Permission-Based Service Discovery Using Access Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing service layer discovery mechanisms lack capabilities for determining permission-based access control, leading to unauthorized access attempts and missed opportunities due to lack of context awareness and feedback on permissions.

Innovation Solution

Implementing permission-based resource and service discovery by including context parameters such as intended operations, roles, locations, and subscription plans in discovery requests, allowing the network node to determine and provide feedback on accessible resources based on permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing service layer discovery mechanisms are used, then resource discovery is enabled, but permission-based access control capability is lost

Engineering Contradiction:
Improvepermission-based access control capabilityVSAvoidunauthorized access prevention
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by evaluating permission context before resource discovery occurs. The network node assesses the registrant's permissions, intended operations, roles, and subscription plans in advance to determine whether to return discovery results. This prevents unauthorized access attempts from succeeding while maintaining efficient resource discovery for authorized entities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by providing the registrant with information about their permission status and which resources they are authorized to access. The discovery response includes permission evaluation results, enabling registrants to understand their access rights and take corrective actions if needed, thereby improving both adaptability and reliability.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If context parameters are added to discovery requests, then permission-based access control is enabled, but request complexity increases

Engineering Contradiction:
Improvepermission-based access controlVSAvoiddiscovery request structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional discovery request structure that handles both traditional resource discovery and permission-based access control evaluation. The same request mechanism accommodates multiple context parameters (intended operations, roles, locations, subscription plans) without requiring separate evaluation processes, thereby enabling permission control while managing complexity through unified processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If permission evaluation is performed for all discovery requests, then unauthorized access is prevented, but processing time increases

Engineering Contradiction:
Improveaccess control securityVSAvoiddiscovery request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing permission evaluation selectively rather than exhaustively for all possible scenarios. The network node evaluates only the relevant permission context parameters (intended operations, roles, locations, subscription plans) that are necessary for the specific discovery request, avoiding unnecessary processing while maintaining secure access control.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250385918A1Permission based resource and service discovery
Publication Date: 2025.12.18 INTERDIGITAL PATENT HOLDINGS INC
  • US20250385918A1 patent drawing
  • US20250385918A1 patent drawing
  • US20250385918A1 patent drawing

AI summary

Current discovery mechanisms lack capabilities, such as capabilities related to permissions associated with a given registrant for example. In an example embodiment, a registrant of a service layer can communicate with a network node that hosts the service layer. The network node may receive a discovery request for a resource from the registrant. The discovery may request include various context. For example, the context of the discovery request may be indicative of an operation that the registrant intends to perform on the resource, a role that the registrant intends to assume if the registrant accesses the resource, a location in which the registrant intends to access the resource, or a subscription plan that the registrant intends to use if the registrant accesses the resource. Based on the context of the discovery request, the network node may determine whether one or more resources at the service layer satisfy the discovery request.