Fine-grained IoT access control via device proxies and SDN-based micro-segmentation

    公开(公告)号:US11070562B2

    公开(公告)日:2021-07-20

    申请号:US15962849

    申请日:2018-04-25

    Applicant: VMware, Inc.

    Abstract: Techniques for implementing fine-grained access control in an IoT (Internet of Things) deployment are provided. In one set of embodiments, a gateway of the IoT deployment can create/maintain a device proxy pertaining to an IoT device and a persona in the IoT deployment, where the device proxy includes one or more access methods for accessing the IoT device, and where the one or more access methods reflect access rights that are deemed appropriate for the persona with respect to the IoT device. An application instance of the IoT deployment can receive a request from the persona to access the IoT device. Networking equipment interconnecting the application instance with the gateway can then automatically route, via one or more SDN micro-segmentation rules, the request to the device proxy for processing via the proxy's access methods.

    FINE-GRAINED IOT ACCESS CONTROL VIA DEVICE PROXIES AND SDN-BASED MICRO-SEGMENTATION

    公开(公告)号:US20190334918A1

    公开(公告)日:2019-10-31

    申请号:US15962849

    申请日:2018-04-25

    Applicant: VMware, Inc.

    Abstract: Techniques for implementing fine-grained access control in an IoT (Internet of Things) deployment are provided. In one set of embodiments, a gateway of the IoT deployment can create/maintain a device proxy pertaining to an IoT device and a persona in the IoT deployment, where the device proxy includes one or more access methods for accessing the IoT device, and where the one or more access methods reflect access rights that are deemed appropriate for the persona with respect to the IoT device. An application instance of the IoT deployment can receive a request from the persona to access the IoT device. Networking equipment interconnecting the application instance with the gateway can then automatically route, via one or more SDN micro-segmentation rules, the request to the device proxy for processing via the proxy's access methods.

Patent Agency Ranking