Delegated Rights for IoT Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for connecting communicating objects to a communication network are either costly due to multiple subscriptions required or inconvenient as they necessitate pairing with a specific access gateway, limiting network access.
Innovation Solution
A method and platform for managing access rights that allows a single subscription to be shared among multiple communicating objects by generating delegated rights from initial user subscription rights, enabling objects to access the network without needing their own subscription or pairing with a specific gateway, using a secure communication channel for configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If each communicating object takes out its own subscription to the communication network, then the object can connect autonomously and transparently to all access points, but the cost increases significantly
Solution Approach 1:
The patent implements a universal subscription model where a single subscription on the access gateway serves multiple communicating objects simultaneously. The gateway's subscription is made multi-functional by enabling it to authenticate and manage multiple devices through delegated rights, eliminating the need for each device to have its own subscription while maintaining autonomous connection capabilities.
Solution Approach 2:
The access gateway acts as an intermediary between the communication network and multiple communicating objects. It receives the single subscription and mediates access by delegating rights to multiple objects, allowing them to connect transparently without each object needing its own direct subscription to the network.
2Quantity of substance
If a single subscription is used on an access gateway, then the cost is reduced, but the communicating object must be paired with a specific gateway and can only access the network in its vicinity
Solution Approach 1:
The patent segments the gateway's subscription rights into multiple delegated rights that can be distributed to different communicating objects. Each object receives a portion of the access authority, enabling them to connect to different access points independently while the gateway maintains overall management, thus providing both cost efficiency and access flexibility.
Solution Approach 2:
The patent implements dynamic right delegation where the gateway can allocate and revoke access rights to different objects based on their needs and locations. This dynamic management allows objects to access the network through various gateways and access points as needed, transforming the static limitation of single-gateway pairing into a flexible, adaptive system.
3Reliability
If pairing with a specific access gateway is required, then security is maintained, but the complexity of connection management increases when objects need to move between gateways
Solution Approach 1:
The gateway serves as a security intermediary that maintains centralized control over access rights. It issues delegated rights to objects that embed authentication credentials, allowing objects to move between gateways and access points while the central gateway maintains security policies and authentication, thus preserving security while reducing connection management complexity.
Solution Approach 2:
The patent creates copies of authentication credentials in the form of delegated rights that are embedded in each communicating object. These credential copies allow objects to authenticate independently at different access points without requiring repeated pairing with specific gateways, maintaining security through cryptographic verification while simplifying connection management.
Data Source
Figure 1
Figure 2~4
Figure 5
AI summary
The invention relates to a method implemented by a communicating object for obtaining access rights (CRD2) to a communication network, the object (1) initially having limited rights for data exchange with a network rights management platform (3), the method comprising: │ a step (E10) of transmitting a signalling message (M1) to the platform (3); and │ a step (E150) of receiving a communication profile (PROF) belonging to the network, said profile being associated in the network with rights belonging to the object (1), termed delegated rights (CRD2), the delegated rights being defined from network access rights, termed initial rights, associated with a user of the object, the delegated rights (CRD2) being suitable for allowing the communicating object (1) to access the communication network.