IoT Access Control via API Group Segmentation and Ticket Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for IoT devices struggle with fine-grained control, leading to complex management mechanisms when multiple users need to perform different control actions on devices, such as adjusting RGB values for light bulbs.

Innovation Solution

An information processing apparatus provides an API group for controlling IoT devices via a network, using tickets to manage access and control, allowing specific APIs to be invoked based on user permissions, with the server device generating and managing tickets to enable or disable access dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing access control systems are used for IoT devices, then basic access control is provided, but fine-grained control for multiple users to perform different control actions is difficult, leading to complex management mechanisms

Engineering Contradiction:
Improvefine-grained control capabilityVSAvoidmanagement mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control by dividing APIs into groups and assigning different permission levels to different user roles. Each API group contains specific control actions (e.g., lock/unlock, lighting control) that can be selectively granted to users, enabling fine-grained control without complex overall management mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different permission characteristics to different API groups based on specific control actions. Each API group has its own permission settings that match the specific requirements of that control function, allowing tailored access control for different device operations.

Inventive Principle:
Principle #3Local quality

2Reliability

If API access is limited to authorized users only, then unauthorized access is prevented, but the system requires complex authentication and permission management mechanisms

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary access control server that mediates between users and IoT devices. This server handles authentication and permission verification centrally, simplifying the authentication mechanism while ensuring reliable prevention of unauthorized access. The server acts as a gateway that manages API group permissions without requiring complex authentication logic in each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple users can control IoT devices with different permissions, then versatile control is enabled, but managing user permissions and API access rights becomes complex

Engineering Contradiction:
Improvemulti-user control capabilityVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments permission management by organizing APIs into groups with different permission levels. Each user is assigned permissions at the API group level rather than individual API level, reducing the complexity of managing multi-user access rights while maintaining versatile control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal permission management system where a single set of API group definitions can be applied across multiple users and devices. The access control server provides multi-functional permission verification that works across different users, devices, and API groups, simplifying permission management through standardized processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11343320B2Information processing apparatus, access control system, and non-transitory computer-readable storage medium for storing access control program
Publication Date: 2022.05.24 FUJITSU LTD
  • US11343320B2 patent drawing
  • US11343320B2 patent drawing
  • US11343320B2 patent drawing

AI summary

An information processing apparatus configured to provide an application programming interface (API) group for controlling a device coupled via a network, the information processing apparatus includes: a memory; and a processor coupled to the memory, the processor being configured to execute a receiving process that includes receiving data on any API of the API group from a terminal, execute a code execution process that includes executing first code indicating processing to be executed by the information processing apparatus, the first code being included in the data, thereby causing an API specified in the first code, of the API group, to be invocable from the terminal, and execute a control process that includes, in response to an invocation request for the API specified in the first code, the invocation request being transmitted from the terminal, performing control in accordance with the API over the device.