Centralized Access Management Gateway for IoT Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IoT platform access management mechanisms require individual setup and maintenance, leading to increased operation costs, inconsistent management policies, and a heavy development burden, particularly when handling sensitive data.
Innovation Solution
An access management apparatus with a gateway that is independent of processing systems or protocols, featuring a protocol relay function, access management function, cache unit, and access source identification, which implements integrated access management through a centralized policy database, allowing for unified access control, priority control, and simultaneous access limits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an access management mechanism is individually mounted on each interface of data processing systems, then access control can be implemented for each system, but operation costs increase and management becomes complex
Solution Approach 1:
The patent merges multiple access management mechanisms into a single centralized access management system that serves multiple data processing systems. Instead of having separate access management mechanisms on each interface, the system uses one unified mechanism that handles access control for all systems through a common policy management architecture.
Solution Approach 2:
The access management system is designed as a universal platform that can manage access control for multiple different data processing systems simultaneously. The system provides multi-functional capabilities including access control, policy management, and system monitoring across various interfaces without requiring system-specific implementations.
2Reliability
If access management mechanisms are individually configured for each processing system, then system-specific access control is achieved, but policy inconsistencies occur between mechanisms
Solution Approach 1:
The patent segments the access management functionality into a centralized policy management component and distributed access control execution. The centralized component maintains unified policy definitions that are consistently applied across all data processing systems, while the execution occurs at individual interfaces through standardized protocols.
Solution Approach 2:
The system implements feedback mechanisms that monitor policy application across different data processing systems and ensure consistent enforcement. The centralized policy management system receives information about access control execution and adjusts policies to maintain consistency across all interfaces.
3Reliability
If individual access management mechanisms are deployed on each interface, then access control is implemented, but application development burden increases
Solution Approach 1:
The patent introduces an intermediary access management system that sits between applications and data processing systems. This intermediary handles access control decisions centrally, allowing applications to interact with the system through simplified interfaces without needing to implement their own access management logic.
Solution Approach 2:
The access management system provides self-service capabilities where policy definitions are managed centrally and automatically applied to different systems. Applications and devices can authenticate and access resources without needing to configure access control mechanisms themselves, reducing development burden.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention provides an access management apparatus capable of realizing integrated access management based on an access management policy set independently of protocols of a plurality of processing systems. The access management apparatus of the present invention is provided with a gateway (11) including an access management function unit (22) that is connected between an access source (AS) and a plurality of processing systems (PS), and that is configured to receive an access request from the access source (AS), and to control the access request based on the set access management policy.