IoT Identity Model Segmentation for Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IoT systems face challenges in managing device identities effectively, leading to difficulties in updating policy enforcements and providing granular observability, especially when devices generate traffic.
Innovation Solution
The proposed solution involves an IoT identity model that allows for refined filtering and policy groupings based on subcomponents within a device class instance. This model includes generating identity records for components using vendor, component class, device class, and device identities, and aggregating these records into groups for policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a one-to-one mapping between device and identity is used, then device identification is simple, but policy management complexity increases and granular observability is lost
Solution Approach 1:
The patent segments the identity system into multiple hierarchical levels: device identity, component class identity, and instance identity. This segmentation allows policy management to operate at different granularities, reducing overall complexity while maintaining simple device identification through the device identity level.
Solution Approach 2:
The patent introduces a new dimensional structure by adding component class and instance dimensions to the traditional device-identity mapping. This multi-dimensional identity space enables granular policy enforcement without complicating basic device identification, as policies can be applied selectively across different dimensions.
2Ease of manufacture
If coarse assigned identifiers are used for devices, then identity assignment is simple, but observability platforms cannot provide granular policies
Solution Approach 1:
The identity system is segmented into coarse device-level identifiers and fine-grained component-level identifiers. The device identity provides simple assignment, while component class identities and instance identities enable precise observability measurements without complicating the initial identity assignment process.
Solution Approach 2:
The patent implements a nested identity structure where component identities are nested within device identities, and instance identities are nested within component identities. This nested structure allows coarse device identification to remain simple while enabling fine-grained observability through the nested component and instance levels.
3Adaptability or versatility
If detailed component identities are created for each device component, then granular policy enforcement is enabled, but the number of identities to manage increases significantly
Solution Approach 1:
The patent merges identities at the component class level, where components of the same class share a common identity. This merging reduces the total number of unique identities that need to be managed while still enabling granular policy enforcement at the instance level, balancing adaptability with manageability.
Solution Approach 2:
Component class identities serve multiple functions: they enable grouping of similar components for bulk policy management, provide a level of abstraction that reduces identity count, and still allow instance-level differentiation when needed. This multi-functionality reduces management complexity while maintaining policy granularity.
4Ease of manufacture
If traditional device identity models are used, then implementation is straightforward, but scalability and policy delegation to different organizations is limited
Solution Approach 1:
The identity model is segmented into manageable hierarchical levels that can be independently configured and delegated. This segmentation maintains implementation straightforwardness at each level while enabling scalable deployment and organizational policy delegation across the hierarchical structure.
Data Source
AI summary
In an embodiment, a method includes onboarding a vendor to an object model, generating a component class in the object model, generating a device class in the object model, and generating a device in the object model. The vendor is associated with a vendor identity, the component class is associated with a component class identity, the device class is associated with a device class identity, and the device is associated with a device identity. The method further includes generating an identity record for a component of the device using the vendor identity, the component class identity, the device class identity, and the device identity.


