Permission-Based Service Discovery Using Access Context
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing service layer discovery mechanisms lack capabilities for determining permission-based access control, leading to unauthorized access attempts and missed opportunities due to lack of context awareness and feedback on permissions.
Innovation Solution
Implementing permission-based resource and service discovery by including context parameters such as intended operations, roles, locations, and subscription plans in discovery requests, allowing the network node to determine and provide feedback on accessible resources based on permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing service layer discovery mechanisms are used, then resource discovery is enabled, but permission-based access control capability is lost
Solution Approach 1:
The patent applies preliminary action by evaluating permission context before resource discovery occurs. The network node assesses the registrant's permissions, intended operations, roles, and subscription plans in advance to determine whether to return discovery results. This prevents unauthorized access attempts from succeeding while maintaining efficient resource discovery for authorized entities.
Solution Approach 2:
The patent implements feedback by providing the registrant with information about their permission status and which resources they are authorized to access. The discovery response includes permission evaluation results, enabling registrants to understand their access rights and take corrective actions if needed, thereby improving both adaptability and reliability.
2Adaptability or versatility
If context parameters are added to discovery requests, then permission-based access control is enabled, but request complexity increases
Solution Approach 1:
The patent applies universality by designing a multi-functional discovery request structure that handles both traditional resource discovery and permission-based access control evaluation. The same request mechanism accommodates multiple context parameters (intended operations, roles, locations, subscription plans) without requiring separate evaluation processes, thereby enabling permission control while managing complexity through unified processing.
3Reliability
If permission evaluation is performed for all discovery requests, then unauthorized access is prevented, but processing time increases
Solution Approach 1:
The patent applies partial action by performing permission evaluation selectively rather than exhaustively for all possible scenarios. The network node evaluates only the relevant permission context parameters (intended operations, roles, locations, subscription plans) that are necessary for the specific discovery request, avoiding unnecessary processing while maintaining secure access control.
Data Source
AI summary
Current discovery mechanisms lack capabilities, such as capabilities related to permissions associated with a given registrant for example. In an example embodiment, a registrant of a service layer can communicate with a network node that hosts the service layer. The network node may receive a discovery request for a resource from the registrant. The discovery may request include various context. For example, the context of the discovery request may be indicative of an operation that the registrant intends to perform on the resource, a role that the registrant intends to assume if the registrant accesses the resource, a location in which the registrant intends to access the resource, or a subscription plan that the registrant intends to use if the registrant accesses the resource. Based on the context of the discovery request, the network node may determine whether one or more resources at the service layer satisfy the discovery request.


