IP Library Granted Patent US 12,413,592
Granted Patent B2
US 12,413,592 · App. 17/775,336 · Granted Sep 9, 2025

Secure data orchestrator for IoT networks

Inventors: Victor Danilchenko (South Hadley, MA); John Brodeur (Londonderry, NH)
Assignee: Schneider Electric USA, Inc.
H04L63/102H04L43/08H04L63/0876H04L63/10H04L67/1072H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,592
App. No.
17/775,336
Granted
Sep 9, 2025
Kind
B2
Abstract

Techniques are described for securely routing data with an Internet of Things environment. A data orchestrator receives a plurality of data values collected by the endpoint device from an endpoint device and determines an identifier that uniquely identifies the endpoint device. The data orchestrator accesses one or more routing tables using the determined identifier and device type data corresponding to the plurality of data values to determine one or more data consumers to route the plurality of data values to. The one or more routing tables were dynamically generated based on at least one of (i) device claim information relating to the endpoint device, (ii) license data relating to the one or more data consumers, and (iii) user information associated with the one or more data consumers. The data orchestrator transmits at least a portion of the plurality of data values to the determined one or more data consumers.

Claims (38)

1. A method, comprising:

receiving, at a data orchestrator, from an endpoint device, a plurality of data values collected by the endpoint device;

determining an identifier that uniquely identifies the endpoint device;

accessing one or more routing tables using the determined identifier and device type data corresponding to the plurality of data values to determine one or more data consumers to route the plurality of data values to, wherein the one or more routing tables were generated based on at least one of (i) device claim information relating to the endpoint device, (ii) license data relating to the one or more data consumers, and (iii) user information associated with the one or more data consumers; and

providing, by the data orchestrator, at least a portion of the plurality of data values from the endpoint device to the determined one or more data consumers for consumption,

wherein the endpoint device comprises one of a plurality of Internet of Things (IoT) devices within an IoT network, and different layers of IoT stack are decoupled from each other within a tenancy context to allow sharing of data between tenancy stovepipes.

2. The method of claim 1 , wherein the identifier that uniquely identifies the endpoint device comprises a unique identifier assigned to the endpoint device by a manufacturer of the endpoint device at a time of manufacture of the endpoint device.

3. The method of claim 1 , wherein the plurality of data values collected by the endpoint device comprise a plurality of sensor data values collected by one or more sensor devices of the endpoint device.

4. The method of claim 3 , wherein the one or more routing tables are dynamically generated by an access control component based on data received from one or more data aggregation components, and wherein the one or more data aggregation components are configured to collect, aggregate and normalize access control-related data from a plurality of sources.

5. The method of claim 1 , wherein the device claim information further comprises user information associated with a device registration operation for the endpoint device.

6. The method of claim 1 , wherein the license data relating to the one or more data consumers further comprises an indication from a license service specifying one or more license types for one or more licenses procured by the one or more data consumers and an indication of whether the one or more licenses are presently valid.

7. The method of claim 1 , wherein the user information associated with the one or more data consumers further comprises a user credential included in a registration of the one or more data consumers.

8. The method of claim 1 , wherein providing at least a portion of the plurality of data values to the determined one or more data consumers further comprises at least one of (i) transmitting the at least a portion of the plurality of data values to the one or more data consumers using a push methodology, (ii) transmitting the at least a portion of the plurality of data values to the one or more data consumers using a pub/sub methodology, and (iii) providing an Application Programming Interface (API) through which the one or more data consumers can request the at least a portion of the plurality of data values and, responsive to such a request, transmitting the at least a portion of the plurality of data values to the one or more data consumers using a pull methodology.

9. The method of claim 1 , wherein the endpoint device comprises a plurality of endpoint devices, the one or more consumers comprises a plurality of consumers, and the data orchestrator is configured to transmit selectively the plurality of data values from the plurality of endpoint devices to the plurality of consumers according to the one or more routing tables using the identifier of the endpoint device and the device data type which correspond to the plurality of data values.

10. A system, comprising:

one or more computer processors; and

a non-transitory memory containing computer program code that, when executed by operation of the one or more computer processors, performs an operation comprising:

receiving, at a data orchestrator, from an endpoint device, a plurality of data values collected by the endpoint device;

determining an identifier that uniquely identifies the endpoint device;

accessing one or more routing tables using the determined identifier and device type data corresponding to the plurality of data values to determine one or more data consumers to route the plurality of data values to, wherein the one or more routing tables were dynamically generated based on at least one of (i) device claim information relating to the endpoint device, (ii) license data relating to the one or more data consumers, and (iii) user information associated with the one or more data consumers; and

transmitting, by the data orchestrator, at least a portion of the plurality of data values from the endpoint device to the determined one or more data consumers for consumption,

wherein the endpoint device comprises one of a plurality of Internet of Things (IoT) devices within an IoT network, and different layers of IoT stack are decoupled from each other within a tenancy context to allow sharing of data between tenancy stovepipes.

11. The system of claim 10 , wherein the identifier that uniquely identifies the endpoint device comprises a unique identifier assigned to the endpoint devices by a manufacturer of the endpoint device at a time of manufacture of the endpoint device.

12. The system of claim 10 , wherein the plurality of data values collected by the endpoint device comprise a plurality of sensor data values collected by one or more sensor devices of the endpoint device.

13. The system of claim 10 , wherein the device claim information further comprises user information associated with a device registration operation for the endpoint device.

14. The system of claim 10 , wherein the license data relating to the one or more data consumers further comprises an indication from a license service specifying one or more license types for one or more licenses procured by the one or more data consumers and an indication of whether the one or more licenses are presently valid.

15. The system of claim 10 , wherein the user information associated with the one or more data consumers further comprises a user credential included in a registration of the one or more data consumers.

16. A non-transitory computer-readable medium containing computer program code that, when executed by operation of one or more computer processors, performs an operation comprising:

receiving, at a data orchestrator, from an endpoint device, a plurality of data values collected by the endpoint device;

determining an identifier that uniquely identifies the endpoint device;

accessing one or more routing tables using the determined identifier and device type data corresponding to the plurality of data values to determine one or more data consumers to route the plurality of data values to, wherein the one or more routing tables were dynamically generated based on at least one of (i) device claim information relating to the endpoint device, (ii) license data relating to the one or more data consumers, and (iii) user information associated with the one or more data consumers; and

transmitting, by the data orchestrator, at least a portion of the plurality of data values from the endpoint device to the determined one or more data consumers for consumption,

wherein the endpoint device comprises one of a plurality of Internet of Things (IoT) devices within an IoT network, and different layers of IoT stack are decoupled from each other within a tenancy context to allow sharing of data between tenancy stovepipes.

17. The non-transitory computer-readable medium of claim 16 , wherein the identifier that uniquely identifies the endpoint device comprises a unique identifier assigned to the endpoint device by a manufacturer of the endpoint device at a time of manufacture of the endpoint device.

18. The non-transitory computer-readable medium of claim 16 , wherein the plurality of data values collected by the endpoint device comprise a plurality of sensor data values collected by one or more sensor devices of the endpoint device.

19. The non-transitory computer-readable medium of claim 16 , wherein the device claim information further comprises user information associated with a device registration operation for the endpoint device.

20. The non-transitory computer-readable medium of claim 16 , wherein the license data relating to the one or more data consumers further comprises an indication from a license service specifying one or more license types for one or more licenses procured by the one or more data consumers and an indication of whether the one or more licenses are presently valid.

21. The non-transitory computer-readable medium of claim 16 , wherein the user information associated with the one or more data consumers further comprises a user credential included in a registration of the one or more data consumers.

Continuity (2)
Provisional Application 62933767 · Nov 11, 2019
Related Publication 20220394031A1 · Dec 8, 2022
References Cited (15)
US 10931743B1 · Chou · 2021 [cited by examiner]
US 20090092124A1 · Singhal et al. · 2009 [cited by applicant]
US 20130179548A1 · Singh et al. · 2013 [cited by applicant]
US 20150019710A1 · Shaashua et al. · 2015 [cited by applicant]
US 20160127254A1 · Kumar et al. · 2016 [cited by applicant]
US 20180270231A1 · Bauer · 2018 [cited by examiner]
US 20190028552A1 · Johnson, II et al. · 2019 [cited by applicant]
EP 2270622A2 · 2011 [cited by applicant]
EP 2270622A3 · 2012 [cited by applicant]
EP 3528148A1 · 2019 [cited by applicant]
WO 2019183628A1 · 2019 [cited by applicant]
Extended European Search Report and Search Opinion dated Aug. 24, 2023 for corresponding European Patent Application No. 20888208.4, 9 pages. [cited by applicant]
Pahl et al. “An architecture pattern for trusted orchestration in IoT edge clouds.” In: 2018 Third International Conference on Fog and Mobile Edge Computing (FMEC). Apr. 26, 2018. Retrieved on Jan. 12, 2021, 10 pp. [cited by applicant]
Wen et al. “Fog orchestration for IoT services: issues, challenges and directions.” In: IEEE Internet Computing. Mar. 1, 2017. Retrieved on Jan. 12, 2021, 8 pp. [cited by applicant]
International Search Report and Written Opinion mailed Feb. 11, 2021 in International Application No. PCT/US2020/059890, 17 pp. [cited by applicant]