CONTEXT AWARE AUTHORIZATION FOR DATA AND SERVICES IN THE IOT/M2M SERVICE LAYER
An Authorization Verification Service (AVS) is disclosed that may be provided by an IoT/M2M service layer to registrants of the service layer for Dynamic Context Aware Authorization. The AVS may allow the IoT/M2M service layer entities to define dynamic limits for authorizing access to services or data. The limits may be set, for example, in terms of the number of allowed accesses. When an IoT/M2M registrant makes a request for data or services for which it has dynamic context aware authorization, the AVS may maintain records of the remaining accesses available.
1 . A method implemented by an authorization verification service of a service layer, the method comprising:
receiving, from a device, a request to access at least one of data or a service made available by the service layer;
determining an authorization policy associated with the at least one of the data or service made available by the service layer;
determining one or more context aware states associated with the authorization policy, wherein the one or more context aware states comprise an indication of one or more conditions for accessing the at least one of the data or service made available by the service layer, and wherein the one or more conditions comprise a number of allowed accesses to the at least one of the data or service made available by the service layer;
determining whether the one or more conditions associated with the one or more context aware states are valid; and
granting, to the device and based on determining that the one or more conditions associated with the one or more context aware states are valid, access to the at least one of the data or service made available by the service layer.
2 . The method of claim 1 , wherein the one or more conditions associated with the one or more context aware states further comprise a time duration for accessing the at least one of the data or service made available by the service layer.
3 . The method of claim 1 , wherein the one or more conditions associated with the one or more context aware states further comprise a type of device that is allowed access to the at least one of the data or service made available by the service layer.
4 . The method of claim 1 , wherein the one or more conditions associated with the one or more context aware states are independent of the device and the request to access the at least one of the data or service made available by the service layer.
5 . The method of claim 1 , wherein the authorization verification service determines the context aware states based on one or more of data stored by the service layer or operations performed by the service layer.
6 . The method of claim 1 , wherein the one or more context aware states are stored in the authorization policy.
7 . The method of claim 1 , further comprising updating, based on granting access to the at least one of the data or service made available by the service layer, the one or more context aware states associated with the authorization policy.
8 . An apparatus comprising a processor and a memory, the memory storing computer-executable instructions which, when executed by the processor, implement a service layer of a communications network and cause an authorization verification service of the service layer to perform operations comprising:
receiving, from a device, a request to access at least one of data or a service made available by the service layer;
determining an authorization policy associated with the at least one of the data or service made available by the service layer;
determining one or more context aware states associated with the authorization policy, wherein the one or more context aware states comprise an indication of one or more conditions for accessing the at least one of the data or service made available by the service layer, and wherein the one or more conditions comprise a number of allowed accesses to the at least one of the data or service made available by the service layer;
determining whether the one or more conditions associated with the one or more context aware states are valid; and
granting, to the device and based on determining that the one or more conditions associated with the one or more context aware states are valid, access to the at least one of the data or service made available by the service layer.
9 . The apparatus of claim 8 , wherein the one or more conditions associated with the one or more context aware states further comprise a time duration for accessing the at least one of the data or service made available by the service layer.
10 . The apparatus of claim 8 , wherein the one or more conditions associated with the one or more context aware states further comprise a type of device that is allowed access to the at least one of the data or service made available by the service layer.
11 . The apparatus of claim 8 , wherein the one or more conditions associated with the one or more context aware states are independent of the device and the request to access the at least one of the data or service made available by the service layer.
12 . The apparatus of claim 8 , wherein the authorization verification service determines the context aware states based on one or more of data stored by the service layer or operations performed by the service layer.
13 . The apparatus of claim 8 , wherein the one or more context aware states are stored in the authorization policy.
14 . The apparatus of claim 8 , wherein the instructions, when executed, further cause the authorization verification service of the service layer to perform operations comprising updating, based on granting access to the at least one of the data or service made available by the service layer, the one or more context aware states associated with the authorization policy.
15 . A computer-readable storage medium storing computer-executable instructions which, when executed by a processor, cause an authorization verification service of a service layer to perform operations comprising:
receiving, from a device, a request to access at least one of data or a service made available by the service layer;
determining an authorization policy associated with the at least one of the data or service made available by the service layer;
determining one or more context aware states associated with the authorization policy, wherein the one or more context aware states comprise an indication of one or more conditions for accessing the at least one of the data or service made available by the service layer, and wherein the one or more conditions comprise a number of allowed accesses to the at least one of the data or service made available by the service layer;
determining whether the one or more conditions associated with the one or more context aware states are valid; and
granting, to the device and based on determining that the one or more conditions associated with the one or more context aware states are valid, access to the at least one of the data or service made available by the service layer.
16 . The computer-readable storage medium of claim 15 , wherein the one or more conditions associated with the one or more context aware states further comprise a time duration for accessing the at least one of the data or service made available by the service layer.
17 . The computer-readable storage medium of claim 15 , wherein the one or more conditions associated with the one or more context aware states further comprise a type of device that is allowed access to the at least one of the data or service made available by the service layer.
18 . The computer-readable storage medium of claim 15 , wherein the one or more conditions associated with the one or more context aware states are independent of the device and the request to access the at least one of the data or service made available by the service layer.
19 . The computer-readable storage medium of claim 15 , wherein the authorization verification service determines the context aware states based on one or more of data stored by the service layer or operations performed by the service layer.
20 . The computer-readable storage medium of claim 15 , wherein the one or more context aware states are stored in the authorization policy.