IoT Attribute Labels for Scalable Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT communication networks face challenges in managing access control policies and quality of service (QoS) requirements due to the large number of devices and services, leading to scalability issues and increased complexity in implementing and maintaining rules for policy enforcement.

Innovation Solution

The implementation of attribute labels for IoT messages, which reduce the number of rules required by encoding source and destination attributes, allowing for more efficient policy enforcement and faster updates in network configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional MAC or IP addressing schemes are used to identify users and devices, then device identification is achieved, but the number of micro-flow rules required for access control policies grows very rapidly

Engineering Contradiction:
Improveaccess control policy implementationVSAvoidnumber of rules
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments device identifiers into two components: a compact identifier (CID) that fits within existing address fields, and an attribute label that captures service characteristics. This segmentation allows policy enforcement to operate on the attribute label rather than requiring separate rules for each device combination, dramatically reducing the rule count while maintaining access control versatility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to device identification by introducing attribute labels that encode service characteristics. Instead of relying solely on traditional addressing schemes, the system overlays an attribute-based dimension that enables policy enforcement to work with service types rather than individual device identities, reducing the combinatorial explosion of required rules

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If a large number of micro-flow rules are created to enumerate all user and device combinations, then access control policies can be implemented, but the cost of hardware devices and maintenance increases

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidhardware cost and maintenance
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent creates a simplified copy of device identity information in the form of attribute labels that capture essential service characteristics. Instead of storing and processing full device identifiers and complex policy rules for each device combination, the system uses these compact attribute label copies to enforce policies, reducing hardware requirements and maintenance costs while preserving policy enforcement capability

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If existing addressing schemes are used to support arbitrary service combinations, then device identification is maintained, but the schemes are insufficient to satisfy all possible service combinations

Engineering Contradiction:
Improveservice combination supportVSAvoidaddressing scheme complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the identification system into traditional address fields for device location and new attribute label fields for service characteristics. This segmentation allows existing addressing schemes to continue functioning while adding service combination support through the attribute labels, without increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The attribute label mechanism serves multiple functions: it identifies service types, encodes access control requirements, and enables policy enforcement all within a single unified structure. This multi-functionality allows the system to support arbitrary service combinations without requiring separate addressing schemes for each service type, reducing complexity while enhancing versatility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10826828B2Systems and methods for encoding and decoding IoT messages
Publication Date: 2020.11.03 NOKIA TECHNOLOGIES OY
  • US10826828B2 patent drawing
  • US10826828B2 patent drawing
  • US10826828B2 patent drawing

AI summary

Internet-of-Things messages can be transported, encoded and decoded using inventive source and destination attribute labels.