Blockchain Broker for Remote IoT Access Control Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for configuring and managing user accounts and access control policies across numerous devices, especially IoT devices, are time-consuming, labor-intensive, and lack effective security infrastructure, making them vulnerable to unauthorized access and breaches.
Innovation Solution
A computer-implemented method using a broker and blockchain system to centrally manage and distribute user accounts and access control policies across networked devices, eliminating the need for human intervention and enabling efficient updates, with a gateway orchestrating and enforcing these policies using a distributed ledger for secure data storage and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices are manually configured with user accounts and access control policies, then each device can be securely configured, but the process becomes time and labor intensive especially for organizations with thousands of devices
Solution Approach 1:
The system enables self-service through automated agent-based configuration where devices automatically receive and apply access control policies from a centralized cloud service, eliminating the need for manual configuration at each device while maintaining security standards
Solution Approach 2:
The centralized cloud service pre-configures access control policies and user accounts before deployment, allowing bulk provisioning to multiple devices simultaneously. This preliminary preparation enables rapid deployment across thousands of devices without sequential manual configuration
2Device complexity
If traditional client-server security systems are used to manage IoT devices, then centralized control is achieved, but the systems fail to account for limited processing power, memory, and user interface elements of IoT devices
Solution Approach 1:
The system segments functionality by separating complex policy management and enforcement logic into a lightweight agent component that runs locally on resource-constrained IoT devices, while the centralized cloud service handles heavy computational tasks like policy generation and user management
Solution Approach 2:
A specialized agent acts as an intermediary between traditional client-server security systems and IoT devices, translating standard security protocols into formats suitable for devices with limited processing power and memory, thereby bridging the compatibility gap
3Productivity
If user accounts and access control policies are stored centrally, then efficient updates can be deployed across all devices, but the system becomes vulnerable to security breaches and unauthorized access
Solution Approach 1:
The system implements local quality by caching access control policies locally on each device and using cryptographic signatures to verify policy authenticity. This allows efficient local enforcement of policies while maintaining security through distributed verification, reducing the impact of potential central storage breaches
Data Source
AI summary
In an embodiment, a computer-implemented method comprising: posting, by a broker computing device, device control data to a distributed datastore including distributed ledger and blockchain, wherein the device control data is collected at a plurality of directory services in a federation; receiving, at a computing hardware device, the device control data from the distributed datastore; using, by the computing hardware device, the device control data received from the distributed datastore, remotely managing user accounts and access control and security policies on at least one networked device.


