Account Management and Access Control
Tenant account
A tenant account is the isolated space on Live Objects dedicated to a specific customer: every interaction between Live Objects and an external actor (user, device, client application, etc.) or registered entities (user accounts, API keys, etc.) is associated with a tenant account.
Live Objects ensures isolation between those accounts: you can’t access the data and entities managed in another tenant account.
Each tenant account is identified by a unique identifier: the tenant ID.
A tenant account also has a name, that should be unique.
User account
A User Account represents a user identity, that can access the Live Objects web portal.
A user account is identified by a login. A user account is associated with one or many roles. A user can authenticate on the Live Objects web portal using a login and password.
When user authentication request succeeds, a temporary API key is generated and returned, with same roles as the User account.
In case of too many invalid login attempts, the user account is locked out for a while.
For security purpose, a password must be at least 12 characters including at least 1 uppercase letter, 1 lowercase letter, 1 special character and 1 digit.
API key
A Live Objects API key is a secret that can be used by a device, an application, or a user to authenticate when accessing to Live Objects on the MQTT or HTTPS/REST interfaces. At least one API key must be generated. As a security measure, an API key can not be retrieved after creation (As describe in this section), .
An API key belongs to a tenant account: after authentication, all interactions will be associated only to this account (and thus isolated from other tenant accounts).
An API key can have zero, one or many Roles. These roles allow to restrict the operations that could be performed with the key.
An API key validity can be limited in time.
Creating a tenant account automatically attribute a "master" API key.
That API key is special: it can’t be deleted.
An API key can generate child-API keys that inherit (a subset of) the parent roles and validity period.
An API key can be restrained to one or more message queues:
-
If one or more message queues are selected, the API key can access only these queues.
-
If no message queue is selected, the API key has no restriction and can access any queue.
Thus, the API key can only be used in MQTT access limited to these selected message queues. This for example, makes it possible, after having oriented the right device to the right queue, to restrict access to the data of specific devices.
Usage:
-
In MQTT, clients must connect to Live Objects by using a valid API key value in the password field of the (first) MQTT « CONNECT » packet,
-
In case of unknown API key value, or invalid, the connection is refused.
-
On success, all messages published on this connection will be enriched with the API key id and roles.
-
-
In HTTPS, clients must specify a valid API key value as HTTP header X-API-Key for every request,
-
In case of unknown API key value, request is refused (HTTP status 403).
-
In case of invalid API key value, request is refused (HTTP status 401).
-
On success, all messages published due to this request will be enriched with the API key id and roles.
-
Role
A Role is attributed to an API key or User Account. It defines the privileges on Live Objects. A Role is attributed to an API key or User Account.
|
Important Notice : Some features are only available if you have subscribed to the corresponding offer, so you may have the proper roles set on your user but no access to some features because these features are not activated on your tenant account (check the tenant offer). The currently available roles and their inclusion in Admin or User profiles: |
| Role Name | Technical value | Admin profile | User profile | Privileges |
|---|---|---|---|---|
API key |
API_KEY_R |
X |
X |
Read parameters and status of an API key. |
API key |
API_KEY_W |
X |
X |
Create, modify, disable an API key. |
User |
USER_R |
X |
X |
Read parameters and status of a user. |
User |
USER_W |
X |
Create, modify, disable a user. |
|
Settings |
SETTINGS_R |
X |
X |
Read the tenant account custom settings. |
Settings |
SETTINGS_W |
X |
X |
Create, modify tenant account custom settings. |
Device |
DEVICE_R |
X |
X |
Read parameters and status of a Device management. |
Device |
DEVICE_W |
X |
Create, modify, disable a Device management, send command, modify config, update resource of a Device. |
|
Device Campaign |
CAMPAIGN_R |
X |
X |
Read parameters and status of a massive deployment campaign on your Device Fleet. |
Device Campaign |
CAMPAIGN_W |
X |
Create, modify a campaign on your Device Fleet. |
|
Device Bootstrap |
BOOTSTRAP_R |
X |
X |
Read parameters and status of the LwM2M Bootstrap configurations and entries. |
Device Bootstrap |
DEVICE_W |
X |
Create ans modify LwM2M Bootstrap configurations and entries. |
|
Data |
DATA_R |
X |
X |
Read the data collected by the Store Service or search into this data using the Search Service. |
Data |
DATA_W |
X |
Insert a data record to the Store Service. Minimum permission required for the API key of a device pushing data to Live Objects in HTTPS. |
|
Data Processing |
DATA_PROCESSING_R |
X |
X |
Read parameters and status of an Action policy rule, an event processing rule or a Data decoder or a FIFO queue. |
Data Processing |
DATA_PROCESSING_W |
X |
Create, modify, disable an Action policy rule, an event processing rule or a Data decoder. |
|
Bus Config |
BUS_CONFIG_R |
X |
X |
(Deprecated) Read config parameters of a FIFO queue. |
Bus Config |
BUS_CONFIG_W |
X |
(Deprecated) Create, modify a FIFO queue. |
|
Bus Access |
BUS_R |
X |
X |
Read data from Live Objects FIFOs. Minimum permission for the API key of an application collecting data on Live Objects in MQTT(s). |
Bus Access |
BUS_W |
X |
X |
(Deprecated) Publish data on the Live Objects bus. |
Bus Access |
DEVICE_ACCESS |
X |
X |
Role to set on a Device API key to allow only MQTT Device mode |
Bus Access |
CONNECTOR_ACCESS |
X |
X |
Role to set on an external connector API key to allow only MQTT external connector mode |
Audit Log |
LOGS_R |
X |
X |
Read the logs collected by the Audit Log service. This right allows users to use the Audit Log service as debugging tool. |