Context-Aware Policy-Based Access Control for IoT Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for access control in mobile computing and IoT devices lack context-awareness, which is crucial for making dynamic and secure policy decisions, especially given the diverse and changing computing contexts of these devices.
Innovation Solution
The integration of Policy Information Points (PIPs) and an Analytical Processing Engine into the policy-based access control architecture, allowing the system to gather, store, and utilize contextual information for more expressive and granular policy rules, with PDPs accessing PIPs for adjudicating queries and PEPs enforcing decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If policy-based access control is implemented without context-awareness, then the system is simpler to implement, but it cannot make dynamic and secure policy decisions in diverse computing contexts
Solution Approach 1:
The system is segmented into distinct functional components: Policy Information Points (PIPs) for storing contextual data, Policy Decision Points (PDPs) for adjudicating access requests, and Policy Enforcement Points (PEPs) for executing decisions. This segmentation allows the system to gain context-awareness capabilities while maintaining manageable complexity through modular design, where each component has a specific responsibility.
Solution Approach 2:
Policy Information Points act as intermediaries between the contextual data sources and the Policy Decision Points. PIPs gather, store, and provide contextual information to PDPs when needed, enabling the system to make informed policy decisions without requiring PDPs to directly access or process raw contextual data, thus maintaining system simplicity while achieving adaptability.
2Manufacturing precision
If contextual information is gathered and stored for policy decisions, then granular and dynamic policy control is enabled, but the system requires additional components and storage capacity
Solution Approach 1:
The architecture is divided into specialized components with distinct roles: PIPs handle contextual information gathering and storage, while PDPs focus on policy adjudication. This segmentation enables fine-grained policy control by allowing PIPs to maintain detailed contextual data without burdening the policy decision-making process, achieving high policy granularity through structured system division.
Solution Approach 2:
Contextual information is gathered and stored in advance in Policy Information Points before policy decisions are needed. This preliminary action enables the system to have contextual data readily available when access requests occur, allowing for granular and dynamic policy control without requiring complex real-time data collection and processing during the decision-making moment.
3Reliability
If the system uses dynamic policy rules based on context, then security in novel computing contexts is improved, but the rules become more complex to formulate and enforce
Solution Approach 1:
Policy Information Points serve as intermediaries that structure and organize contextual information in a standardized format accessible to Policy Decision Points. This intermediary layer simplifies the formulation of dynamic policy rules by providing a consistent interface to contextual data, allowing security rules to be expressed in terms of structured context parameters rather than raw, unstructured data, thereby improving reliability in novel contexts while managing rule complexity.
Solution Approach 2:
The system enables dynamic policy rules by allowing policy parameters to change based on contextual information stored in PIPs. Instead of static rules, policies can reference contextual parameters (such as device state, user context, environmental conditions) that dynamically adjust the effective policy parameters. This approach improves security adaptability in novel contexts while keeping the rule formulation mechanism systematic and manageable through parameter-based policy expressions.
Data Source
AI summary
A system and methods for context-aware and situation-aware secure, policy-based access control for computing devices. The invention enhances the previously disclosed policy-based control system by adding contextual information to the set of resources by which a policy decision point can adjudicate a query to execute a transaction or to access a secure resource. Policy information points are able to store information collected over time related to resources under the control of the system. The system can further include an analytical processing engine capable of inferring new information from existing information that also can be used by the decision points. The policy information points provide context to the decision. They are also able to consider and include information that is external to the system or detected outside the system itself.


