IoT Device Provisioning via Pre-existing User Roles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT networks face challenges in implementing user-friendly security and access management, particularly in ad hoc networks with hidden controls and communication pathways, leading to limited adoption of trust, privacy, safety, and security measures.

Innovation Solution

A computer-implemented method and apparatus that automates the provisioning of IoT devices by discovering available devices, accessing preexisting user roles and relationships, reviewing recommended privilege levels, establishing secure links, and creating access control lists based on these factors to manage IoT device functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access control management is implemented in conventional IoT networks, then security control is achieved, but system complexity and ease of operation deteriorate due to the need for manual user addition and credential sharing

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically discovering IoT devices and pre-configuring access control lists based on device types and network roles before users need to access them. This eliminates the need for manual user addition and credential distribution, resolving the contradiction between security control and ease of operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing IoT devices to automatically join the network and establish secure connections without manual intervention. Devices self-provision themselves by receiving appropriate access credentials based on their device type and intended functionality, eliminating the need for users to manually manage access controls

Inventive Principle:
Principle #25Self-service

2Ease of operation

If full control access is provided to all users in conventional IoT networks, then access simplicity is improved, but security and privacy deteriorate due to lack of per-user permission management

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity and privacy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies local quality by creating customized access control lists for different device types and user roles. Each IoT device receives tailored permissions based on its specific functionality and the user's role in the network, rather than applying uniform access rights to all users. This allows access simplicity for legitimate users while maintaining security through differentiated permissions

Inventive Principle:
Principle #3Local quality

3Productivity

If automated device provisioning is implemented, then ease of operation and productivity are improved, but device complexity increases due to automated security configuration

Engineering Contradiction:
Improveprovisioning speedVSAvoidsecurity configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary security manager component that handles the complexity of automated security configuration. This intermediary automatically discovers IoT devices, determines appropriate access control policies based on device types, and provisions security credentials without requiring the IoT devices themselves to be complex. The complexity is centralized in the security manager rather than distributed across individual devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10623497B2Leveraging pre-existing groups for IoT device access
Publication Date: 2020.04.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10623497B2 patent drawing
  • US10623497B2 patent drawing
  • US10623497B2 patent drawing

AI summary

The application is directed to a computer-implemented method and apparatus for provisioning an Internet of Things (IoT) device on an IoT network. The application is also directed to a method for managing access to functionality of an IoT device in a networked group.