Authorization Component for IIoT User Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Role-Based Access Control (RBAC) systems in Industrial Internet of Things (IIoT) are inadequate for providing fine-grained access control, leading to exponential role duplication and maintenance issues, which can result in unauthorized information access and security breaches.

Innovation Solution

A computer system that authorizes users based on geographical location and device type, using an authorization component that retrieves user-specific data from a directory to grant or deny access, allowing for more granular control and reducing the complexity and errors associated with RBAC systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Role-Based Access Control (RBAC) is used to provide access control in IIoT systems, then access control functionality is provided, but the system experiences exponential role duplication and maintenance problems

Engineering Contradiction:
Improveaccess control functionalityVSAvoidrole duplication and maintenance
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control into two independent dimensions: geographical location and device type. Instead of creating composite roles for each combination, the system separately manages location-based access rules and device-type-based access rules. This segmentation prevents the exponential proliferation of roles while maintaining fine-grained control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces geographical location as an additional dimension for access control beyond traditional device type. By adding this spatial dimension, the system achieves finer granularity in access control without requiring exponential role multiplication, as location-based filtering operates independently from device-type filtering.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Manufacturing precision

If RBAC is extended to provide fine-grained access control by location and device type, then access control granularity is improved, but the number of roles increases exponentially

Engineering Contradiction:
Improveaccess control granularityVSAvoidnumber of roles
Core Design Contradiction:
Manufacturing precisionVSQuantity of substance

Solution Approach 1:

The patent divides access control into separate dimensional filters (geographical location and device type) rather than creating composite roles for each combination. This segmentation allows fine-grained control by applying independent location-based and device-type-based filtering rules, preventing the exponential increase in role quantity while achieving high granularity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal access control mechanisms that handle multiple device types and locations through a single framework. The system uses universal location-based access rules and device-type-based access rules that can be applied across multiple contexts without requiring separate roles for each specific combination, thereby reducing the total number of roles needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional RBAC is used in cloud computing platforms, then basic access control is provided, but fine-grained control for different geographical locations and device types cannot be achieved

Engineering Contradiction:
Improvebasic access controlVSAvoidfine-grained access control capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent extends traditional RBAC by adding geographical location as a new dimension for access control. This dimensional extension enables fine-grained control over data access based on location without complicating the basic RBAC operation, as the location filter operates as an independent layer over the traditional role-based framework.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces location-based access rules and device-type-based access rules as intermediary filtering layers between the user and the data. These intermediary rules provide fine-grained control by filtering access requests based on location and device type, while maintaining the simplicity of traditional RBAC for basic access control operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11019493B2System and method for user authorization
Publication Date: 2021.05.25 ABB (SCHWEIZ) AG
  • US11019493B2 patent drawing
  • US11019493B2 patent drawing
  • US11019493B2 patent drawing

AI summary

A computer system for authorizing a user to process data received from one or more devices includes: an interface component for receiving the data; an application component for receiving requests from the user, the requests including one or more requests to perform data processing operations on at least a subset of the data; a data storage and data access component for storing and access the data; one or more evaluation components for processing the data; and an authorization component for granting or denying to the user access to process at least a subset of the data, a grant or denial being based on user specific data stored in a user directory for a registered user. The user specific data includes data on a geographical location associated with the user and data on a type of a device to which type the user is authorized to get access.