IoT Identity Model Segmentation for Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT systems face challenges in managing device identities effectively, leading to difficulties in updating policy enforcements and providing granular observability, especially when devices generate traffic.

Innovation Solution

The proposed solution involves an IoT identity model that allows for refined filtering and policy groupings based on subcomponents within a device class instance. This model includes generating identity records for components using vendor, component class, device class, and device identities, and aggregating these records into groups for policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a one-to-one mapping between device and identity is used, then device identification is simple, but policy management complexity increases and granular observability is lost

Engineering Contradiction:
Improvedevice identificationVSAvoidpolicy management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the identity system into multiple hierarchical levels: device identity, component class identity, and instance identity. This segmentation allows policy management to operate at different granularities, reducing overall complexity while maintaining simple device identification through the device identity level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional structure by adding component class and instance dimensions to the traditional device-identity mapping. This multi-dimensional identity space enables granular policy enforcement without complicating basic device identification, as policies can be applied selectively across different dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If coarse assigned identifiers are used for devices, then identity assignment is simple, but observability platforms cannot provide granular policies

Engineering Contradiction:
Improveidentity assignment simplicityVSAvoidobservability precision
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The identity system is segmented into coarse device-level identifiers and fine-grained component-level identifiers. The device identity provides simple assignment, while component class identities and instance identities enable precise observability measurements without complicating the initial identity assignment process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested identity structure where component identities are nested within device identities, and instance identities are nested within component identities. This nested structure allows coarse device identification to remain simple while enabling fine-grained observability through the nested component and instance levels.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If detailed component identities are created for each device component, then granular policy enforcement is enabled, but the number of identities to manage increases significantly

Engineering Contradiction:
Improvepolicy enforcement granularityVSAvoidnumber of identities to manage
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges identities at the component class level, where components of the same class share a common identity. This merging reduces the total number of unique identities that need to be managed while still enabling granular policy enforcement at the instance level, balancing adaptability with manageability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Component class identities serve multiple functions: they enable grouping of similar components for bulk policy management, provide a level of abstraction that reduces identity count, and still allow instance-level differentiation when needed. This multi-functionality reduces management complexity while maintaining policy granularity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If traditional device identity models are used, then implementation is straightforward, but scalability and policy delegation to different organizations is limited

Engineering Contradiction:
Improveimplementation straightforwardnessVSAvoidscalability and policy delegation
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The identity model is segmented into manageable hierarchical levels that can be independently configured and delegated. This segmentation maintains implementation straightforwardness at each level while enabling scalable deployment and organizational policy delegation across the hierarchical structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250175389A1Method and System for Device Identity Management
Publication Date: 2025.05.29 CISCO TECHNOLOGY INC
  • US20250175389A1 patent drawing
  • US20250175389A1 patent drawing
  • US20250175389A1 patent drawing

AI summary

In an embodiment, a method includes onboarding a vendor to an object model, generating a component class in the object model, generating a device class in the object model, and generating a device in the object model. The vendor is associated with a vendor identity, the component class is associated with a component class identity, the device class is associated with a device class identity, and the device is associated with a device identity. The method further includes generating an identity record for a component of the device using the vendor identity, the component class identity, the device class identity, and the device identity.