Blockchain Broker for Remote IoT Access Control Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for configuring and managing user accounts and access control policies across numerous devices, especially IoT devices, are time-consuming, labor-intensive, and lack effective security infrastructure, making them vulnerable to unauthorized access and breaches.

Innovation Solution

A computer-implemented method using a broker and blockchain system to centrally manage and distribute user accounts and access control policies across networked devices, eliminating the need for human intervention and enabling efficient updates, with a gateway orchestrating and enforcing these policies using a distributed ledger for secure data storage and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are manually configured with user accounts and access control policies, then each device can be securely configured, but the process becomes time and labor intensive especially for organizations with thousands of devices

Engineering Contradiction:
Improvesecurity configurationVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service through automated agent-based configuration where devices automatically receive and apply access control policies from a centralized cloud service, eliminating the need for manual configuration at each device while maintaining security standards

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The centralized cloud service pre-configures access control policies and user accounts before deployment, allowing bulk provisioning to multiple devices simultaneously. This preliminary preparation enables rapid deployment across thousands of devices without sequential manual configuration

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If traditional client-server security systems are used to manage IoT devices, then centralized control is achieved, but the systems fail to account for limited processing power, memory, and user interface elements of IoT devices

Engineering Contradiction:
Improvecentralized controlVSAvoidIoT device compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system segments functionality by separating complex policy management and enforcement logic into a lightweight agent component that runs locally on resource-constrained IoT devices, while the centralized cloud service handles heavy computational tasks like policy generation and user management

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A specialized agent acts as an intermediary between traditional client-server security systems and IoT devices, translating standard security protocols into formats suitable for devices with limited processing power and memory, thereby bridging the compatibility gap

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If user accounts and access control policies are stored centrally, then efficient updates can be deployed across all devices, but the system becomes vulnerable to security breaches and unauthorized access

Engineering Contradiction:
Improvepolicy update efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements local quality by caching access control policies locally on each device and using cryptographic signatures to verify policy authenticity. This allows efficient local enforcement of policies while maintaining security through distributed verification, reducing the impact of potential central storage breaches

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10965713B2Centrally managing data for orchestrating and managing user accounts and access control and security policies remotely across multiple devices
Publication Date: 2021.03.30 XAGE SECURITY INC
  • US10965713B2 patent drawing
  • US10965713B2 patent drawing
  • US10965713B2 patent drawing

AI summary

In an embodiment, a computer-implemented method comprising: posting, by a broker computing device, device control data to a distributed datastore including distributed ledger and blockchain, wherein the device control data is collected at a plurality of directory services in a federation; receiving, at a computing hardware device, the device control data from the distributed datastore; using, by the computing hardware device, the device control data received from the distributed datastore, remotely managing user accounts and access control and security policies on at least one networked device.