Context-Aware Policy-Based Access Control for IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for access control in mobile computing and IoT devices lack context-awareness, which is crucial for making dynamic and secure policy decisions, especially given the diverse and changing computing contexts of these devices.

Innovation Solution

The integration of Policy Information Points (PIPs) and an Analytical Processing Engine into the policy-based access control architecture, allowing the system to gather, store, and utilize contextual information for more expressive and granular policy rules, with PDPs accessing PIPs for adjudicating queries and PEPs enforcing decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If policy-based access control is implemented without context-awareness, then the system is simpler to implement, but it cannot make dynamic and secure policy decisions in diverse computing contexts

Engineering Contradiction:
Improvecontext-awarenessVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional components: Policy Information Points (PIPs) for storing contextual data, Policy Decision Points (PDPs) for adjudicating access requests, and Policy Enforcement Points (PEPs) for executing decisions. This segmentation allows the system to gain context-awareness capabilities while maintaining manageable complexity through modular design, where each component has a specific responsibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Policy Information Points act as intermediaries between the contextual data sources and the Policy Decision Points. PIPs gather, store, and provide contextual information to PDPs when needed, enabling the system to make informed policy decisions without requiring PDPs to directly access or process raw contextual data, thus maintaining system simplicity while achieving adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If contextual information is gathered and stored for policy decisions, then granular and dynamic policy control is enabled, but the system requires additional components and storage capacity

Engineering Contradiction:
Improvepolicy granularityVSAvoidarchitecture complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The architecture is divided into specialized components with distinct roles: PIPs handle contextual information gathering and storage, while PDPs focus on policy adjudication. This segmentation enables fine-grained policy control by allowing PIPs to maintain detailed contextual data without burdening the policy decision-making process, achieving high policy granularity through structured system division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Contextual information is gathered and stored in advance in Policy Information Points before policy decisions are needed. This preliminary action enables the system to have contextual data readily available when access requests occur, allowing for granular and dynamic policy control without requiring complex real-time data collection and processing during the decision-making moment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system uses dynamic policy rules based on context, then security in novel computing contexts is improved, but the rules become more complex to formulate and enforce

Engineering Contradiction:
Improvesecurity in novel contextsVSAvoidpolicy rule complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Policy Information Points serve as intermediaries that structure and organize contextual information in a standardized format accessible to Policy Decision Points. This intermediary layer simplifies the formulation of dynamic policy rules by providing a consistent interface to contextual data, allowing security rules to be expressed in terms of structured context parameters rather than raw, unstructured data, thereby improving reliability in novel contexts while managing rule complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables dynamic policy rules by allowing policy parameters to change based on contextual information stored in PIPs. Instead of static rules, policies can reference contextual parameters (such as device state, user context, environmental conditions) that dynamically adjust the effective policy parameters. This approach improves security adaptability in novel contexts while keeping the rule formulation mechanism systematic and manageable through parameter-based policy expressions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10685130B2System and methods for context-aware and situation-aware secure, policy-based access control for computing devices
Publication Date: 2020.06.16 SEQUITUR LABS INC
  • US10685130B2 patent drawing
  • US10685130B2 patent drawing
  • US10685130B2 patent drawing

AI summary

A system and methods for context-aware and situation-aware secure, policy-based access control for computing devices. The invention enhances the previously disclosed policy-based control system by adding contextual information to the set of resources by which a policy decision point can adjudicate a query to execute a transaction or to access a secure resource. Policy information points are able to store information collected over time related to resources under the control of the system. The system can further include an analytical processing engine capable of inferring new information from existing information that also can be used by the decision points. The policy information points provide context to the decision. They are also able to consider and include information that is external to the system or detected outside the system itself.