IP Library Granted Patent US 11,888,748
Granted Patent B2
US 11,888,748 · App. 18/092,042 · Granted Jan 30, 2024

Enforcing access to endpoint resources

Inventors: Scott Dale Brown (Raleigh, NC); Andrew Keats (Seneca, SC); Matthew Rockey (Raleigh, NC); Jason Estes (Spokane, WA)
Assignee: ITRON, INC.
H04L47/20H04L9/3236H04L9/3263H04L47/125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,888,748
App. No.
18/092,042
Granted
Jan 30, 2024
Kind
B2
Abstract

Techniques are directed to controlling access to resources on a message bus of a network communication device. The techniques may include, by the network communication device, processing a message bus access policy file uniquely corresponding to a process. The message bus access policy file may include a certificate securely associating the message bus access policy file with the process. The techniques may further include, by the network communication device, based at least in part on the processing the message bus access policy file, exposing one or more resources of the network communication device to the process on the message bus, in a manner corresponding to at least one resource access permission indication contained within the message bus access policy file.

Claims (46)

1. A method to control access to resources, comprising:

by a hosted distributed intelligence (DI) application, communicating with an agent operating on a network communications device;

by the agent on the network communications device, communicating with the hosted DI application, wherein an access policy file corresponding to the agent includes a certificate securely associating the access policy file with the agent; and

by the network communications device, based at least in part on the access policy file, exposing one or more resources of the network communications device to the agent to provide the agent with access to the one or more resources indicated by the access policy file, wherein the hosted DI application is able to access the one or more resources through operation of the agent.

2. The method of claim 1 , wherein:

the network communications device is a smart utility meter; and

exposing the one or more resources comprises exposing metering data obtained by the smart utility meter.

3. The method of claim 1 , wherein the access policy file governs functionality comprising:

upstream network data limits for each of the one or more resources indicated in the access policy file.

4. The method of claim 1 , wherein the access policy file governs functionality comprising:

a load control switch configured to selectively enable and disable energy loads.

5. The method of claim 1 , wherein the access policy file governs functionality comprising:

gathering of high-speed data related to energy usage and other energy-related parameters.

6. The method of claim 1 , wherein the access policy file governs functionality comprising:

peer-to-peer communications with a smart electric meter or other communications device.

7. The method of claim 1 , wherein the access policy file governs functionality comprising:

tightly coupling each of a plurality of access policy files to a corresponding agent.

8. A system to control access to resources, comprising:

a hosted distributed intelligence (DI) application; and

a network communications device, comprising:

one or more resources;

an agent container; and

an agent operating within the agent container, wherein the agent is configured to include a certificate securely associating an access policy file with the agent, and wherein the agent is configured to perform acts comprising:

communicating with the hosted DI application;

receiving, based at least in part on permissions of the access policy file, resources from the network communications device; and

providing access to the resources to the hosted DI application.

9. The system of claim 8 , wherein:

the agent container comprises a plurality of agents; and

each agent from among the plurality of agents is prioritized with respect to other agents from among the plurality of agents, and wherein an order of termination of the agents is based at least in part on a priority of each agent.

10. The system of claim 8 , wherein the access policy file of the agent specifies how the agent may publicize information about each feature that the agent supports.

11. The system of claim 8 , wherein the access policy file governs whether the agent of the network communications device is subscribable only by devices internal to a network of the system or also by devices external to the network of the system.

12. The system of claim 8 , wherein the access policy file indicates specific network data limits for features supported by the agent.

13. The system of claim 8 , wherein the access policy file is configured in eXtensible Markup Language (XML) statements and organized as categories of an ordered labelled tree.

14. The system of claim 8 , wherein the network communications device comprises electricity usage metrology circuitry.

15. The system of claim 8 , wherein an access control function of the agent defines an amount of resources the agent is permitted to consume prior to the access control function raising an alarm or blocking another agent from further consumption of the resources of the agent.

16. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, configure a system to control access to resources and perform acts comprising:

by a hosted distributed intelligence (DI) application, communicating with an agent operating on a network communications device;

by the agent on the network communications device, communicating with the hosted DI application, wherein an access policy file corresponding to the agent includes a certificate securely associating the access policy file with the agent; and

by the network communications device, based at least in part on the access policy file, exposing one or more resources of the network communications device to the agent to provide the agent with access to the one or more resources indicated by the access policy file, wherein the hosted DI application is able to access the one or more resources through operation of the agent.

17. The one or more non-transitory computer-readable media of claim 16 , wherein an access control function of the agent determines what to do with data after transmission of the data is blocked due to a limit on resources.

18. The one or more non-transitory computer-readable media of claim 16 , wherein the agent comprises a plurality of features, and wherein at least one of the features is utilized by a second agent of the network communications device.

19. The one or more non-transitory computer-readable media of claim 16 , wherein the agent comprises a plurality of features, and wherein one of the plurality of features outputs an alarm responsive to electrical line voltage being measured by a sensor falling below a threshold value.

20. The one or more non-transitory computer-readable media of claim 16 , wherein the agent comprises a plurality of features, the features comprising:

communicating with other network communications devices;

accessing data corresponding to environmental measurements; and

controlling a switch to enable or disable electricity consumption by a device.

Assignments (2)
SECURITY INTEREST Recorded Sep 15, 2025
From: ITRON, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 072870/0873 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2023
From: BROWN, SCOTT DALE; KEATS, ANDREW; ROCKEY, MATTHEW; ESTES, JASON
To: ITRON, INC.
Reel/Frame 062450/0444 →