Passlet-Based Access Control Broker for Smart Spaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems in distributed networks are overly complex, making it difficult for non-expert users to manage access control across networked devices, as they require understanding of various security protocols and mechanisms, leading to underutilization due to intimidation and complexity.
Innovation Solution
The introduction of 'passlets' as user-perceived entities that abstract security concepts, allowing users to easily manage access control through user-level tools, which translate high-level user intent into specific security settings, independent of the underlying security framework, enabling intuitive interaction and access management across networked devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security mechanisms and protocols are implemented in networked devices, then security guarantees are improved, but user complexity and difficulty of operation increase
Solution Approach 1:
The patent introduces a middleware layer called the 'access control broker' that sits between users and the complex security infrastructure. This broker translates simple user-level access requests into appropriate security mechanism selections and configurations, hiding the complexity of multiple security protocols from end users while maintaining strong security guarantees through proper mechanism selection and coordination
2Reliability
If multiple security mechanisms are implemented at different levels, then security coverage is improved, but system complexity increases
Solution Approach 1:
The access control broker is designed as a universal intermediary that can handle multiple types of security mechanisms and protocols through a single unified interface. It provides multi-functional capabilities to translate various user-level access control requests into appropriate security mechanism configurations, reducing the need for separate specialized components for each security protocol
Solution Approach 2:
The broker acts as a mediating layer that coordinates multiple security mechanisms without requiring direct integration between them. It selects and configures appropriate security mechanisms based on user requests and device characteristics, managing the complexity of multiple security layers through centralized control and abstraction
3Adaptability or versatility
If security mechanisms require user configuration, then security customization is improved, but ease of operation deteriorates
Solution Approach 1:
The access control broker automatically selects and configures appropriate security mechanisms based on user-level requests and device characteristics, eliminating the need for users to manually configure complex security settings. The system performs self-service by translating high-level user intent into specific security configurations automatically
Solution Approach 2:
The broker serves as an intermediary that translates simple user requests into detailed security configurations. Users interact with the broker at a high level without needing to understand underlying security mechanisms, while the broker handles the customization and configuration of appropriate security measures based on the requested access control policies
Data Source
AI summary
Management of access control in wireless networks known as smart spaces includes a framework that presents non-expert users with a consistent and intuitive interaction mechanism to manage access to devices they own in the smart space without exposing to them the complexity of the underlying security infrastructure. Access control of devices in a network can include providing an interface between a user-level tool on a first device connected to a network and security components associated with the network, communicating a passlet between the user-level tool and the interface, verifying access permission at a second device on the network where access permissions are based on the passlet, and providing a response to the first device based on the verification of the access permission in the passlet. The passlet provides access permissions based on a particular user rather than a particular device.


