EP4725272A1 - Authorizing a controller device which has registered interest to control a controllable device - Google Patents
Authorizing a controller device which has registered interest to control a controllable deviceInfo
- Publication number
- EP4725272A1 EP4725272A1 EP24728642.0A EP24728642A EP4725272A1 EP 4725272 A1 EP4725272 A1 EP 4725272A1 EP 24728642 A EP24728642 A EP 24728642A EP 4725272 A1 EP4725272 A1 EP 4725272A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- message
- controllable
- controller device
- controllable system
- controller
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H05—ELECTRIC TECHNIQUES NOT OTHERWISE PROVIDED FOR
- H05B—ELECTRIC HEATING; ELECTRIC LIGHT SOURCES NOT OTHERWISE PROVIDED FOR; CIRCUIT ARRANGEMENTS FOR ELECTRIC LIGHT SOURCES, IN GENERAL
- H05B47/00—Circuit arrangements for operating light sources in general, i.e. where the type of light source is not relevant
- H05B47/10—Controlling the light source
- H05B47/175—Controlling the light source by remote control
- H05B47/19—Controlling the light source by remote control via wireless transmission
-
- H—ELECTRICITY
- H05—ELECTRIC TECHNIQUES NOT OTHERWISE PROVIDED FOR
- H05B—ELECTRIC HEATING; ELECTRIC LIGHT SOURCES NOT OTHERWISE PROVIDED FOR; CIRCUIT ARRANGEMENTS FOR ELECTRIC LIGHT SOURCES, IN GENERAL
- H05B47/00—Circuit arrangements for operating light sources in general, i.e. where the type of light source is not relevant
- H05B47/10—Controlling the light source
- H05B47/175—Controlling the light source by remote control
- H05B47/196—Controlling the light source by remote control characterised by user interface arrangements
- H05B47/1965—Controlling the light source by remote control characterised by user interface arrangements using handheld communication devices
-
- H—ELECTRICITY
- H05—ELECTRIC TECHNIQUES NOT OTHERWISE PROVIDED FOR
- H05B—ELECTRIC HEATING; ELECTRIC LIGHT SOURCES NOT OTHERWISE PROVIDED FOR; CIRCUIT ARRANGEMENTS FOR ELECTRIC LIGHT SOURCES, IN GENERAL
- H05B47/00—Circuit arrangements for operating light sources in general, i.e. where the type of light source is not relevant
- H05B47/10—Controlling the light source
- H05B47/175—Controlling the light source by remote control
- H05B47/198—Grouping of control procedures or address assignation to light sources
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Selective Calling Equipment (AREA)
Abstract
A controllable system (1) is configured to detect user interaction with, e.g. a button (8) of, the controllable system and obtain one or more identifiers associated with one or more interested controller devices (21,31) which have previously registered interest for controlling one or more controllable systems of a predetermined system type. The controllable system is further configured to, upon detecting the user interaction, transmit a message which comprises access information to each of the one or more interested controller devices based on the one or more identifiers, receive a further message from one of the controller devices, and authorize this controller device to control the controllable system over a network if the further message is determined to comprise the access information.
Description
AUTHORIZING A CONTROLLER DEVICE WHICH HAS REGISTERED INTEREST TO
CONTROL A CONTROLLABLE DEVICE
FIELD OF THE INVENTION
The invention relates to a controllable system which is controllable by a controller device over a network after said controller device has been authorized and relates to such a controller device.
The inventions further relates to a method of authorizing a controller device to control a controllable system over a network and to a method of controlling a controllable system over a network.
The invention also relates to one or more computer program products enabling a computer system to perform one or more of such methods.
BACKGROUND OF THE INVENTION
Connected systems such as the Hue lighting system can typically be controlled with an app running on a mobile device. To prevent that just anyone is able to use this app on their mobile device to control a controllable system that they do not own, access control is normally implemented. For example, in the Hue system, a user typically pairs their app with a bridge in their home by letting the app search for bridges and at the same time pressing a button on the bridge, thereby using as proof of ownership a button press on the bridge when the app wants to communicate to the bridge. This button is referred to as “Push Link button” in the Hue system.
WO 2021/136706 Al discloses that since it may be cumbersome for users to press the button on the bridge, e.g. if the bridge is located at a location that is difficult to access and hidden, the user may be allowed to interact with a light control device, e.g. a light switch, to provide access rights to a new device and/or application.
In both cases, users should interact with the controllable system at around the same time as letting the app search for controllable systems and this timing is important. However, due to the required timing, users are regularly not able to find their bridge, e.g. because the time between pressing the button on the bridge and starting the search is relatively long, possibly in combination with delayed network messages.
WO 2016/036453 Al discloses a computing device, comprising: a processor configured with processor-executable instructions to perform operations comprising: receiving, from a proximity broadcast receiver, a sighting message that includes a secure identifier of a wireless identity transmitter; determining whether the proximity broadcast receiver is authorized to receive identification information for provisioning a device associated with the wireless identity transmitter based on stored profile information corresponding to the secure identifier and the proximity broadcast receiver in response to receiving the sighting message; and transmitting a return message including the identification information for provisioning the device in response to determining that the proximity broadcast receiver is authorized to receive the identification information.
SUMMARY OF THE INVENTION
It is a first object of the invention to provide a system, which can be used to make it simpler to authorize a controller device to control a controllable system.
It is a second object of the invention to provide a method, which can be used to make it simpler to authorize a controller device to control a controllable system.
In a first aspect of the invention, a controllable system which is controllable by a controller device over a network after said controller device has been authorized comprises at least one input interface, at least one transmitter, and at least one processor configured to detect user interaction with said controllable system via said at least one input interface, obtain one or more identifiers associated with one or more interested controller devices, said one or more interested controller devices having previously registered interest for controlling one or more controllable systems of a predetermined system type, upon detecting said user interaction, transmit, via said at least one transmitter, a message to each of said one or more interested controller devices based on said one or more identifiers, said message comprising access information, receive a further message from said controller device via said at least one input interface, said controller device being one of said one or more interested controller devices, and authorize said controller device to control said controllable system if said further message is determined to comprise said access information.
By allowing interested controller devices to register interest for controlling one or more controllable systems of a predetermined system type well before the user interaction with the controllable system occurs, the likelihood that users are not able to find a new controllable system on their controller device decreases. As an additional advantage, the
controller device does not need to perform polling, thereby reducing network bandwidth consumption.
The access information may comprise an access token, for example. Said at least one processor may be configured receive a control command and execute said control command, said control command being included in said further message or in a second message received from said controller device. The network is typically a local network. The controllable system may comprise a single device or multiple devices. The controllable system may be a lighting system, a home security system, a Heating, Ventilation and Air- Conditioning (HVAC) system, or a controllable device in such a system, for example. The user interaction may comprise the user pressing a physical button on the controllable system.
Said one or more identifiers may comprise one or more service identifiers and said at least one processor may be configured to obtain said one or more service identifiers by discovering one or more services of a predetermined service type. Network service discovery is supported by default by most mobile devices, e.g. in Apple’s Bonjour and Google Android’s Network Service Discovery (NSD) protocols. For example, an app running on the controller device may register a discoverable network service on the local network and when a user presses the (Push Link) button on the controllable system, the controllable system may then transmit (e.g. multicast) a message to the registered network services on the local network. An identifier of a service may comprise a name of the service and/or an IP address and port number of the service, for example.
Said one or more interested controller devices may comprise multiple interested controller devices and each of said multiple interested controller devices may be transmitted the same access information. This allows the access information to be multicast.
Said at least one processor may be configured to receive, via said at least one input interface, another message from another controller device of said multiple interested controller devices, said other message being received after said further message, said other message comprising said access information, and refuse authorization of said other controller device. This may be used as security measure. In this case, although the user may take some time between interacting with the controllable system and causing the controller device to use the obtained access information, the more time between these events, the more likely it is that another controller device uses the access information and that further user interaction needs to occur.
If this security measure is implemented, it may be beneficial to make the controller device transmit the further message as soon as possible after receiving the
message. If this security measure is implemented, it may be beneficial to not represent the controllable system in an app on the controller device before an acceptance message has been received by the controller device from the controllable system.
Said controllable system may further comprise at least one control interface and said at least one processor may be configured to control, via said at least one control interface, one or more light sources of said controllable system or of another system in response to said control command. Said controllable system may be a lighting system or a controllable device in a lighting system. Said controllable device may be a light controller/bridge, an HDMI module (e.g. a HueSync box), or a lighting device, for example.
Said access information may specify an access level and/or an access duration. For example, the user of the first controller device to be authorized may become admin user with the highest access level and unlimited access duration and users of further controller devices to be authorized may get a lower access level and/or lower access duration, which may then be specified in the access information.
In a second aspect of the invention, a controller device which is able to control a controllable system over a network after said controller device has been authorized comprises at least one receiver, at least one transmitter, and at least one processor configured to register, on said network, interest for controlling one or more controllable systems of a predetermined system type, receive a message from said controllable system via said at least one receiver, said controllable system transmitting said message upon detecting user interaction with said controllable system, said message comprising access information, and transmit, via said at least one transmitter, one or more further messages to said controllable system to obtain authorization for controlling said controllable system and to control said controllable system, said one or more further messages comprising said access information.
Said at least one processor of said controller device may be configured to register said interest for controlling one or more controllable systems of said predetermined system type by registering a network service of a predetermined service type. Each controllable system of the same system type may register a network service of the same service type but with a different name.
Said at least one processor of said controller device may be configured to obtain said authorization and control said controllable system with a single message, said single message comprising a control command and said access information. For example, each message which comprises a control command may further be required to comprise an access token and this access token may be comprised in the access information.
Said at least one processor of said controller device may be configured to check whether an identifier of said controllable system is already stored in relation to said controller device and/or request a confirmation from a user of said controller device that said controllable system should be controllable with said controller device, and store said identifier of said controllable system and said access information in relation to said controller device in dependence on a result of said check and/or receipt of said confirmation.
If multiple controllable systems of the same predetermined system type are available on the network, it may be beneficial to ask for user confirmation, e.g. in case the user only wants to control one of these controllable systems, and/or check whether it is already possible to control the controllable system with this controller device, before adding the controllable system to a control app on the controller device.
In a third aspect of the invention, a method of authorizing a controller device to control a controllable system over a network comprises detecting user interaction with said controllable system, obtaining one or more identifiers associated with one or more interested controller devices, said one or more interested controller devices having previously registered interest for controlling one or more controllable systems of a predetermined system type, upon detecting said user interaction, transmitting a message to each of said one or more interested controller devices based on said one or more identifiers, said message comprising access information, receiving a further message from said controller device, said controller device being one of said one or more interested controller devices, and authorizing said controller device to control said controllable system if said further message is determined to comprise said access information. Said method may be performed by software running on a programmable device. This software may be provided as a computer program product.
In a fourth aspect of the invention, a method of controlling a controllable system over a network comprises registering on said network, interest for controlling one or more controllable systems of a predetermined system type, receiving a message from said controllable system, said controllable system transmitting said message upon detecting user interaction with said controllable system, said message comprising access information, and transmitting one or more further messages to said controllable system to obtain authorization for controlling said controllable system and to control said controllable system, said one or more further messages comprising said access information. Said method may be performed by software running on a programmable device. This software may be provided as a computer program product.
Moreover, a computer program for carrying out the methods described herein, as well as a non-transitory computer readable storage-medium storing the computer program are provided. A computer program may, for example, be downloaded by or uploaded to an existing device or be stored upon manufacturing of these systems.
A non-transitory computer-readable storage medium stores at least a first software code portion, the first software code portion, when executed or processed by a computer, being configured to perform executable operations for authorizing a controller device to control a controllable system over a network.
The executable operations comprise detecting user interaction with said controllable system, obtaining one or more identifiers associated with one or more interested controller devices, said one or more interested controller devices having previously registered interest for controlling one or more controllable systems of a predetermined system type, upon detecting said user interaction, transmitting a message to each of said one or more interested controller devices based on said one or more identifiers, said message comprising access information, receiving a further message from said controller device, said controller device being one of said one or more interested controller devices, and authorizing said controller device to control said controllable system if said further message is determined to comprise said access information.
A non-transitory computer-readable storage medium stores at least a second software code portion, the second software code portion, when executed or processed by a computer, being configured to perform executable operations for controlling a controllable system over a network comprises registering on said network.
The executable operations comprise registering on said network, interest for controlling one or more controllable systems of a predetermined system type, receiving a message from said controllable system, said controllable system transmitting said message upon detecting user interaction with said controllable system, said message comprising access information, and transmitting one or more further messages to said controllable system to obtain authorization for controlling said controllable system and to control said controllable system, said one or more further messages comprising said access information.
As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as a device, a method or a computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.) or an embodiment combining software and hardware aspects that may all
generally be referred to herein as a "circuit", "module" or "system." Functions described in this disclosure may be implemented as an algorithm executed by a processor/microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied, e.g., stored, thereon.
Any combination of one or more computer readable medium(s) may be utilized. The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer readable storage medium may include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present invention, a computer readable storage medium may be any tangible medium that can contain, or store, a program for use by or in connection with an instruction execution system, apparatus, or device.
A computer readable signal medium may include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium may be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber, cable, RF, etc., or any suitable combination of the foregoing. Computer program code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the
remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).
Aspects of the present invention are described below with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustrations and/or block diagrams, and combinations of blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor, in particular a microprocessor or a central processing unit (CPU), of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer, other programmable data processing apparatus, or other devices create means for implementing the functions/acts specified in the flowchart and/or block diagram block or blocks.
These computer program instructions may also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function/act specified in the flowchart and/or block diagram block or blocks.
The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions/acts specified in the flowchart and/or block diagram block or blocks.
The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of devices, methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example,
two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and/or flowchart illustrations, and combinations of blocks in the block diagrams and/or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.
BRIEF DESCRIPTION OF THE DRAWINGS
These and other aspects of the invention are apparent from and will be further elucidated, by way of example, with reference to the drawings, in which:
Fig. l is a block diagram of an embodiment of the controllable system and of an embodiment of the controller device;
Fig. 2 is a flow diagram of first embodiments of the methods of authorizing a controller device to control a controllable system and controlling a controllable system;
Fig. 3 shows an example of communication between the devices of Fig. 1 in a first implementation of the devices;
Fig. 4 is a flow diagram of a second embodiment of the method of authorizing a controller device to control a controllable system;
Fig. 5 is a flow diagram of a third embodiment of the method of authorizing a controller device to control a controllable system;
Fig. 6 shows an example of communication between the devices of Fig. 1 in a second implementation of the devices;
Fig. 7 shows an example communication between the devices of Fig. 1 in a third implementation of the devices;
Fig. 8 is a flow diagram of a second embodiment of the method of controlling a controllable system; and
Fig. 9 is a block diagram of an exemplary data processing system for performing the method of the invention.
Corresponding elements in the drawings are denoted by the same reference numeral.
DETAILED DESCRIPTION OF THE EMBODIMENTS
Fig. 1 shows an embodiment of the controllable system and of an embodiment of the controller device. The controllable system is controllable by the controller device over
a network after the controller device has been authorized. The network may comprise a wireless part and/or a wired part. The network is typically a local network. Controller devices 21 and 31 may be mobile devices such mobile phones or tablets. Controller devices 21 and 31 each comprise a receiver 23, a transmitter 24, a processor 25, memory 27, and a touchscreen display 29.
Controllable systems 1 and 11 may each comprise a single device or multiple devices. Controllable systems 1 and 11 may each be a lighting system, a home security system, a Heating, Ventilation and Air-Conditioning (HVAC) system, or a controllable device in such a system, for example. Examples of controllable devices in a lighting system are a light controller/bridge, a lighting device, and an HDMI module (e.g. a Hue Sync Box). An example of a controllable device in a home security system is an IP camera. Controllable systems 1 and 11 each comprise a receiver 3, a transmitter 4, a processor 5, memory 7, and a button 8.
The processor 5 is configured to detect user interaction with the controllable system 1 via the button 8 and obtain one or more identifiers associated with one or more interested controller devices. The one or more interested controller devices have previously registered interest for controlling one or more controllable systems of a predetermined system type. In an alternative embodiment, user interaction with the controllable system is detected via a different input interface.
The processor 5 is further configured to, upon detecting the user interaction, transmit, via the transmitter 4, a message to each of the one or more interested controller devices, e.g. controller device 21 and/or controller device 31, based on the one or more identifiers. The message comprises access information. If the one or more interested controller devices comprise multiple interested controller devices, each of the multiple interested controller devices may be transmitted the same access information.
The processor 5 is further configured to receive a further message from one of these one or more controllable systems via the receiver 3 to authorize the controller device to control the controllable system if (when) the further message is determined to comprise the access information. Controlling the controllable system may cause the controllable system to transmit commands to one or more other systems. For example, the controllable system may be a light controller/bridge and the one or more other systems may be one or more lighting devices.
The processor 25 is configured to register, on the network, interest for controlling one or more controllable systems of a predetermined system type and receive, via
the receiver 23, a message from a controllable system, e.g. controllable system 1 or 11, which transmitted the message upon detecting user interaction with the controllable system. The interest may be registered on the network by the processor 25 by registering a service on the network. The service may be registered on a network device, e.g. domain name server 43, or on the controller device itself. In both cases, other devices connected to the network are able to access the service. The message comprises access information.
The processor 25 is further configured to transmit, via the transmitter 24, one or more further messages to the controllable system to obtain authorization for controlling the controllable system and to control the controllable system. The one or more further messages comprise the access information.
In the embodiment of the controllable system shown in Fig. 1, the controllable systems 1 and 11 comprise one processor 5. In an alternative embodiment, the controllable systems 1 and 11 comprise multiple processors. The processor 5 may be a general-purpose processor, e.g. ARM-based, or an application-specific processor. The processor 5 may run a Unix-based operating system for example. The memory 7 may comprise one or more memory units. The memory 7 may comprise one or more hard disks and/or solid-state memory, for example.
The receiver 3 and the transmitter 4 may use one or more wired or wireless communication technologies to communicate over the network, for example. In an alternative embodiment, multiple receivers and/or multiple transmitters are used instead of a single receiver and a single transmitter. In the embodiment shown in Fig. 1, a separate receiver and a separate transmitter are used. In an alternative embodiment, the receiver 3 and the transmitter 4 are combined into a transceiver. The controllable system 1 may comprise other components typical for a controllable system such as a power connector. The invention may be implemented using a computer program running on one or more processors.
In the embodiment of the controller device shown in Fig. 1, the controller devices 21 and 31 comprises one processor 25. In an alternative embodiment, the controller devices 21 and 31 comprises multiple processors. The processor 25 may be a general-purpose processor, e.g. from ARM or Qualcomm or an application-specific processor. The processor 25 may run an Android or iOS operating system for example. The display 29 may comprise an LCD or OLED display panel, for example. The memory 27 may comprise one or more memory units. The memory 27 may comprise solid state memory, for example.
The receiver 23 and the transmitter 24 may use one or more wired or wireless communication technologies to communicate over the network, for example. In an alternative
embodiment, multiple receivers and/or multiple transmitters are used instead of a single receiver and a single transmitter. In the embodiment shown in Fig. 1, a separate receiver and a separate transmitter are used. In an alternative embodiment, the receiver 23 and the transmitter 24 are combined into a transceiver. The controller devices 21 and 31 may comprise other components typical for a controller device such as a battery and a power connector. The invention may be implemented using a computer program running on one or more processors.
A first embodiment of the method of authorizing a controller device to control a controllable system over a network and a first embodiment of the method of controlling a controllable system over a network are shown in Fig. 2. The former method may be performed by the controllable systems 1 and 11 of Fig. 1, for example. The latter method may be performed by the controller devices 21 and 31 of Fig. 1, for example.
A step 111 comprises the controller device registering over the network, interest for controlling one or more controllable systems of a predetermined system type. Step 111 may comprise an app on the controller device registering a network service of a predetermined service type. Each controllable system of the same system type may register a network service of the same service type but with a different name. Step 111 may be performed by the controller device after a user has started a (e.g. light) control application on the controller device for the first time, for example.
A step 101 comprises the controllable system detecting user interaction with the controllable system, e.g. the pressing of a button on the controllable system. A user may interact with the controllable system immediately after starting a control application on the controller device for the first time, but this interaction typically occurs somewhat later.
Steps 103 and 105 are performed upon detecting user interaction in step 101. Step 103 comprises the controllable system obtaining one or more identifiers associated with one or more interested controller devices. The one or more interested controller devices have previously registered interest for controlling one or more controllable systems of a predetermined system type in step 111. The one or more identifiers may comprise one or more service identifiers, for example. Step 103 may comprise discovering one or more services of a predetermined service type, for example. An identifier of a service may comprise a name of the service and/or an IP address and port number of the service, for example. An IP address and port number of the service may be obtained based on the name of the service.
Step 105 comprises the controllable system transmitting a message to each of the one or more interested controller devices based on the one or more identifiers obtained in step 103. The message comprises access information, e.g. an access token. The access information may specify an access level and/or an access duration. For example, the user of the first controller device to be authorized may become admin user with the highest access level and unlimited access duration and users of further controller devices to be authorized may get a lower access level and/or lower access duration, which may then be specified in the access information.
For instance, only the admin user of a lighting system may be able to add and remove lighting devices and rooms/zones to/from the lighting system. The access level and/or access duration of the further controller devices may configured by the admin user. A step 113 comprises the controller device receiving the message from the controllable system. The message may be received by the app which registered the service.
A step 115 comprises the controller device transmitting one or more further messages to the controllable system to obtain authorization for controlling the controllable system and to control the controllable system. The one or more further messages comprise the access information. The controller device may obtain the authorization and control the controllable system with a single message which comprises a control command and the access information. For example, each message which comprises a control command may further be required to comprise an access token and this access token may be comprised in the access information. A step 107 comprises the controllable system receiving the one or more further messages from the controller device.
A step 109 comprises the controllable system authorizing the controller device to control the controllable system if the one or more further messages received in step 107 are determined to comprise the access information. Additionally, one or more steps of one or more of the embodiments of Figs. 4, 5, and 8 may be added to the embodiment of Fig. 2.
Fig. 3 shows an example of communication between the devices of Fig. 1 in a first implementation of the devices. In this example, the controllable system 1 of Fig. 1 performs steps 101 to 109 of Fig. 2 and controller device 21 performs steps 111 to 115 of Fig. 2. In this example, DNS Service Discovery (DNS-SD) is used to discover services. DNS-SD is used by Apple’s Bonjour and Google Android’s Network Service Discovery (NSD) protocols, for example.
In step 111 of Fig. 2, with message 201, the controller device 21 registers a network service of a predetermined service type at DNS server 43, e.g. after a user has started
a (e.g. light) control application on the controller device for the first time. Later, a user 45 interacts with the controllable system 1 with user interaction 202, e.g. presses a button on the controllable system 1. After the controllable system 1 detects this interaction in step 101 of Fig. 2, it performs step 103 of Fig. 2. The controllable system 1 transmits a message 203 to the DNS server 43 to discover network services of the predetermined service type and receives a message 204 from the DNS server 43 indicating one or more identifiers associated with one or more interested controller devices, including an identifier associated with controller device 21.
The controllable system 1 then transmits a message 205 in step 105 of Fig. 2, which is received by the controller device 21 in step 113 of Fig. 2. The message 205 comprises access information, e.g. an access token that can be exchanged for access to the system without any further user interaction. After receiving message 205, the controller device 21 optionally requests, with a request 206, a confirmation from the user 45 that controllable system 1 should be controllable with controller device 21. If the user 45 then provides confirmation 207, the controller device 21 stores the identifier of controllable system 1 and the access information in a memory such that the user 45 can control the controllable system 1 with controller device 21, e.g. by using an app running on controller device 21.
When the user later provides user interaction 208 to the controller device 21 in relation to controllable system 1, the controller device 21 transmits a message 209 to the controllable system in step 115 of Fig. 2, which is received by the controllable system 1 in step 107 of Fig. 2. The message 209 comprises the stored access information that was included in message 205 and a control command that is determined based on the user interaction 208. The controllable system 1 then authorizes the controller device 21 to control the controllable system 1 in step 109 of Fig. 2 and executes the control command.
A second embodiment of the method of authorizing a controller device to control a controllable system over a network is shown in Fig. 4. The second embodiment of Fig. 4 is an extension of the first embodiment of Fig. 2. In the embodiment of Fig. 4, a step 131 is performed after step 109 of Fig. 2. Step 131 comprises executing a control command. The control command is included in the one or more further messages received in step 109. The control command and the access information may be included in a single message or in different messages.
Step 131 may comprise controlling one or more light sources of the controllable system, e.g. if the controllable system comprises a lighting device, in response to
the control command. If the controllable system is a controllable device that does not comprise a light source, e.g. a light controller/bridge, step 131 may comprise controlling one or more light sources of another system that does comprise a light source, e.g. a lighting device, in response to the control command. Additionally, one or more steps of one or more of the embodiments of Fig. 5 may be added to the embodiment of Fig. 4.
A third embodiment of the method of authorizing a controller device to control a controllable system over a network is shown in Fig. 5. The third embodiment of Fig. 5 is an extension of the first embodiment of Fig. 2. In the embodiment of Fig. 5, step 105 of Fig. 2 is implemented by a step 141 and steps 143 and 145 are performed after step 109 of Fig. 2. Step 141 comprises the controllable system, upon detecting the user interaction, transmitting a message to multiple interested controller devices based on the one or more identifiers obtained in step 103, e.g. controller devices 21 and 31 of Fig. 1. Each of the multiple interested controller devices is transmitted the same access information, e.g. access token.
Step 143 comprises receiving another message from another controller device of the multiple interested controller devices. This other message is received after the further message was received in step 107 and also comprises the access information. Step 145 comprises refusing authorization of the other controller device, because the access information can only be used by one controllable system in the embodiment of Fig. 5. Additionally, one or more steps of one or more of the embodiments of Fig. 4 may be added to the embodiment of Fig. 5.
In the embodiment of Fig. 5, a controller device transmitting access information is not sufficient for it to be authorized to control the controllable device. In the embodiment of Fig. 5, it may be beneficial to make the controller device transmit the further message as soon as possible after receiving the message. In the embodiment of Fig. 5, it may be beneficial not to represent the controllable system in an app on the controller device before an acceptance message has been received by the controller device from the controllable system.
Fig. 6 shows an example of communication between the devices of Fig. 1 in a second implementation of the devices. In this example, like in the example of Fig. 3, DNS Service Discovery (DNS-SD) is used to discover services. The communication with respect to controller device 21 as shown in Fig. 3 also occurs in the example of Fig. 6. In the example of Fig. 6, the controllable system 1 transmits an acceptance message 217 to indicate to the controller device 21 that the controller device 21 has been authorized to control the
controllable system 1, which means that the controller device 21 is able to use the access information to control the controllable system 1.
In the example of Fig. 6, communication relating to a second controller device 31 of Fig. 1 is also shown. In this example, the controller device 31 performs steps 111 to 115 of Fig. 2 and the controllable system 1 of Fig. 1 performs steps 101 to 109 and steps 141 to 145 of Fig. 5. The controller device 31 first registers a network service of the predetermined service type at DNS server 43 with message 211, e.g. after a user has started a (e.g. light) control application on the controller device 31 for the first time.
In the example of Fig. 6, the message 204 received by the controllable system 1 does not only include an identifier associated with controller device 21, but also an identifier associated with controller device 31. The controllable system 1 does not only transmit message 205 to controller device 21 but also transmits a message 215 to controller device 31. In this second implementation, the message 205 and the message 215 comprise the same access information, e.g. access token.
Sometime after the controller device 21 has transmitted message 209 to controllable system 1 and the controllable system 1 has accepted the access information, the controller device 31 transmits a message 218 to the controllable system 1, which is received by the controllable system 1 in step 143 of Fig. 5. The message 218 comprises the stored access information that was included in message 215 and a further control command. This further control command may be determined based on interaction of the user 45 or of a different user with the controllable system 31.
In this second implementation, the access information can only be used for one controller device. Therefore, the controllable system 1 does not authorize the controller device 31 to control the controllable system 1 and transmits a refusal message 219 in step 145 of Fig. 5 to indicate to the controller device 31 that the controller device 31 has not been authorized to control the controllable system 1. The controller device 31 can then repeat steps 111 to 115 to obtain usable access information and control the controllable system 1.
Fig. 7 shows an example communication between the devices of Fig. 1 in a third implementation of the devices. In this example, the controllable system 1 of Fig. 1 performs steps 101 to 109 of Fig. 2 and controller device 21 performs steps 111 to 115 of Fig. 2. In this example, Simple Service Discovery (SSDP) is used to discover services. SSDP is used by the Universal Plug and Play (UPnP) protocol, for example.
In step 111 of Fig. 2, with internal message 221, the controller device 21 registers a network service of a predetermined service type at the controller device 21, e.g.
after a user has started a (e.g. light) control application on the controller device for the first time. Later, a user 45 interacts with the controllable system 1 with user interaction 202, e.g. presses a button on the controllable system 1.
After the controllable system 1 detects this interaction in step 101 of Fig. 2, it performs step 103 of Fig. 2. The controllable system 1 multicasts a message 223 to a group address, to which controller device 21 is listening, to discover network services of the predetermined service type and receives a message 224 from the controller device 21 in response. The message 224 includes an identifier associated with controller device 21.
The controllable system 1 may also receive messages from other controller devices which have registered a network service of the predetermined service type; this is not shown in Fig. 7. After this interaction and communication, message 205, interactions 206- 208, and message 208 are the same in the example of Fig. 7 as in the example of Fig. 3.
A second embodiment of the method of controlling a controllable system over a network is shown in Fig. 8. The second embodiment of Fig. 8 is an extension of the first embodiment of Fig. 2. In the embodiment of Fig. 8, steps 161, 163, 165, and 167 are performed between steps 113 and 115 of Fig. 2. Step 161 comprises checking whether an identifier of the controllable system from which the message was received in step 113 is already stored in a memory, e.g. a non-volatile memory such as a HDD or SSD, in relation to the controller device. If not, step 163 is performed next. The identifier may be included in the message, for example.
Step 163 comprises requesting a confirmation from a user of the controller device that the controllable system should be controllable with the controller device. Step 165 comprises checking whether a confirmation is received from the user. If so, step 167 is performed next. Step 167 comprises storing the identifier of the controllable system and the access information in the memory. This access information is included in the further message transmitted to the controllable system when step 115 is performed.
Fig. 9 depicts a block diagram illustrating an exemplary data processing system that may perform the method as described with reference to Figs. 2, 4, 5, and 8.
As shown in Fig. 9, the data processing system 300 may include at least one processor 302 coupled to memory elements 304 through a system bus 306. As such, the data processing system may store program code within memory elements 304. Further, the processor 302 may execute the program code accessed from the memory elements 304 via a system bus 306. In one aspect, the data processing system may be implemented as a computer that is suitable for storing and/or executing program code. It should be appreciated,
however, that the data processing system 300 may be implemented in the form of any system including a processor and a memory that is capable of performing the functions described within this specification.
The memory elements 304 may include one or more physical memory devices such as, for example, local memory 308 and one or more bulk storage devices 310. The local memory may refer to random access memory or other non-persistent memory device(s) generally used during actual execution of the program code. A bulk storage device may be implemented as a hard drive or other persistent data storage device. The processing system 300 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the quantity of times program code must be retrieved from the bulk storage device 310 during execution. The processing system 300 may also be able to use memory elements of another processing system, e.g. if the processing system 300 is part of a cloud-computing platform.
Input/output (I/O) devices depicted as an input device 312 and an output device 314 optionally can be coupled to the data processing system. Examples of input devices may include, but are not limited to, a keyboard, a pointing device such as a mouse, a microphone (e.g. for voice and/or speech recognition), or the like. Examples of output devices may include, but are not limited to, a monitor or a display, speakers, or the like. Input and/or output devices may be coupled to the data processing system either directly or through intervening VO controllers.
In an embodiment, the input and the output devices may be implemented as a combined input/output device (illustrated in Fig. 9 with a dashed line surrounding the input device 312 and the output device 314). An example of such a combined device is a touch sensitive display, also sometimes referred to as a “touch screen display” or simply “touch screen”. In such an embodiment, input to the device may be provided by a movement of a physical object, such as e.g. a stylus or a finger of a user, on or near the touch screen display.
A network adapter 316 may also be coupled to the data processing system to enable it to become coupled to other systems, computer systems, remote network devices, and/or remote storage devices through intervening private or public networks. The network adapter may comprise a data receiver for receiving data that is transmitted by said systems, devices and/or networks to the data processing system 300, and a data transmitter for transmitting data from the data processing system 300 to said systems, devices and/or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapter that may be used with the data processing system 300.
As pictured in Fig. 9, the memory elements 304 may store an application 318. In various embodiments, the application 318 may be stored in the local memory 308, the one or more bulk storage devices 310, or separate from the local memory and the bulk storage devices. It should be appreciated that the data processing system 300 may further execute an operating system (not shown in Fig. 9) that can facilitate execution of the application 318. The application 318, being implemented in the form of executable program code, can be executed by the data processing system 300, e.g., by the processor 302. Responsive to executing the application, the data processing system 300 may be configured to perform one or more operations or method steps described herein.
Fig. 9 shows the input device 312 and the output device 314 as being separate from the network adapter 316. However, additionally or alternatively, input may be received via the network adapter 316 and output be transmitted via the network adapter 316. For example, the data processing system 300 may be a cloud server. In this case, the input may be received from and the output may be transmitted to a user device that acts as a terminal.
Various embodiments of the invention may be implemented as a program product for use with a computer system, where the program(s) of the program product define functions of the embodiments (including the methods described herein). In one embodiment, the program(s) can be contained on a variety of non-transitory computer-readable storage media, where, as used herein, the expression “non-transitory computer readable storage media” comprises all computer-readable media, with the sole exception being a transitory, propagating signal. In another embodiment, the program(s) can be contained on a variety of transitory computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media (e.g., read-only memory devices within a computer such as CD-ROM disks readable by a CD-ROM drive, ROM chips or any type of solid-state non-volatile semiconductor memory) on which information is permanently stored; and (ii) writable storage media (e.g., flash memory, floppy disks within a diskette drive or hard-disk drive or any type of solid-state random-access semiconductor memory) on which alterable information is stored. The computer program may be run on the processor 302 described herein.
The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and/or "comprising," when used in this specification, specify the presence of stated features,
integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof.
The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of embodiments of the present invention has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the implementations in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the present invention.
The embodiments were chosen and described in order to best explain the principles and some practical applications of the present invention, and to enable others of ordinary skill in the art to understand the present invention for various embodiments with various modifications as are suited to the particular use contemplated.
Claims
1. A controllable system, said controllable system being controllable by a controller device over a network after said controller device has been authorized, said controllable system comprising: at least one input interface; at least one transmitter; and at least one processor configured to:
- detect user interaction with said controllable system via said at least one input interface,
- obtain identifiers associated with multiple interested controller devices, said multiple interested controller devices having previously registered interest for controlling one or more controllable systems of a predetermined system type,
- upon detecting said user interaction, transmit, via said at least one transmitter, a message to each of said multiple interested controller devices based on said identifiers, said message comprising access information,
- receive a further message from said controller device via said at least one input interface, said controller device being one of said multiple interested controller devices, and
- authorize said controller device to control said controllable system if said further message is determined to comprise said access information, wherein said at least one processor is further configured to:
- receive, via said at least one input interface, another message from another controller device of said multiple interested controller devices, said other message being received after said further message, said other message comprising said access information, and
- refuse authorization of said other controller device.
2. A controllable system as claimed in claim 1, wherein said multiple identifiers comprise one or more service identifiers and said at least one processor is configured to
obtain said one or more service identifiers by discovering one or more services of a predetermined service type.
3. A controllable system as claimed in claim 1 or 2, wherein said access information comprises an access token.
4. A controllable system as claimed in any one of the preceding claims, wherein said at least one processor is configured receive a control command and execute said control command, said control command being included in said further message or in a second message received from said controller device.
5. A controllable system as claim in claim 4, wherein said controllable system further comprises at least one control interface and said at least one processor is configured to control, via said at least one control interface, one or more light sources of said controllable system or of another system in response to said control command.
6. A controllable system as claimed in any one of the preceding claims, wherein said access information specifies an access level and/or an access duration.
7. A method of authorizing a controller device to control a controllable system over a network, said method comprising:
- detecting (101) user interaction with said controllable system;
- obtaining (103) identifiers associated with multiple interested controller devices, said multiple interested controller devices having previously registered interest for controlling one or more controllable systems of a predetermined system type;
- upon detecting said user interaction, transmitting (105) a message to each of said multiple interested controller devices based on said one or more identifiers, said message comprising access information;
- receiving (107) a further message from said controller device, said controller device being one of said multiple interested controller devices;
- authorizing (109) said controller device to control said controllable system if said further message is determined to comprise said access information; wherein the method further comprises:
- receiving another message from another controller device of said multiple interested controller devices, said other message being received after said further message, said other message comprising said access information, and
- refusing authorization of said other controller device.
8. A computer program product for a computing device, the computer program product comprising computer program code to perform the method of claim 7 when the computer program product is run on a processing unit of the computing device.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP23177441 | 2023-06-06 | ||
| PCT/EP2024/064942 WO2024251610A1 (en) | 2023-06-06 | 2024-05-30 | Authorizing a controller device which has registered interest to control a controllable device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4725272A1 true EP4725272A1 (en) | 2026-04-15 |
Family
ID=86693162
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP24728642.0A Pending EP4725272A1 (en) | 2023-06-06 | 2024-05-30 | Authorizing a controller device which has registered interest to control a controllable device |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4725272A1 (en) |
| CN (1) | CN121264174A (en) |
| WO (1) | WO2024251610A1 (en) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016036453A1 (en) | 2014-09-02 | 2016-03-10 | Qualcomm Incorporated | Proximity application discovery and provisioning |
| US10904234B2 (en) * | 2014-11-07 | 2021-01-26 | Privakey, Inc. | Systems and methods of device based customer authentication and authorization |
| WO2021136706A1 (en) | 2020-01-02 | 2021-07-08 | Signify Holding B.V. | A network controller for granting access rights to a set of devices |
-
2024
- 2024-05-30 EP EP24728642.0A patent/EP4725272A1/en active Pending
- 2024-05-30 CN CN202480037619.1A patent/CN121264174A/en active Pending
- 2024-05-30 WO PCT/EP2024/064942 patent/WO2024251610A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| WO2024251610A1 (en) | 2024-12-12 |
| CN121264174A (en) | 2026-01-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN105578470B (en) | A method, device and system for Internet of Things equipment to access network | |
| US10911436B2 (en) | Method and device for registering and certifying device in wireless communication system | |
| CN105652675B (en) | A kind of control method of smart home device, device, terminal and system | |
| JP6467422B2 (en) | Method, apparatus and terminal device for determining control authority of user device | |
| CN107517438B (en) | Method for requesting sharing of Bluetooth device, electronic device and computer storage medium | |
| CN107567009B (en) | Bluetooth device sharing request and control method and device, and computer storage medium | |
| US20150046830A1 (en) | Methods, Device and Social Network Manager for Enabling Interaction with Another Device | |
| CN107708099B (en) | Bluetooth device sharing request and control method and device, and readable storage medium | |
| WO2021135299A1 (en) | Binding method and system for device network configuration, and mobile terminal and storage medium | |
| US11871471B1 (en) | Process for managing reconnections of devices in a network | |
| TW201442524A (en) | Configuring secure wireless networks | |
| US10523763B2 (en) | Communication device, communication method, controlled device, and non-transitory computer readable medium | |
| WO2022105365A1 (en) | Device control method and system, electronic device, and storage medium | |
| CN105898890A (en) | Device searching method and electronic device for supporting the same | |
| CN115412920A (en) | Internet of things equipment binding system, method and device and electronic equipment | |
| TW201605203A (en) | Home control gateway and home control network connection method thereof | |
| WO2017182002A1 (en) | Device control method, apparatus and storage medium | |
| WO2019037581A1 (en) | Method and device for carrying out wireless connection pre-authorization for user equipment | |
| WO2016150191A1 (en) | Data sharing method and device | |
| CN108353069B (en) | Computing Devices and Communication Systems | |
| CN103561063A (en) | Method and terminal for logging onto set top box | |
| CN112152827A (en) | Management method and device of Internet of things equipment, gateway and readable storage medium | |
| CN103546352A (en) | Remote control method and device based on wireless login | |
| WO2019037603A1 (en) | Method and device for carrying out wireless connection pre-authorization for user equipment | |
| US9900660B2 (en) | Password protected stream receivers |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20260107 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |