IP Library › Granted Patent US 12,028,456
Granted Patent B2
US 12,028,456 · App. 17/731,455 · Granted Jul 2, 2024

System and method for authorizing access of local and remote client devices to smart devices in a local environment

Inventor: Ted Hallberg (Osby, SE)
Assignee: Inter IKEA Systems B.V.
H04L9/3213H04L9/0819H04L9/0825H04L9/0838H04L9/088H04L9/3271H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,028,456
App. No.
17/731,455
Granted
Jul 2, 2024
Kind
B2
Abstract

A computer-implemented system for authorizing access to one or more smart devices provided in a local environment is disclosed herein. The system comprises a client device, a local network node, and a remote network node. The remote network node is configured generate a link and send it to an address associated with a personal identifier of the client device, and in response to the client device having executed the link, the client device being configured to receive an authorization code. The authorization code is locally or remotely validated based on a challenge previously generated by the client device. An access token is generated and sent to the client device, thereby authorizing the client device access to the one or more smart devices in the local environment.

Claims (71)

1. A computer-implemented system for authorizing access to one or more smart devices provided in a local environment, the computer-implemented system comprising:

a smart mobile communication device comprising memory and a processor provided in, or external to, the local environment;

a local internet of things gateway provided in the local environment;

and a remote cloud-based service provided external to the local environment;

wherein the smart mobile communication device is configured to:

generate a challenge, and

provide the challenge and a personal identifier to the local internet of things gateway upon the smart mobile communication device being provided in the local environment, or to the remote cloud-based service upon the smart mobile communication device being provided external to the local environment;

wherein either one of the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, is configured to:

generate authorization data comprising at least an authorization code; wherein the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, is configured to:

send the personal identifier to the remote cloud-based service; wherein the remote cloud-based service is configured to:

generate a link and send the link to an address associated with the personal identifier;

and wherein either one of the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, is configured to:

in response to the smart mobile communication device having executed the link, send the authorization code to the smart mobile communication device,

receive an access token request from the smart mobile communication device, the access token request comprising the authorization code,

validate the authorization code based on the challenge, and upon successful validation of the authorization code:

generate an access token, and

send the access token to the smart mobile communication device, thereby authorizing the smart mobile communication device access to the one or more smart devices in the local environment.

2. The computer-implemented system according to claim 1 , wherein after receiving the access token, the smart mobile communication device is enabled to send one or more control instructions together with the access token to the one or more smart devices.

3. The computer-implemented system according to claim 2 , wherein the access token comprises an authorization signature and an expiry time, and is associated with a unique smart mobile communication device identifier.

4. The computer-implemented system according to claim 3 , wherein either one of the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, is configured to verify the one or more control instructions by verifying that:

the authorization signature is valid,

the expiry time has not passed, and

the unique smart mobile communication device identifier is associated with the smart mobile communication device.

5. The computer-implemented system according to claim 1 , wherein either one of the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, is configured to:

generate a refresh token being associated with the access token,

send the refresh token to the smart mobile communication device together with the access token, and

send the refresh token to the local internet of things gateway upon being generated by the remote cloud-based service, or send the refresh token to the remote cloud-based service upon being generated by the local internet of things gateway,

wherein the refresh token comprises an expiry time and is associated with a unique smart mobile communication device identifier.

6. The computer-implemented system according to claim 5 , wherein the local internet of things gateway and the remote cloud-based service are configured to maintain a record of each generated refresh token.

7. The computer-implemented system according to claim 6 , wherein the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, is configured to generate a new access token upon the previous access token being invalid, based on data in the record of the refresh token being associated with the previous access token.

8. The computer-implemented system according to claim 5 , wherein the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, is configured to generate a new refresh token upon:

the expiry time of the previous refresh token having passed, or

the smart mobile communication device having requested a new access token using the previous refresh token.

9. The computer-implemented system according to claim 1 , wherein the access token is provided for the smart mobile communication device in the local environment, the local internet of things gateway being configured to generate a local symmetric key, the remote cloud-based service being configured to generate a remote asymmetric key pair including a remote private key and a remote public key, wherein the local internet of things gateway and the remote cloud-based service are configured to perform a key exchange.

10. The computer-implemented system according to claim 9 , wherein the remote cloud-based service is further configured to generate a complete encryption key by means of the local symmetric key and a remote symmetric key stored at the remote cloud-based service.

11. The computer-implemented system according to claim 1 , wherein the authorization data further comprises one or more randomly generated numbers, wherein the link is based on the one or more randomly generated numbers.

12. The computer-implemented system according to claim 11 , wherein in response to the smart mobile communication device having executed the link, the remote cloud-based service is configured to:

discard the one or more randomly generated numbers, and

send the authorization code to the smart mobile communication device.

13. The computer-implemented system according to claim 1 , wherein the access token request further comprises a verifier associated with the challenge, and wherein validating the authorization code involves:

generating a control challenge for the authorization code based on the verifier, and

comparing said generated control challenge to the challenge.

14. The computer-implemented system according to claim 1 , wherein the link identifies a resource at the remote cloud-based service, and wherein execution of the link by the smart mobile communication device triggers the identified resource at the remote cloud-based service, thereby validating the integrity of the link.

15. The computer-implemented system according to claim 1 , wherein the one or more smart devices are selected from the group consisting of home furnishing, home appliances, home equipment, office furnishing, office appliances and office equipment.

16. A computer-implemented method for authorizing access to one or more smart devices provided in a local environment, the method involving:

by a smart mobile communication device provided in, or external to, the local environment:

generating a challenge;

and providing the challenge and a personal identifier to a local internet of things gateway provided in the local environment upon the smart mobile communication device being provided in the local environment, or to a remote cloud-based service provided external to the local environment upon the smart mobile communication device being provided external to the local environment;

by either one of the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment:

generating authorization data comprising at least an authorization code;

by the local internet of things gateway, upon the smart mobile communication device being provided in the local environment:

sending the personal identifier to the remote cloud-based service;

by the remote cloud-based service:

generating a link, and sending the link to an address associated with the personal identifier;

and by either one of the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment:

in response to the smart mobile communication device having executed the link, sending the authorization code to the smart mobile communication device;

receiving an access token request from the smart mobile communication device, the access token request comprising the authorization code,

validating the authorization code based on the challenge, and

upon successful validation of the authorization code:

generating an access token, and

sending the access token to the smart mobile communication device, thereby authorizing the smart mobile communication device access to the one or more smart devices in the local environment.

17. The computer-implemented method according to claim 16 , wherein after receiving the access token, the smart mobile communication device sends one or more control instructions together with the access token to the one or more smart devices.

18. The computer-implemented method according to claim 17 , wherein the access token comprises an authorization signature and an expiry time, and is associated with a unique smart mobile communication device identifier, wherein the method further involves, by the local internet of things gateway, upon the smart mobile communication device being provided in the local environment, or by the remote cloud-based service, upon the smart mobile communication device being provided external to the local environment, verifying the one or more control instructions by verifying:

the validity of the authorization signature,

that the expiry time has not passed, and

that the unique smart mobile communication device identifier is associated with the smart mobile communication device.

19. The computer-implemented method according to claim 16 , wherein the access token is provided for the smart mobile communication device in the local environment, the method further involving:

by the local internet of things gateway, generating a local symmetric key,

by the remote cloud-based service, generating a remote asymmetric key pair including a remote private key and a remote public key, and

performing a key exchange between the remote cloud-based service and the local internet of things gateway.

20. The computer-implemented method according to claim 19 , wherein the method further involves, by the remote cloud-based service, generating a complete encryption key by means of the local symmetric key and a remote symmetric key stored at the remote cloud-based service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2022
From: HALLBERG, TED
To: INTER IKEA SYSTEMS B.V.
Reel/Frame 059772/0815 →
Priority Claims (1)
EP 21157054 · Feb 15, 2021 · regional
Continuity (2)
Continuation In Part PCTEP2022053525 · Feb 14, 2022
Related Publication 20220329429A1 · Oct 13, 2022