Account Identifier Segmentation for Access Control Downtime
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face significant downtime and costs when vulnerabilities are discovered, as replacing or reprogramming digital access controls can be time-consuming and costly, leading to temporary unavailability of resources for authorized users.
Innovation Solution
The implementation of an access management system that assigns multiple account identifiers to each account, allowing different identifiers to be mapped to various interfaces of an account identification card, enabling the deactivation of compromised identifiers without affecting other interfaces, and includes features like single-use, accessor-specific, and geolocation-based restrictions, as well as identifier recycling to minimize downtime.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital access controls are replaced or reprogrammed when vulnerabilities are discovered, then security is improved, but downtime and costs increase significantly
Solution Approach 1:
The patent divides the access control system into multiple independent account identifiers (first account identifier and second account identifier) that can be independently deactivated and activated. This segmentation allows one identifier to be compromised and deactivated without affecting the other identifiers, thereby maintaining system availability while improving security.
Solution Approach 2:
The system dynamically changes the active account identifier parameter by switching between multiple identifiers. When one identifier is found to be vulnerable or compromised, the system deactivates it and activates an alternative identifier, effectively changing the security parameter without requiring complete system replacement or causing downtime.
2Reliability
If digital access controls are replaced or reprogrammed when vulnerabilities are discovered, then security is improved, but costs increase significantly
Solution Approach 1:
By segmenting the access control into multiple account identifiers, the system avoids the need to replace or reprogram the entire access control infrastructure when one identifier is compromised. Only the specific vulnerable identifier needs to be deactivated, while other identifiers continue to function, thereby reducing remediation costs.
Solution Approach 2:
The system creates multiple copies (alternative account identifiers) of the access control credentials. When one copy is compromised, the system can switch to another copy without needing to create entirely new access control infrastructure, reducing the costs associated with vulnerability remediation.
3Reliability
If account identifiers are deactivated when compromised, then security is improved, but resource availability decreases temporarily
Solution Approach 1:
The access control system is segmented into multiple independent account identifiers linked to the same account. When one identifier is deactivated for security reasons, other identifiers remain active and can immediately take over, ensuring continuous resource availability without interruption to authorized users.
Solution Approach 2:
The system performs preliminary action by having alternative account identifiers ready and linked to the account before any compromise occurs. When a vulnerability is detected, the system can immediately switch to a pre-prepared alternative identifier, avoiding any interruption in resource availability.
Data Source
AI summary
An access management system includes a database configured to store access data including account identifiers and accessor identifiers, wherein the access data indicates particular accounts that have been accessed by particular accessors. The access management system also includes a computer system that receives a reservation request comprising an account identifier and an accessor identifier and determines whether the account identifier is included in the database. The computer system also determines, in response to the account identifier being present in the database, whether the access data correlates the account identifier to the accessor and authorizes the reservation of the one or more resources in the account by the accessor in response to the access data correlating the account identifier to the accessor.


