Message Bus Access Policy for IoT Endpoint Resource Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multiple agents on an IoT endpoint can lead to resource overload and threats to privacy and security due to unrestricted access to capabilities and features, such as communication bandwidth overload and potential malicious or accidental disruptions in energy management systems.

Innovation Solution

Implementing a message bus access policy file that securely associates permissions with each process, controlling access to resources based on resource access permission indications within the policy file, ensuring only authorized access and preventing unauthorized changes or modifications during execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple agents are allowed to access IoT endpoint resources, then functionality and versatility are improved, but resource overload and system reliability deteriorate

Engineering Contradiction:
ImprovefunctionalityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments access control by creating individual policy files for each agent-process pair. Each policy file contains specific permission indications that divide and control access to different resources (communication medium, metrology data, load control switches) on a per-agent basis, preventing any single agent from overloading the system while allowing multiple agents to function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy files as an intermediary layer between agents and endpoint resources. These policy files act as mediators that enforce access control rules, allowing the system to support multiple agents (improving versatility) while preventing resource overload (maintaining reliability) through controlled access enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If agents are given broad access to endpoint capabilities, then ease of operation is improved, but security and privacy protection worsen

Engineering Contradiction:
Improveaccess easeVSAvoidsecurity threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by granting different access permissions to different agents based on their specific needs. Each policy file contains customized permission indications that give agents only the minimum necessary access to specific resources (e.g., communication medium, metrology data), making operation easy for authorized functions while preventing security threats through restricted access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of access permissions by encoding specific allow/deny indications in policy files for each agent-process combination. This allows the system to maintain ease of operation for authorized agents while preventing security threats by dynamically controlling access parameters based on policy definitions.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If unrestricted agent access is permitted, then adaptability is improved, but loss of information and privacy worsen

Engineering Contradiction:
Improveagent access flexibilityVSAvoidprivacy protection
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments information access by creating policy-specific permission indications for each agent. This segmentation allows the system to maintain adaptability by supporting multiple agents while preventing privacy loss by ensuring each agent can only access information explicitly permitted in its policy file, such as controlling access to metrology data and customer information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11888748B2Enforcing access to endpoint resources
Publication Date: 2024.01.30 ITRON INC
  • US11888748B2 patent drawing
  • US11888748B2 patent drawing
  • US11888748B2 patent drawing

AI summary

Techniques are directed to controlling access to resources on a message bus of a network communication device. The techniques may include, by the network communication device, processing a message bus access policy file uniquely corresponding to a process. The message bus access policy file may include a certificate securely associating the message bus access policy file with the process. The techniques may further include, by the network communication device, based at least in part on the processing the message bus access policy file, exposing one or more resources of the network communication device to the process on the message bus, in a manner corresponding to at least one resource access permission indication contained within the message bus access policy file.