Service Provisioning for Constrained IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing resource management systems in constrained environments lack dynamic conditional access and resource control policies, which are essential for efficient service provisioning and network bandwidth management, especially in scenarios with sleepy nodes and heavy network loads.

Innovation Solution

Implementing a system that uses access control lists (ACLs) with dynamic admission and resource control policies, expressed in conditional expressions, to manage access based on network conditions and device capabilities, allowing for secure and efficient service provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct resource access is allowed for constrained devices, then device connectivity is improved, but network load increases and energy efficiency decreases

Engineering Contradiction:
Improvedevice connectivityVSAvoidnetwork energy consumption
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent introduces a resource directory as an intermediary component between constrained devices and resources. The resource directory mediates resource discovery and access by maintaining a centralized registry of available resources and their locations, allowing constrained devices to perform efficient lookups without direct multicast communication. This mediator approach reduces network traffic while maintaining connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary service registration and discovery mechanisms where resources are pre-registered in the resource directory with their metadata and locations. This preliminary action allows constrained devices to obtain resource information through efficient lookups before actual access occurs, avoiding the need for continuous network scanning and reducing overall network load.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If service commissioning and verification procedures are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improveservice securityVSAvoidcommissioning procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the service commissioning and verification process into distinct functional components: resource registration, service advertisement, commissioner verification, and policy enforcement. Each segment handles a specific aspect of security independently, making the overall complex security framework more manageable and implementable in constrained environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service mechanisms where constrained devices automatically perform service discovery and verification through standardized protocols. The commissioner device autonomously verifies services and enforces policies without requiring manual configuration, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Productivity

If access control policies are enforced for all services, then resource management efficiency is improved, but network throughput decreases

Engineering Contradiction:
Improveresource management efficiencyVSAvoidnetwork throughput
Core Design Contradiction:
ProductivityVSSpeed

Solution Approach 1:

The patent applies local quality by enforcing access control policies selectively based on the specific service, resource type, and client characteristics. Rather than uniform blocking, the system allows differentiated access where appropriate, maintaining security while preserving necessary throughput for authorized services.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic access control policies that can adapt to changing network conditions and service requirements. Policies are not static but can be modified in real-time based on resource availability, client priorities, and network load, allowing the system to optimize between security and throughput dynamically.

Inventive Principle:
Principle #15Dynamics

4Manufacturing precision

If conditional access based on service level agreements is implemented, then resource control precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy enforcement complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent uses parameter changes to express conditional access policies in terms of modifiable parameters such as client identifiers, service types, quality of service levels, and time constraints. By representing policies as parameter-based rules rather than complex logic, the system achieves precise control while keeping the enforcement mechanism simple and manageable.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3295652B1Methods, systems, and apparatuses of service provisioning for resource management in a constrained environment
Publication Date: 2020.02.05 HUAWEI TECH CO LTD
  • EP3295652B1 patent drawingFigure 1~2
  • EP3295652B1 patent drawingFigure 3~4
  • EP3295652B1 patent drawingFigure 5~6

AI summary

The present invention provides a service provisioning method to support configurations of admission control, and resource control policies for constrained devices by using commissioning procedure. In one implementation, the apparatus comprises the obtaining module (808) is configured to obtain at least one service information including at least one pre-registered service along with associated device ID from said commissioning device, the creation module (810) is configured to create at least one service ID against said service information received, and create said admission control policy and/or said resource control policy for said service ID, the lookup module (812) is configured to lookup for service ID associated with said service in said provisioning device, on receipt of at least one request, from said client device, to access said service, and the access module (814) is configured to grant/deny access for said service, based on said policies decided, to said client device.