IoT Device Access Management via Distributed Ledgers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Accessing and managing information from IoT devices owned by disparate entities is challenging, particularly in incidents where public safety officers need additional information, such as video footage, due to difficulties in determining relevant devices, managing access, and authenticating these devices.

Innovation Solution

A communication system utilizing a Computer Aided Dispatch (CAD) system connected to an IoT Gateway and distributed ledgers (Incident Ledger and IoT Ledger) for data management, where IoT devices are registered and affiliated with incidents based on geofence coordinates and device attributes, enabling secure and decentralized access to relevant data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are owned and managed by various disparate entities, then device diversity and coverage are improved, but access management and authentication become more difficult

Engineering Contradiction:
Improvedevice coverageVSAvoidaccess management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a centralized access management system that acts as an intermediary between public safety officers and IoT devices owned by disparate entities. This system handles authentication, authorization, and device discovery, allowing officers to access relevant devices without directly managing the complexity of multiple ownership entities. The intermediary abstracts the heterogeneity of device owners while maintaining unified access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a centralized system is used to manage IoT device access, then access control is simplified, but single points of failure and security risks increase

Engineering Contradiction:
Improveaccess controlVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access management system into multiple distributed components, including local device servers, regional hubs, and cloud-based services. This segmentation allows the system to maintain centralized coordination while distributing critical functions across multiple nodes, eliminating single points of failure. If one component fails, others can continue to provide access management services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements redundant authentication mechanisms and backup access paths in advance. Multiple authentication methods (cryptographic keys, certificates, token-based systems) are prepared beforehand, along with fallback procedures. This cushioning ensures that if one authentication mechanism fails or is compromised, alternative methods are already in place to maintain security and access continuity.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Device complexity

If all IoT devices are authenticated through a single entity, then authentication process is simplified, but security vulnerabilities increase

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements local quality by allowing different authentication methods and security policies for different device types, owners, and contexts. Rather than applying a uniform authentication approach to all devices, the system tailors authentication mechanisms to specific device characteristics and ownership structures. This enables simplified authentication for some devices while maintaining enhanced security for others, optimizing both ease of operation and security on a per-device basis.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3794778B1Method and system to associate IoT devices with an incident and manage access
Publication Date: 2023.04.05 MOTOROLA SOLUTIONS INC
  • EP3794778B1 patent drawingFigure 1
  • EP3794778B1 patent drawingFigure 2~3
  • EP3794778B1 patent drawingFigure 4

AI summary

A method for registering an Internet of Things (IoT) device to an incident IoT ledger system is provided. An IoT device is installed at a location. At least one feature of the IoT device is prevented from functioning the IoT device is registered with an incident IoT ledger system. Upon registering incident-relevant attributes associated with the IoT device and the location of the IoT device with an incident IoT ledger system, full functioning of the IoT device is enabled after successful registration with the incident IoT ledger system.