015Filed: May 31, 2019Published: Sep 19, 2019
Est. expiryAug 9, 2035(~9 yrs left)· nominal 20-yr term from priority
H04L 63/101H04W 4/70H04W 12/06H04L 63/166H04W 12/08H04L 63/18H04L 63/0428H04L 67/12H04L 63/0876H04L 63/108H04W 4/80H04L 67/125H04W 12/003H04W 12/50Y04S40/18
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Requesting, by a requesting device, from an Internet of Things (IoT) device, an IoT device identifier over a communication link between the devcies. Requesting, by the requesting device from an authorization device over a communication network including at least one TCP/IP link, authorization to command the IoT device to perform an action. Determining, by the authorization device, an authorization of the requesting device to command the identified IoT device to perform the requested action based on the IoT device identifier, the requesting device identifier, and the command. For a requesting device determined authorized, transmitting an encrypted authorization to the requesting device over the communication network. Relaying, by the requesting device to the IoT device via the first communication link, the authorization. Decrypting, by the IoT device, the authorization and performing the action specified therein.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A computer-implemented method to control communication between devices, comprising:
 requesting, by a first device, from an authorization device and via a first communication network, an action to be performed by a second device;   determining, by the authorization device in response to receiving the request, an authorization of the first device to request that the second device perform the action;   for the first device determined by the authorization device to be authorized to request that the second device perform the action, communicating, by the authorization device with the first device over the first communication network, an authorization authorizing the first device to perform the action, the authorization encrypted and secured from decryption by the first device;   relaying, by the first device to the second device via a communication link other than the first communication network, the received transmitted encrypted authorization;   decrypting, by the second device, the relayed authorization;   determining, by the second device, that the decrypted authorization is valid; and   performing, by the second device the authorized action in response to a valid decrypted authorization.   
     
     
         22 . The method of  claim 21 , wherein the second device and the authorization device are not in communication over the first communication network. 
     
     
         23 . The method of  claim 21 :
 wherein the second device comprises a beacon;   prior to the requesting, the first device receives a beacon broadcast of the second device comprising a second device identifier; and   the request comprises the second device identifier.   
     
     
         24 . The method of  claim 23 , wherein the beacon is a Bluetooth personal area network (PAN) beacon. 
     
     
         25 . The method of claim  20 , wherein the broadcast is a JavaScript Object Notation (JSON)-formatted request over the Bluetooth PAN. 
     
     
         26 . The method of  claim 21 , wherein the requesting is a Remote Procedure Call (RPC) over the communication network including at least one TCP/IP communication link. 
     
     
         27 . The method of  claim 21 , wherein the authorization expires upon one of a pre-determined condition and a predetermined period of time. 
     
     
         28 . A computer program product, comprising:
 a non-transitory computer-readable storage device having computer-executable program instructions embodied thereon that when executed by a computer cause the computer to:
 request, by a first device, from an authorization device and via a first communication network, an action to be performed by a second device; 
 determine, by the authorization device in response to receiving the request, an authorization of the first device to request that the second device perform the action; 
 for the first device determined by the authorization device to be authorized to request that the second device perform the action, communicate, by the authorization device with the first device over the first communication network, an authorization authorizing the first device to perform the action, the authorization encrypted and secured from decryption by the first device; 
 relay, by the first device to the second device via a communication link other than the first communication network, the received transmitted encrypted authorization; 
 decrypt, by the second device, the relayed authorization; 
 determine, by the second device, that the decrypted authorization is valid; and 
 perform, by the second device the authorized action in response to a valid decrypted authorization. 
   
     
     
         29 . The computer program product of  claim 28 , wherein the second device and the authorization device are not in communication over the first communication network. 
     
     
         30 . The computer program product of  claim 28 :
 wherein the second device comprises a beacon;   prior to the requesting, the first device receives a beacon broadcast of the second device comprising a second device identifier; and   the request comprises the second device identifier.   
     
     
         31 . The computer program product of  claim 30 , wherein the beacon is a Bluetooth personal area network (PAN) beacon. 
     
     
         32 . The computer program product of  claim 31 , wherein the broadcast is a JavaScript Object Notation (JSON)-formatted request over the Bluetooth PAN. 
     
     
         33 . The computer program product of  claim 28 , wherein the requesting is a Remote Procedure Call (RPC) over the communication network including at least one TCP/IP communication link. 
     
     
         34 . The computer program product of  claim 28 , wherein the authorization expires upon one of a pre-determined condition and a predetermined period of time. 
     
     
         35 . A system to control communication between devices, the system comprising:
 at least one storage device; and   at least one processor communicatively coupled to the ay least one storage device, wherein the processor executes application code instructions that are stored in the storage device to cause the system to:
 request, by a first device, from an authorization device and via a first communication network, an action to be performed by a second device; 
 determine, by the authorization device in response to receiving the request, an authorization of the first device to request that the second device perform the action; 
 for the first device determined by the authorization device to be authorized to request that the second device perform the action, communicate, by the authorization device with the first device over the first communication network, an authorization authorizing the first device to perform the action, the authorization encrypted and secured from decryption by the first device; 
 relay, by the first device to the second device via a communication link other than the first communication network, the received transmitted encrypted authorization; 
 decrypt, by the second device, the relayed authorization; 
 determine, by the second device, that the decrypted authorization is valid; and 
 perform, by the second device the authorized action in response to a valid decrypted authorization. 
   
     
     
         36 . The system of  claim 35 , wherein the second device and the authorization device are not in communication over the first communication network. 
     
     
         37 . The system of  claim 35 :
 wherein the second device comprises a beacon;   prior to the requesting, the first device receives a beacon broadcast of the second device comprising a second device identifier; and   the request comprises the second device identifier.   
     
     
         38 . The system of  claim 37 , wherein the beacon is a Bluetooth personal area network (PAN) beacon. 
     
     
         39 . The system of  claim 38 , wherein the broadcast is a JavaScript Object Notation (JSON)-formatted request over the Bluetooth PAN. 
     
     
         40 . The system of  claim 35 , wherein the requesting is a Remote Procedure Call (RPC) over the communication network including at least one TCP/IP communication link.

Join the waitlist — get patent alerts

Track US2019289003A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.