Authorization Component for IIoT User Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Role-Based Access Control (RBAC) systems in Industrial Internet of Things (IIoT) are inadequate for providing fine-grained access control, leading to exponential role duplication and maintenance issues, which can result in unauthorized information access and security breaches.
Innovation Solution
A computer system that authorizes users based on geographical location and device type, using an authorization component that retrieves user-specific data from a directory to grant or deny access, allowing for more granular control and reducing the complexity and errors associated with RBAC systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Role-Based Access Control (RBAC) is used to provide access control in IIoT systems, then access control functionality is provided, but the system experiences exponential role duplication and maintenance problems
Solution Approach 1:
The patent segments access control into two independent dimensions: geographical location and device type. Instead of creating composite roles for each combination, the system separately manages location-based access rules and device-type-based access rules. This segmentation prevents the exponential proliferation of roles while maintaining fine-grained control capabilities.
Solution Approach 2:
The patent introduces geographical location as an additional dimension for access control beyond traditional device type. By adding this spatial dimension, the system achieves finer granularity in access control without requiring exponential role multiplication, as location-based filtering operates independently from device-type filtering.
2Manufacturing precision
If RBAC is extended to provide fine-grained access control by location and device type, then access control granularity is improved, but the number of roles increases exponentially
Solution Approach 1:
The patent divides access control into separate dimensional filters (geographical location and device type) rather than creating composite roles for each combination. This segmentation allows fine-grained control by applying independent location-based and device-type-based filtering rules, preventing the exponential increase in role quantity while achieving high granularity.
Solution Approach 2:
The patent creates universal access control mechanisms that handle multiple device types and locations through a single framework. The system uses universal location-based access rules and device-type-based access rules that can be applied across multiple contexts without requiring separate roles for each specific combination, thereby reducing the total number of roles needed.
3Ease of operation
If traditional RBAC is used in cloud computing platforms, then basic access control is provided, but fine-grained control for different geographical locations and device types cannot be achieved
Solution Approach 1:
The patent extends traditional RBAC by adding geographical location as a new dimension for access control. This dimensional extension enables fine-grained control over data access based on location without complicating the basic RBAC operation, as the location filter operates as an independent layer over the traditional role-based framework.
Solution Approach 2:
The patent introduces location-based access rules and device-type-based access rules as intermediary filtering layers between the user and the data. These intermediary rules provide fine-grained control by filtering access requests based on location and device type, while maintaining the simplicity of traditional RBAC for basic access control operations.
Data Source
AI summary
A computer system for authorizing a user to process data received from one or more devices includes: an interface component for receiving the data; an application component for receiving requests from the user, the requests including one or more requests to perform data processing operations on at least a subset of the data; a data storage and data access component for storing and access the data; one or more evaluation components for processing the data; and an authorization component for granting or denying to the user access to process at least a subset of the data, a grant or denial being based on user specific data stored in a user directory for a registered user. The user specific data includes data on a geographical location associated with the user and data on a type of a device to which type the user is authorized to get access.


