IoT Data Orchestrator for Context-Aware Secure Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IoT networks face significant challenges in data security, privacy, and regulatory compliance due to the vertically integrated concept of tenancy, which limits the ability to unlock the value of cross-domain data sharing.
Innovation Solution
A data orchestrator system that decouples the IoT stack layers to enable secure data sharing by using device identifiers, user information, and licensing data to dynamically generate routing tables for data interchange, respecting the 'least privilege' principle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional vertically integrated tenancy is used for data isolation, then data security and privacy are maintained, but cross-domain data sharing capability is limited
Solution Approach 1:
The patent segments the traditional vertically integrated tenancy architecture into separate functional layers: data collection layer, data processing layer, and data sharing layer. This segmentation allows data isolation at the collection layer while enabling controlled sharing at the processing and sharing layers through dynamic tenancy assignment, thus resolving the contradiction between security and sharing capability.
Solution Approach 2:
The patent implements dynamic tenancy assignment where data consumers can be assigned to different tenancy groups based on licensing data and device claim information. This dynamic approach allows the system to adaptively control data sharing permissions rather than using static isolation, enabling cross-domain sharing while maintaining security through policy-based access control.
2Reliability
If traditional tenancy framework is used, then data isolation is achieved, but the ability to unlock value from cross-domain data is limited
Solution Approach 1:
The patent introduces a data broker as an intermediary component that facilitates controlled data sharing between isolated tenancy groups. The data broker receives data from multiple sources, applies routing rules based on licensing information, and delivers data to authorized consumers, thus enabling value extraction from cross-domain data while maintaining isolation through the intermediary layer.
Solution Approach 2:
The patent creates a universal data sharing framework that can handle multiple data types, multiple consumers, and multiple licensing scenarios through a single unified system. This multi-functional approach allows the same infrastructure to serve diverse data sharing needs across different domains, maximizing data value utilization while maintaining isolation principles.
3Adaptability or versatility
If data sharing across domains is enabled, then data value is unlocked, but security and privacy challenges increase
Solution Approach 1:
The patent performs preliminary security actions by establishing routing rules and tenancy assignments before data sharing occurs. The system pre-configures which data consumers can access which data sources based on licensing data and device claim information, conducting security validation in advance rather than during data transmission, thus enabling sharing while mitigating security risks proactively.
Solution Approach 2:
The patent implements feedback mechanisms where the data broker continuously monitors data sharing operations and validates access requests against licensing information and routing rules. This real-time feedback control ensures that data sharing remains within authorized boundaries, allowing versatile sharing capability while maintaining security through continuous validation and control.
Data Source
AI summary
Techniques are described for securely routing data with an Internet of Things environment. A data orchestrator receives a plurality of data values collected by the endpoint device from an endpoint device and determines an identifier that uniquely identifies the endpoint device. The data orchestrator accesses one or more routing tables using the determined identifier and device type data corresponding to the plurality of data values to determine one or more data consumers to route the plurality of data values to. The one or more routing tables were dynamically generated based on at least one of (i) device claim information relating to the endpoint device, (ii) license data relating to the one or more data consumers, and (iii) user information associated with the one or more data consumers. The data orchestrator transmits at least a portion of the plurality of data values to the determined one or more data consumers.


