Automated IoT Access Control via Dynamic ACL Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual creation of VPN credentials and access control lists (ACLs) for large deployments of IoT devices connected to cellular networks is cumbersome, error-prone, and time-consuming, requiring an automated solution for secure and efficient access management.

Innovation Solution

A computer-implemented method and system that dynamically associates IoT devices with user accounts, assigns IP addresses, and generates ACLs to restrict access, using a network carrier interconnect, API gateway, and access control service for automated VPN credential creation and management, enabling secure access control for IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual creation of VPN credentials and ACLs is performed, then security control is achieved, but the process becomes cumbersome and error-prone for large device deployments

Engineering Contradiction:
Improveaccess control accuracyVSAvoidcredential creation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service automation where the access control service automatically generates VPN credentials and ACLs based on device provisioning data, eliminating the need for manual configuration and reducing human error in large-scale deployments

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An access control service acts as an intermediary between device provisioning and VPN credential generation, automatically translating device information into appropriate access credentials and ACL rules without requiring manual intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual ACL generation is performed for each device, then access restrictions are established, but the process becomes time-consuming for large volumes of devices

Engineering Contradiction:
Improveaccess restriction enforcementVSAvoiddevice provisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary action by pre-generating VPN credentials and ACLs automatically at the time of device provisioning, so that access control is already in place before devices are deployed, eliminating the need for subsequent manual configuration

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control service automatically generates ACLs for each device based on provisioning data, enabling bulk device provisioning without manual ACL creation and significantly improving deployment productivity

Inventive Principle:
Principle #25Self-service

3Productivity

If automated systems are implemented for VPN credential management, then efficiency increases, but system complexity increases

Engineering Contradiction:
Improvecredential management efficiencyVSAvoidaccess control system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The access control service performs multiple functions including device association, credential generation, and ACL creation within a single automated system, improving efficiency while managing complexity through functional integration rather than proliferation of separate systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11916912B2Method and system for providing secure access to IoT devices using access control
Publication Date: 2024.02.27 AERIS COMM INC
  • US11916912B2 patent drawing
  • US11916912B2 patent drawing
  • US11916912B2 patent drawing

AI summary

A computer-implemented method, system and computer program product for providing secure access to devices enabled for connectivity using access control are disclosed. The computer-implemented method for providing secure access to devices enabled for connectivity comprises dynamically associating each of the one or more devices to at least one user account; assigning an IP address to each of the one or more devices enabled for connectivity; dynamically generating at least one access-control list (ACL) for each of the one or more devices associated with the at least one user account; and restricting access only to the at least one user account via ACL generated for the one or more devices.