Access Control via Facility-Task Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems struggle to manage complex access control scenarios involving multiple users and facilities in supply chains, where detailed and diverse access restrictions are necessary, especially when tasks are executed across different facilities.

Innovation Solution

An access control system that manages supply chains as a model, tracks execution history as case data, identifies facilities performing tasks, and references execution facility data to permit access based on facility associations, implementing tenant-and-task-based access control to restrict or allow access accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control by OS and application is used, then basic access control is achieved, but detailed and diverse access control in complex multi-user supply chain systems cannot be handled

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control system segments the supply chain into multiple facilities, each with independent access control policies. Execution facility data is divided into separate records for each facility, allowing granular control over which facilities can access which cases. This segmentation enables detailed access control without requiring complex global policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces execution facility data as an intermediary layer between users and cases. This intermediary contains facility identification information that mediates access decisions by matching the executing facility with authorized facilities in the case data, enabling detailed access control without direct complex user-case mappings.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If access control is restricted to basic OS and application levels, then system simplicity is maintained, but detailed facility-specific access control cannot be implemented

Engineering Contradiction:
Improveaccess control precisionVSAvoiddata structure complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system applies local quality by associating specific facility identification information with each case in the case data. Instead of uniform access control rules, each case can have customized facility associations that define precisely which facilities are authorized to execute its tasks, enabling high-precision access control tailored to local requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements a nested data structure where execution facility data is embedded within case data. The case data contains facility identification information that is nested within the broader supply chain model, allowing detailed facility-specific access control to be integrated seamlessly into the overall system without requiring separate complex management structures.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS20230334386A1Access control system, access control method, and access control program
Publication Date: 2023.10.19 HITACHI LTD
  • US20230334386A1 patent drawing
  • US20230334386A1 patent drawing
  • US20230334386A1 patent drawing

AI summary

An access control system includes: a model management unit that manages a chain of supply-related tasks as a model; a case data management unit that manages an execution history of the supply-related tasks as case data; an execution facility data management unit that manages identification information of a facility that performs the task as execution facility data in association with case identification information; a belonging facility management unit that manages a facility to which an executor of the task belongs; and an access control unit that refers to the execution facility data when access from the executor of the task is accepted, and permits access to a case associated with the facility to which the executor belongs. With such a configuration, detailed access control can be performed for the chain of the supply-related tasks.