IoT Attribute Labels for Scalable Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IoT communication networks face challenges in managing access control policies and quality of service (QoS) requirements due to the large number of devices and services, leading to scalability issues and increased complexity in implementing and maintaining rules for policy enforcement.
Innovation Solution
The implementation of attribute labels for IoT messages, which reduce the number of rules required by encoding source and destination attributes, allowing for more efficient policy enforcement and faster updates in network configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional MAC or IP addressing schemes are used to identify users and devices, then device identification is achieved, but the number of micro-flow rules required for access control policies grows very rapidly
Solution Approach 1:
The patent segments device identifiers into two components: a compact identifier (CID) that fits within existing address fields, and an attribute label that captures service characteristics. This segmentation allows policy enforcement to operate on the attribute label rather than requiring separate rules for each device combination, dramatically reducing the rule count while maintaining access control versatility
Solution Approach 2:
The patent adds a new dimension to device identification by introducing attribute labels that encode service characteristics. Instead of relying solely on traditional addressing schemes, the system overlays an attribute-based dimension that enables policy enforcement to work with service types rather than individual device identities, reducing the combinatorial explosion of required rules
2Adaptability or versatility
If a large number of micro-flow rules are created to enumerate all user and device combinations, then access control policies can be implemented, but the cost of hardware devices and maintenance increases
Solution Approach 1:
The patent creates a simplified copy of device identity information in the form of attribute labels that capture essential service characteristics. Instead of storing and processing full device identifiers and complex policy rules for each device combination, the system uses these compact attribute label copies to enforce policies, reducing hardware requirements and maintenance costs while preserving policy enforcement capability
3Adaptability or versatility
If existing addressing schemes are used to support arbitrary service combinations, then device identification is maintained, but the schemes are insufficient to satisfy all possible service combinations
Solution Approach 1:
The patent segments the identification system into traditional address fields for device location and new attribute label fields for service characteristics. This segmentation allows existing addressing schemes to continue functioning while adding service combination support through the attribute labels, without increasing overall system complexity
Solution Approach 2:
The attribute label mechanism serves multiple functions: it identifies service types, encodes access control requirements, and enables policy enforcement all within a single unified structure. This multi-functionality allows the system to support arbitrary service combinations without requiring separate addressing schemes for each service type, reducing complexity while enhancing versatility
Data Source
AI summary
Internet-of-Things messages can be transported, encoded and decoded using inventive source and destination attribute labels.


