Access Control for Internet of Things Devices
Abstract
Requesting, by a requesting device, from an Internet of Things (IoT) device, an IoT device identifier over a communication link between the devcies. Requesting, by the requesting device from an authorization device over a communication network including at least one TCP/IP link, authorization to command the IoT device to perform an action. Determining, by the authorization device, an authorization of the requesting device to command the identified IoT device to perform the requested action based on the IoT device identifier, the requesting device identifier, and the command. For a requesting device determined authorized, transmitting an encrypted authorization to the requesting device over the communication network. Relaying, by the requesting device to the IoT device via the first communication link, the authorization. Decrypting, by the IoT device, the authorization and performing the action specified therein.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computer-implemented method to control communication between devices, comprising:
requesting, by a first device, from an authorization device and via a first communication network, an action to be performed by a second device; determining, by the authorization device in response to receiving the request, an authorization of the first device to request that the second device perform the action; for the first device determined by the authorization device to be authorized to request that the second device perform the action, communicating, by the authorization device with the first device over the first communication network, an authorization authorizing the first device to perform the action, the authorization encrypted and secured from decryption by the first device; relaying, by the first device to the second device via a communication link other than the first communication network, the received transmitted encrypted authorization; decrypting, by the second device, the relayed authorization; determining, by the second device, that the decrypted authorization is valid; and performing, by the second device the authorized action in response to a valid decrypted authorization.
22 . The method of claim 21 , wherein the second device and the authorization device are not in communication over the first communication network.
23 . The method of claim 21 :
wherein the second device comprises a beacon; prior to the requesting, the first device receives a beacon broadcast of the second device comprising a second device identifier; and the request comprises the second device identifier.
24 . The method of claim 23 , wherein the beacon is a Bluetooth personal area network (PAN) beacon.
25 . The method of claim 20 , wherein the broadcast is a JavaScript Object Notation (JSON)-formatted request over the Bluetooth PAN.
26 . The method of claim 21 , wherein the requesting is a Remote Procedure Call (RPC) over the communication network including at least one TCP/IP communication link.
27 . The method of claim 21 , wherein the authorization expires upon one of a pre-determined condition and a predetermined period of time.
28 . A computer program product, comprising:
a non-transitory computer-readable storage device having computer-executable program instructions embodied thereon that when executed by a computer cause the computer to:
request, by a first device, from an authorization device and via a first communication network, an action to be performed by a second device;
determine, by the authorization device in response to receiving the request, an authorization of the first device to request that the second device perform the action;
for the first device determined by the authorization device to be authorized to request that the second device perform the action, communicate, by the authorization device with the first device over the first communication network, an authorization authorizing the first device to perform the action, the authorization encrypted and secured from decryption by the first device;
relay, by the first device to the second device via a communication link other than the first communication network, the received transmitted encrypted authorization;
decrypt, by the second device, the relayed authorization;
determine, by the second device, that the decrypted authorization is valid; and
perform, by the second device the authorized action in response to a valid decrypted authorization.
29 . The computer program product of claim 28 , wherein the second device and the authorization device are not in communication over the first communication network.
30 . The computer program product of claim 28 :
wherein the second device comprises a beacon; prior to the requesting, the first device receives a beacon broadcast of the second device comprising a second device identifier; and the request comprises the second device identifier.
31 . The computer program product of claim 30 , wherein the beacon is a Bluetooth personal area network (PAN) beacon.
32 . The computer program product of claim 31 , wherein the broadcast is a JavaScript Object Notation (JSON)-formatted request over the Bluetooth PAN.
33 . The computer program product of claim 28 , wherein the requesting is a Remote Procedure Call (RPC) over the communication network including at least one TCP/IP communication link.
34 . The computer program product of claim 28 , wherein the authorization expires upon one of a pre-determined condition and a predetermined period of time.
35 . A system to control communication between devices, the system comprising:
at least one storage device; and at least one processor communicatively coupled to the ay least one storage device, wherein the processor executes application code instructions that are stored in the storage device to cause the system to:
request, by a first device, from an authorization device and via a first communication network, an action to be performed by a second device;
determine, by the authorization device in response to receiving the request, an authorization of the first device to request that the second device perform the action;
for the first device determined by the authorization device to be authorized to request that the second device perform the action, communicate, by the authorization device with the first device over the first communication network, an authorization authorizing the first device to perform the action, the authorization encrypted and secured from decryption by the first device;
relay, by the first device to the second device via a communication link other than the first communication network, the received transmitted encrypted authorization;
decrypt, by the second device, the relayed authorization;
determine, by the second device, that the decrypted authorization is valid; and
perform, by the second device the authorized action in response to a valid decrypted authorization.
36 . The system of claim 35 , wherein the second device and the authorization device are not in communication over the first communication network.
37 . The system of claim 35 :
wherein the second device comprises a beacon; prior to the requesting, the first device receives a beacon broadcast of the second device comprising a second device identifier; and the request comprises the second device identifier.
38 . The system of claim 37 , wherein the beacon is a Bluetooth personal area network (PAN) beacon.
39 . The system of claim 38 , wherein the broadcast is a JavaScript Object Notation (JSON)-formatted request over the Bluetooth PAN.
40 . The system of claim 35 , wherein the requesting is a Remote Procedure Call (RPC) over the communication network including at least one TCP/IP communication link.Join the waitlist — get patent alerts
Track US2019289003A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.