Centralized Access Management Gateway for IoT Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT platform access management mechanisms require individual setup and maintenance, leading to increased operation costs, inconsistent management policies, and a heavy development burden, particularly when handling sensitive data.

Innovation Solution

An access management apparatus with a gateway that is independent of processing systems or protocols, featuring a protocol relay function, access management function, cache unit, and access source identification, which implements integrated access management through a centralized policy database, allowing for unified access control, priority control, and simultaneous access limits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an access management mechanism is individually mounted on each interface of data processing systems, then access control can be implemented for each system, but operation costs increase and management becomes complex

Engineering Contradiction:
Improveaccess controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple access management mechanisms into a single centralized access management system that serves multiple data processing systems. Instead of having separate access management mechanisms on each interface, the system uses one unified mechanism that handles access control for all systems through a common policy management architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access management system is designed as a universal platform that can manage access control for multiple different data processing systems simultaneously. The system provides multi-functional capabilities including access control, policy management, and system monitoring across various interfaces without requiring system-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If access management mechanisms are individually configured for each processing system, then system-specific access control is achieved, but policy inconsistencies occur between mechanisms

Engineering Contradiction:
Improveaccess controlVSAvoidpolicy consistency
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent segments the access management functionality into a centralized policy management component and distributed access control execution. The centralized component maintains unified policy definitions that are consistently applied across all data processing systems, while the execution occurs at individual interfaces through standardized protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms that monitor policy application across different data processing systems and ensure consistent enforcement. The centralized policy management system receives information about access control execution and adjusts policies to maintain consistency across all interfaces.

Inventive Principle:
Principle #23Feedback

3Reliability

If individual access management mechanisms are deployed on each interface, then access control is implemented, but application development burden increases

Engineering Contradiction:
Improveaccess controlVSAvoiddevelopment burden
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary access management system that sits between applications and data processing systems. This intermediary handles access control decisions centrally, allowing applications to interact with the system through simplified interfaces without needing to implement their own access management logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access management system provides self-service capabilities where policy definitions are managed centrally and automatically applied to different systems. Applications and devices can authenticate and access resources without needing to configure access control mechanisms themselves, reducing development burden.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3687122B1Access management device, access management method and access management program
Publication Date: 2024.01.24 NIPPON TELEGRAPH & TELEPHONE CORP
  • EP3687122B1 patent drawingFigure 1
  • EP3687122B1 patent drawingFigure 2
  • EP3687122B1 patent drawingFigure 3

AI summary

The present invention provides an access management apparatus capable of realizing integrated access management based on an access management policy set independently of protocols of a plurality of processing systems. The access management apparatus of the present invention is provided with a gateway (11) including an access management function unit (22) that is connected between an access source (AS) and a plurality of processing systems (PS), and that is configured to receive an access request from the access source (AS), and to control the access request based on the set access management policy.