Trust Manager Security Broker Embedded Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing secure access to embedded devices in networks is challenging due to the need for numerous security credentials and the difficulty in scaling secure connections, especially as the number of devices grows, leading to inefficiencies and potential security vulnerabilities.
Innovation Solution
Implementing a trust manager and security broker system that authenticates clients and security brokers, establishing secure connections by verifying account information and permissions, reducing the need to store multiple device secrets and minimizing unrestricted access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secure access methods are used for embedded devices, then security credentials must be managed for each device, but this leads to increased device complexity and difficulty in scaling
Solution Approach 1:
The patent introduces a security broker as an intermediary component between clients and embedded devices. The security broker handles authentication and authorization operations, allowing clients to access devices without needing to manage individual security credentials for each device. This mediator approach reduces the complexity of credential management while maintaining security.
Solution Approach 2:
The security broker provides universal access control functionality that can be applied across multiple embedded devices. Instead of requiring device-specific credential management, the system uses a single security broker that handles authentication for all devices, enabling scalable access management.
2Reliability
If numerous security credentials are stored for each embedded device, then access control is maintained, but this increases the number of stored secrets and management overhead
Solution Approach 1:
The patent extracts the security credential storage function from individual embedded devices and consolidates it into a centralized security broker. This extraction removes the burden of storing multiple device secrets from each device, reducing the overall quantity of stored secrets while maintaining access control capabilities.
3Ease of operation
If direct access is granted to embedded devices, then connectivity is established, but this creates unrestricted access and security vulnerabilities
Solution Approach 1:
The security broker serves as a mandatory intermediary between clients and embedded devices. All access requests must pass through the security broker, which applies authentication and authorization policies before allowing device access. This mediator approach maintains ease of operation while preventing unrestricted access.
Data Source
AI summary
A trust manager receives client account information from a client, determines whether the client account information is valid, and determines whether the client is authorized to access one or more embedded devices that are in electronic communication with a security broker. The trust manager also receives security broker account information from the security broker, determines whether the security broker account information is valid, and determines whether the security broker is authorized to provide access to the embedded device(s). If the client account information from the client is valid and the client is authorized to access the embedded device(s), and if the security broker account information from the security broker is valid and the security broker is authorized to provide access to the embedded device(s), the trust manager establishes a secure trusted connection between the client and the security broker.


