Access Privilege Management via Group Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing access privileges in networked devices are cumbersome and lack alternatives for customizing privileges, especially when dealing with multiple devices and users, leading to complex administration.

Innovation Solution

A method that involves selecting access identities, accumulating access privileges for each function of networked devices, presenting these privileges in an editable interface, and configuring access based on changes, allowing decentralized processing to simplify management and reduce processing power.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access privileges are set individually for each user and each camera, then customization of access privileges is improved, but system complexity and administrative burden increase significantly

Engineering Contradiction:
Improvecustomization of access privilegesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access privilege management process into distinct components: user group definition, camera group definition, and privilege assignment. By dividing users into groups and cameras into groups, the system allows administrators to manage privileges at a group level rather than individually for each user-camera pair, reducing complexity while maintaining customization capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of organization by grouping users and cameras into hierarchical structures. Instead of managing access in a flat one-to-one manner, the system creates multi-dimensional groupings where users can belong to multiple user groups and cameras to multiple camera groups, enabling complex access patterns through simpler group-based assignments

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If access privileges are managed for a large number of users and devices, then system functionality is improved, but administrative burden and processing requirements increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidadministrative burden
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent merges multiple access privilege assignments into unified camera groups. By combining multiple cameras into a single camera group and assigning user groups to that camera group, the system processes multiple privilege assignments in a single operation, significantly reducing administrative time and processing requirements compared to configuring each camera individually

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal camera groups that can serve multiple purposes and multiple user groups simultaneously. A single camera group can be assigned to different user groups with different privilege levels, and the same camera group can be used across multiple contexts, reducing redundant configuration work and processing overhead

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8713643B2Method and devices for handling access privileges
Publication Date: 2014.04.29 AXIS
  • US8713643B2 patent drawing
  • US8713643B2 patent drawing
  • US8713643B2 patent drawing

AI summary

A method and apparatus are disclosed for configuring access privileges in a system of networked devices. A plurality of access identities is selected and information of access privileges of each of the selected access identities to accessible functions of networked devices is retrieved. The access privileges of the selected access identities for each one of said accessible function of each one of said networked devices is accumulated. The accumulated access privileges are presented for each one of said accessible function of each one of said networked devices in an interface allowing editing of the accumulated access privileges. Change in accumulated access privileges to a specific function in a specific networked device is indicated, and the specific function of the specific networked device is configured for allowing access by the selected users in accordance with the indicated change of accumulated access privileges.