IP Library Granted Patent US 11,765,586
Granted Patent B2
US 11,765,586 · App. 16/771,728 · Granted Sep 19, 2023

Context aware authorization for data and services in the IoT/M2M service layer

Inventors: William Robert Flynn, IV (Schwenksville, PA); Dale N. Seed (Allentown, PA); Zhuo Chen (Claymont, DE); Quang Ly (North Wales, PA); Catalina Mihaela Mladin (Hatboro, PA); Rocco Di Girolamo (Laval, CA)
Assignee: Convida Wireless, LLC
H04W12/08H04W4/70H04W12/37H04W12/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,765,586
App. No.
16/771,728
Granted
Sep 19, 2023
Kind
B2
Abstract

An Authorization Verification Service (AVS) is disclosed that may be provided by an IoT/M2M service layer to registrants of the service layer for Dynamic Context Aware Authorization. The AVS may allow the IoT/M2M service layer entities to define dynamic limits for authorizing access to services or data. The limits may be set, for example, in terms of the number of allowed accesses. When an IoT/M2M registrant makes a request for data or services for which it has dynamic context aware authorization, the AVS may maintain records of the remaining accesses available.

Claims (41)

1. A method implemented by an authorization verification service of a service layer, the method comprising:

receiving, from a device, a request to access at least one of data or a service made available by the service layer;

determining an authorization policy associated with information indicative of prior access attempts for the at least one of the data or service made available by the service layer;

determining one or more context aware states associated with the authorization policy, wherein the one or more context aware states comprise an indication of a plurality of conditions for accessing the at least one of the data or service made available by the service layer, and wherein the plurality of conditions comprise a number of allowed accesses to the at least one of the data or service made available by the service layer within a defined period of time;

determining whether the plurality of conditions associated with the one or more context aware states are valid;

granting, to the device and based on determining that the plurality of conditions associated with the one or more context aware states are valid, access to the at least one of the data or service made available by the service layer;

determining the defined period of time elapses; and

resetting the number of allowed accesses, based on the elapsed period of time, to the at least one of the data or service made available by the service layer.

2. The method of claim 1 , wherein the one or more conditions associated with the one or more context aware states further comprise a time duration for accessing the at least one of the data or service made available by the service layer.

3. The method of claim 1 , wherein the one or more conditions associated with the one or more context aware states further comprise a type of device that is allowed access to the at least one of the data or service made available by the service layer.

4. The method of claim 1 , wherein the one or more conditions associated with the one or more context aware states are independent of the device and the request to access the at least one of the data or service made available by the service layer.

5. The method of claim 1 , wherein the authorization verification service determines the context aware states based on one or more of data stored by the service layer or operations performed by the service layer.

6. The method of claim 1 , wherein the one or more context aware states are stored in the authorization policy.

7. The method of claim 1 , further comprising updating, based on granting access to the at least one of the data or service made available by the service layer, the one or more context aware states associated with the authorization policy.

8. An apparatus comprising a processor and a memory, the memory storing computer-executable instructions which, when executed by the processor, implement a service layer of a communications network and cause an authorization verification service of the service layer to perform operations comprising:

receiving, from a device, a request to access at least one of data or a service made available by the service layer;

determining an authorization policy associated with information indicative of prior access attempts for the at least one of the data or service made available by the service layer;

determining one or more context aware states associated with the authorization policy, wherein the one or more context aware states comprise an indication of a plurality of conditions for accessing the at least one of the data or service made available by the service layer, and wherein the plurality of conditions comprise a number of allowed accesses to the at least one of the data or service made available by the service layer within a defined period of time;

determining whether the plurality of conditions associated with the one or more context aware states are valid;

granting, to the device and based on determining that the plurality of conditions associated with the one or more context aware states are valid, access to the at least one of the data or service made available by the service layer;

determining the defined period of time elapses; and

resetting the number of allowed access, based on the elapsed period of time, to the at least one of the data or service made available by the service layer.

9. The apparatus of claim 8 , wherein the one or more conditions associated with the one or more context aware states further comprise a time duration for accessing the at least one of the data or service made available by the service layer.

10. The apparatus of claim 8 , wherein the one or more conditions associated with the one or more context aware states further comprise a type of device that is allowed access to the at least one of the data or service made available by the service layer.

11. The apparatus of claim 8 , wherein the one or more conditions associated with the one or more context aware states are independent of the device and the request to access the at least one of the data or service made available by the service layer.

12. The apparatus of claim 8 , wherein the authorization verification service determines the context aware states based on one or more of data stored by the service layer or operations performed by the service layer.

13. The apparatus of claim 8 , wherein the one or more context aware states are stored in the authorization policy.

14. The apparatus of claim 8 , wherein the instructions, when executed, further cause the authorization verification service of the service layer to perform operations comprising updating, based on granting access to the at least one of the data or service made available by the service layer, the one or more context aware states associated with the authorization policy.

15. A non-transitory computer-readable storage medium storing computer-executable instructions which, when executed by a processor, cause an authorization verification service of a service layer to perform operations comprising:

receiving, from a device, a request to access at least one of data or a service made available by the service layer;

determining an authorization policy associated information indicative of prior access attempts for with the at least one of the data or service made available by the service layer;

determining one or more context aware states associated with the authorization policy, wherein the one or more context aware states comprise an indication of a plurality of conditions for accessing the at least one of the data or service made available by the service layer, and wherein the plurality of conditions comprise a number of allowed accesses to the at least one of the data or service made available by the service layer within a defined period of time;

determining whether the plurality of conditions associated with the one or more context aware states are valid;

granting, to the device and based on determining that the plurality of conditions associated with the one or more context aware states are valid, access to the at least one of the data or service made available by the service layer;

determining the defined period of time elapses; and

resetting the number of allowed accesses, based on the elapsed period of time, to the at least one of the data or service made available by the service layer.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more conditions associated with the one or more context aware states further comprise a time duration for accessing the at least one of the data or service made available by the service layer.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more conditions associated with the one or more context aware states further comprise a type of device that is allowed access to the at least one of the data or service made available by the service layer.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more conditions associated with the one or more context aware states are independent of the device and the request to access the at least one of the data or service made available by the service layer.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the authorization verification service determines the context aware states based on one or more of data stored by the service layer or operations performed by the service layer.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more context aware states are stored in the authorization policy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2025
From: CONVIDA WIRELESS, LLC
To: INTERDIGITAL PATENT HOLDINGS, INC.
Reel/Frame 071773/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2020
From: FLYNN, WILLIAM ROBERT, IV; SEED, DALE N.; CHEN, ZHUO; LY, QUANG; MLADIN, CATALINA MIHAELA; DI GIROLAMO, ROCCO
To: CONVIDA WIRELESS, LLC
Reel/Frame 052903/0535 →
Continuity (2)
Provisional Application 62607006 · Dec 18, 2017
Related Publication 20210176637A1 · Jun 10, 2021