Verifiable Data Audit for IoT Device Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a growing concern about the security and misuse of data collected by third parties from connected devices, such as IoT devices, which can discourage users from utilizing these devices due to concerns over unauthorized access.
Innovation Solution
A system comprising a data resource with a device data log, permissions log, and consent log that provides a verifiable data audit to determine whether a party is authorized to access device data, ensuring that user consent and permissions are properly managed and recorded, using cryptographic keys and immutable records to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is collected and stored by third parties from connected devices, then data aggregation and accessibility are improved, but data security and user privacy are worsened
Solution Approach 1:
The patent segments data access permissions by creating separate permission records for different parties (manufacturers, service providers, researchers) and different data types (device data, user data, aggregated data). Each party receives only the specific permissions they need, preventing unauthorized access while allowing broad data utilization across multiple stakeholders.
Solution Approach 2:
The patent introduces a cloud service as an intermediary between connected devices and third parties. The cloud service manages permission records, consent logs, and data sharing agreements, acting as a trusted mediator that enables data aggregation and sharing while maintaining security controls and user privacy protections.
2Productivity
If comprehensive data access is allowed for service providers and manufacturers, then device functionality and service quality are improved, but unauthorized access and data misuse risks are worsened
Solution Approach 1:
The patent implements preliminary action by requiring that permission records and consent logs be established before any data access occurs. The system pre-defines acceptable use policies, data sharing agreements, and access restrictions for different parties, ensuring that authorization is granted only after proper verification and user consent, thereby preventing unauthorized access before it can happen.
3Reliability
If data sharing agreements and permission records are implemented, then data security and user consent management are improved, but system complexity and implementation overhead are worsened
Solution Approach 1:
The patent applies universality by designing a multi-functional permission record system that handles multiple data types (device data, user data, aggregated data), multiple parties (manufacturers, service providers, researchers), and multiple access scenarios within a single unified framework. This universal permission system reduces overall complexity compared to implementing separate authorization mechanisms for each data type and party.
Data Source
AI summary
The present techniques generally relate to a system comprising: a data resource comprising: a device data log to store a device data record for device data of a first device; a permissions log to store a permissions record for one or more permissions associated with the device data; a consent log to store a consent record comprising a consent status for the one or more permissions; wherein the consent record, permissions record and device data record provide a verifiable data audit to determine whether a party is authorized to access the device data.


