IoT Access Control via API Group Segmentation and Ticket Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems for IoT devices struggle with fine-grained control, leading to complex management mechanisms when multiple users need to perform different control actions on devices, such as adjusting RGB values for light bulbs.
Innovation Solution
An information processing apparatus provides an API group for controlling IoT devices via a network, using tickets to manage access and control, allowing specific APIs to be invoked based on user permissions, with the server device generating and managing tickets to enable or disable access dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing access control systems are used for IoT devices, then basic access control is provided, but fine-grained control for multiple users to perform different control actions is difficult, leading to complex management mechanisms
Solution Approach 1:
The patent segments access control by dividing APIs into groups and assigning different permission levels to different user roles. Each API group contains specific control actions (e.g., lock/unlock, lighting control) that can be selectively granted to users, enabling fine-grained control without complex overall management mechanisms.
Solution Approach 2:
The patent applies local quality by assigning different permission characteristics to different API groups based on specific control actions. Each API group has its own permission settings that match the specific requirements of that control function, allowing tailored access control for different device operations.
2Reliability
If API access is limited to authorized users only, then unauthorized access is prevented, but the system requires complex authentication and permission management mechanisms
Solution Approach 1:
The patent introduces an intermediary access control server that mediates between users and IoT devices. This server handles authentication and permission verification centrally, simplifying the authentication mechanism while ensuring reliable prevention of unauthorized access. The server acts as a gateway that manages API group permissions without requiring complex authentication logic in each device.
3Adaptability or versatility
If multiple users can control IoT devices with different permissions, then versatile control is enabled, but managing user permissions and API access rights becomes complex
Solution Approach 1:
The patent segments permission management by organizing APIs into groups with different permission levels. Each user is assigned permissions at the API group level rather than individual API level, reducing the complexity of managing multi-user access rights while maintaining versatile control capabilities.
Solution Approach 2:
The patent creates a universal permission management system where a single set of API group definitions can be applied across multiple users and devices. The access control server provides multi-functional permission verification that works across different users, devices, and API groups, simplifying permission management through standardized processes.
Data Source
AI summary
An information processing apparatus configured to provide an application programming interface (API) group for controlling a device coupled via a network, the information processing apparatus includes: a memory; and a processor coupled to the memory, the processor being configured to execute a receiving process that includes receiving data on any API of the API group from a terminal, execute a code execution process that includes executing first code indicating processing to be executed by the information processing apparatus, the first code being included in the data, thereby causing an API specified in the first code, of the API group, to be invocable from the terminal, and execute a control process that includes, in response to an invocation request for the API specified in the first code, the invocation request being transmitted from the terminal, performing control in accordance with the API over the device.


