IoT Broker Policy Manager Dynamic Incident Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT systems lack dynamic policy management capabilities during incidents, limiting the flexibility and interoperability of IoT devices in emergency or multi-organization communications networks, where static certificates and policies restrict access and control.
Innovation Solution
Implementing a Broker Policy Manager (BPM) that dynamically adjusts IoT client policies using certificate-based IoT brokers, allowing IoT clients to join incident communications networks and change subscription and publication permissions in real-time through protocols like HTTP, MQTT, or XMPP, enabling dynamic IoT policy management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static certificates and policies are used for IoT devices, then security and control are maintained, but flexibility and adaptability during incidents are limited
Solution Approach 1:
The patent implements dynamic policy management by allowing the Broker Policy Manager to modify IoT client policies in real-time during incidents. The system transitions from static certificate-based access control to dynamic policy adjustment, where permissions can be changed based on incident requirements while maintaining security through continuous authentication.
Solution Approach 2:
The system changes the parameter of policy status from static to dynamic. The Broker Policy Manager can modify subscription and publication permissions, change topic access rights, and update device roles during incidents. This allows the same IoT device to have different access levels at different times while maintaining security through authenticated policy changes.
2Ease of operation
If central administrator controls all communications resources, then coordination is simplified, but organizational autonomy and control are lost
Solution Approach 1:
The Broker Policy Manager acts as an intermediary between central coordination and organizational autonomy. It receives incident information from the Incident-Based System, processes policy changes, and applies them to individual IoT clients. This mediator enables coordinated incident response while preserving organizational control over their own resources.
Solution Approach 2:
The system segments control by maintaining separate policy management for different organizations while enabling coordinated action during incidents. Each organization retains control of its resources through authenticated policies, but the Broker Policy Manager can coordinate access across organizations when incident requirements demand it.
3Adaptability or versatility
If multiple disparate communications resources exist, then system capability is expanded, but interoperability and cooperation are reduced
Solution Approach 1:
The patent implements a universal communication framework that supports multiple communication protocols and resource types through a single Broker Policy Manager. The system can manage diverse IoT devices and communications resources using common policy mechanisms, enabling interoperability without requiring separate coordination systems for each resource type.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Some embodiments include a broker policy manager (BPM) comprising a transceiver and a processor, where the processor is configured to dynamically change a policy associated with an Internet of Things (IoT) client certificate based on an incident invitational model. In some embodiments the processor can determine that a first IoT client is a participant of an incident communications network corresponding to an incident, and transmit first instructions to a certificate-based IoT broker to change a first IoT policy associated with a first certificate of the first IoT client, to enable the first IoT client to publish or subscribe to a topic that corresponds to the incident. The first instructions can indicate a change to a second IoT policy associated with a second certificate of a second IoT client that enables the second IoT client to publish or subscribe to the topic that corresponds to the incident.