Broker-Coordinated Selective Data Sharing in IoT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies in IoT networks lack effective access control mechanisms to ensure that only authorized data is retrieved from multiple device manufacturers, often relying on 'all or nothing' authorization and cloud-based data storage, which exposes data risks.

Innovation Solution

A broker-coordinated system where a centralized broker device manages data-access policies and transmits them to gateway devices, allowing selective sharing of data by determining authorized access on a per-element basis, establishing secure connections between trusted partners and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-based data storage is used for IoT networks, then data accessibility is improved, but data security and risk of exposure deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A broker device is introduced as an intermediary between data requestors and IoT devices. The broker receives data requests, determines authorized access based on data-access policies, and selectively shares data elements. This mediator approach enables controlled data access without requiring centralized cloud storage, thereby improving data security while maintaining accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If 'all or nothing' authorization is used for data access, then access control simplicity is improved, but data sharing flexibility deteriorates

Engineering Contradiction:
Improveaccess control simplicityVSAvoiddata sharing flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments data into discrete data elements and implements granular access control at the element level rather than treating data as a single unit. The broker determines authorized access to specific data elements based on data-access policies, enabling selective sharing of individual elements or combinations of elements. This segmentation approach maintains policy management simplicity while dramatically increasing data sharing flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different access permissions to different data elements based on local characteristics and requirements. Each data element can have its own access control rules defined in data-access policies, allowing customized permission sets for different entities without requiring complex centralized authorization logic. This enables flexible, context-specific access control.

Inventive Principle:
Principle #3Local quality

3Productivity

If multiple entities access IoT device data, then data utility is improved, but access control complexity deteriorates

Engineering Contradiction:
Improvedata utilityVSAvoidaccess control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The broker acts as a centralized intermediary that manages access control for multiple entities requesting data from IoT devices. Instead of implementing complex access control logic at each IoT device or data collector, the broker receives all data requests, determines authorized access based on centralized data-access policies, and distributes appropriate data elements. This concentrates access control complexity in a single manageable location while enabling multiple entities to access data with appropriate permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11411957B2Broker-coordinated selective sharing of data
Publication Date: 2022.08.09 CISCO TECHNOLOGY INC
  • US11411957B2 patent drawing
  • US11411957B2 patent drawing
  • US11411957B2 patent drawing

AI summary

In one embodiment, a gateway device receives, from a centralized broker device, a data-access policy for a given computer network, the data-access policy defining which of one or more accessing entities are granted access to specific elements of data within the given computer network. When the gateway device then receives, from a particular accessing entity, a request for one or more particular elements of data from within the given computer network, it may determine, based on the data-access policy, whether the particular accessing entity has been granted access to each of the one or more particular elements of data of the request. As such, the gateway device may prevent access for the particular accessing entity to any of the one or more particular elements of the data request to which the particular accessing entity has not been granted access.