Verifiable Data Audit for IoT Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a growing concern about the security and misuse of data collected by third parties from connected devices, such as IoT devices, which can discourage users from utilizing these devices due to concerns over unauthorized access.

Innovation Solution

A system comprising a data resource with a device data log, permissions log, and consent log that provides a verifiable data audit to determine whether a party is authorized to access device data, ensuring that user consent and permissions are properly managed and recorded, using cryptographic keys and immutable records to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is collected and stored by third parties from connected devices, then data aggregation and accessibility are improved, but data security and user privacy are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data access permissions by creating separate permission records for different parties (manufacturers, service providers, researchers) and different data types (device data, user data, aggregated data). Each party receives only the specific permissions they need, preventing unauthorized access while allowing broad data utilization across multiple stakeholders.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud service as an intermediary between connected devices and third parties. The cloud service manages permission records, consent logs, and data sharing agreements, acting as a trusted mediator that enables data aggregation and sharing while maintaining security controls and user privacy protections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If comprehensive data access is allowed for service providers and manufacturers, then device functionality and service quality are improved, but unauthorized access and data misuse risks are worsened

Engineering Contradiction:
Improveservice qualityVSAvoidaccess authorization
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by requiring that permission records and consent logs be established before any data access occurs. The system pre-defines acceptable use policies, data sharing agreements, and access restrictions for different parties, ensuring that authorization is granted only after proper verification and user consent, thereby preventing unauthorized access before it can happen.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If data sharing agreements and permission records are implemented, then data security and user consent management are improved, but system complexity and implementation overhead are worsened

Engineering Contradiction:
Improveconsent managementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional permission record system that handles multiple data types (device data, user data, aggregated data), multiple parties (manufacturers, service providers, researchers), and multiple access scenarios within a single unified framework. This universal permission system reduces overall complexity compared to implementing separate authorization mechanisms for each data type and party.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11356450B2Managing data access
Publication Date: 2022.06.07 ARM IP
  • US11356450B2 patent drawing
  • US11356450B2 patent drawing
  • US11356450B2 patent drawing

AI summary

The present techniques generally relate to a system comprising: a data resource comprising: a device data log to store a device data record for device data of a first device; a permissions log to store a permissions record for one or more permissions associated with the device data; a consent log to store a consent record comprising a consent status for the one or more permissions; wherein the consent record, permissions record and device data record provide a verifiable data audit to determine whether a party is authorized to access the device data.