Automated Access Provisioning Framework for Physical Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current physical access control systems (PACS) face challenges in efficiently managing and assigning dynamic permissions, particularly in large organizations, due to the complexity of static permissions databases and the need for manual administration, which can lead to errors and policy violations.

Innovation Solution

A framework for access provisioning in PACS that includes a permissions request interface, a permissions recommendation module, a permissions validation module, and an approval workflow identification module, which automates the process of assigning or revoking permissions based on user attributes, static permissions, and access control policies to ensure compliance and reduce administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual permission assignment is used in PACS, then administrators can control access permissions, but the process becomes time-consuming and error-prone due to the large number of permissions and cardholders

Engineering Contradiction:
Improvepermission assignment processVSAvoidtime required for administrative tasks
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service through automated permission assignment where the PACS automatically determines and assigns permissions to cardholders based on their attributes and organizational policies, eliminating the need for manual administrator intervention in routine permission assignments

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention changes the approach from static manual permission assignment to dynamic automated assignment based on cardholder attributes (such as job title, department, location) and organizational policies, allowing permissions to be automatically adjusted as attributes change

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If manual permission assignment is used in PACS, then administrators can control access permissions, but the process becomes error-prone leading to policy violations

Engineering Contradiction:
Improvepermission assignment processVSAvoidaccess control policy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system incorporates feedback mechanisms where the PACS continuously monitors permission assignments against organizational policies and provides feedback to correct potential violations, ensuring that automated permission assignments comply with established access control policies

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The invention performs preliminary validation of permission assignments against organizational policies before execution, preventing policy violations from occurring in the first place by checking compliance requirements in advance of the permission assignment

Inventive Principle:
Principle #10Preliminary action

3Speed

If static permissions database is maintained centrally, then access control decisions can be made quickly, but the system becomes complex to manage and update

Engineering Contradiction:
Improveaccess decision response timeVSAvoidpermissions database management
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The invention segments the permission management function by separating the central permissions database from the decision-making logic, allowing the database to remain centralized for fast access while the complexity of managing and updating permissions is distributed to automated systems and local controllers

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3590101B1A framework for access provisioning in physical access control systems
Publication Date: 2022.01.26 CARRIER CORP
  • EP3590101B1 patent drawingFigure 1
  • EP3590101B1 patent drawingFigure 2
  • EP3590101B1 patent drawingFigure 3

AI summary

A framework for access provisioning in a physical access control system (PACS). The framework includes a permissions request interface, the permissions request interface configured to permit a user or an administrator to request for a permission to access/revoke access to a resource, a permissions recommendation module communicating with the permissions request interface to receive the request and recommending a permission to be assigned to, or removed from, the user. The framework also includes a permissions validation module operable to ensure that the permission to be assigned to or to be removed does not violate an existing access control policy, that the permission to be assigned permits access to all permitted resources, or that the permission to be removed from the user denies access to all revoked resources and an approval workflow identification module identifying an approval required to assign or remove the permission.