Dynamic Authorization Framework for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control mechanisms are not well-suited for IoT systems, as they are centrally controlled and do not provide dynamic access, assuming pre-established trust relationships and non-constrained devices, which is not feasible for IoT environments where devices are constrained and access is needed without prior relationships.

Innovation Solution

A dynamic authorization framework that classifies resources based on security value, determines required security mechanisms, and allows clients to select appropriate authorization models and protocols for secure access, using a Security Classification Process, Security Achievability Determination Process, and Security Achievability Listing Process to enable secure and flexible access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static access control mechanisms are used, then access control is simple to implement, but flexibility and adaptability to dynamic environments are poor

Engineering Contradiction:
ImproveflexibilityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization by allowing clients to select from multiple authorization models (OAuth 2.0, ACE, DCAF) based on the resource's security classification and the client's capabilities. The authorization server dynamically determines which model to use, enabling the system to adapt to varying security requirements and device constraints without requiring a single complex unified system.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authorization parameters dynamically based on resource security classification. High-security resources require more stringent authorization models with enhanced security mechanisms, while lower-security resources use simpler models. This parameter-based adaptation allows the system to maintain simplicity for common cases while providing flexibility when needed.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If pre-established trust relationships are assumed, then authorization is simplified, but applicability to IoT environments without prior relationships is limited

Engineering Contradiction:
Improveapplicability to IoTVSAvoidauthorization mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authorization server is designed to handle multiple authorization scenarios universally. It can process requests from clients without pre-established trust relationships by selecting appropriate authorization models that accommodate unknown clients. The system universally applies security classifications and model selection logic across all resource types and client scenarios, making it suitable for both traditional and IoT environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a trusted third-party authorization server as an intermediary between clients and resources. This intermediary evaluates client credentials, selects appropriate authorization models, and issues authorization tokens. The intermediary handles the complexity of trust evaluation and model selection, allowing clients without pre-established relationships to access resources through a centralized security gateway.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If constrained devices are supported, then device diversity is improved, but computational and communication overhead increases

Engineering Contradiction:
Improvedevice diversityVSAvoidcomputational overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system applies different authorization quality levels to different devices based on their capabilities. Constrained devices receive simplified authorization flows appropriate for their limited computational resources, while more capable devices can utilize enhanced security models. The authorization server tailors the security mechanism complexity to match the client's device class, reducing unnecessary computational overhead on constrained devices.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3318036B1Resource-driven dynamic authorization framework
Publication Date: 2022.11.23 CONVIDA WIRELESS LLC
  • EP3318036B1 patent drawingFigure 1
  • EP3318036B1 patent drawingFigure 2
  • EP3318036B1 patent drawingFigure 3

AI summary

Embodiments concern a dynamic authorization framework. Security Classification Process (SCP) is the process of classifying raw data, information extracted from raw data, content or code from security-value perspective. Security Achievability Determination Process (SADP) is a process based on a SV/SC that has been assigned, the RHE may determine the Security Requirements and how the security requirements may be achieved. During the Security Achievability Listing Process (SALP), the RHE uploads onto the Resource Listing Entity (RLE) the URI of the resource, the SAM associated with the resource and optionally a digital certificate associated with the resource. During the SAM Assessment Process (SAMAP) process, a Client evaluates the security mechanisms that must be carried out in order to meet the SAM that was provided as part of the Discovery Process (DP). Based on the SAM obtained from the RLE, the Client may initiate a Security Achievability Enabling Process (SAEP). The Client may be required to initiate an Authentication, Authorization, Payment and obtain an assertion of secure behavior from a Security -Achievability Enabler Function (SAEF), which may be a trusted third-party Function or Entity.