Indirect Access Control for IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of IoT devices poses challenges in maintaining connectivity and access control, especially in underserved wireless network areas where network coverage and capacity are limited, hindering authentication and access control processes.

Innovation Solution

A system where a requestee computing device verifies the trust score of a requestor device based on peer data and next degree peer data, granting access levels iteratively through a chain of trusted devices, even in areas with limited connectivity, using a cloud service and metadata for access control permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based authentication and access control services are used, then security and centralized management are improved, but system reliability deteriorates in areas with limited wireless network coverage

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces peer devices as intermediaries in the authentication process. When cloud services are unavailable, the requestee device can verify the requestor device through a chain of peer device attestations. This intermediary mechanism enables decentralized authentication, maintaining system reliability in areas with limited network coverage while reducing dependence on centralized cloud infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If iterative verification of peer data through multiple degrees of separation is performed, then trust score accuracy is improved, but computational complexity and verification time increase

Engineering Contradiction:
Improvetrust score accuracyVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements iterative verification that can stop at any degree of separation based on predefined thresholds. The system performs verification to a sufficient depth (partial action) rather than always completing the maximum possible iterations. This approach achieves adequate trust score accuracy without the excessive computational overhead and time consumption of exhaustive multi-degree verification.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If trust scores are calculated based on multiple peer degrees and verification chains, then access control security is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improveaccess control securityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent employs dynamic verification depth adjustment based on contextual factors such as available network connectivity, device energy levels, and security requirements. When cloud services are available, the system uses standard authentication. When connectivity is limited, it dynamically switches to peer-based verification with adjusted depth, balancing security needs against energy consumption and processing overhead in real-time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10069823B1Indirect access control
Publication Date: 2018.09.04 CA TECH INC
  • US10069823B1 patent drawing
  • US10069823B1 patent drawing
  • US10069823B1 patent drawing

AI summary

Indirect access control is performed between a requestor computing device and a requestee computing device. Peer data is transmitted from the requestor to the requestee that asserts that the requestor is trusted by a peer computing device. It is verified that the requestor has a first degree of trust with the peer. Next degree peer data is received from the peer that asserts that the peer is trusted by a next degree peer computing device. It is verified that the peer has a next degree of trust with the next degree peer. A trust score is calculated for the requestor based on the verification of the peer data and the next degree peer data, and an access level is granted to the requestor based on the trust score.