AR Access Control for Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computing networks with multiple users and devices, existing technologies face challenges in clearly managing user permissions and executing commands, especially with voice commands, leading to ambiguity and confusion regarding access control.
Innovation Solution
An augmented reality-based system that displays user interface elements to users, allowing them to visualize their permissions and execute commands on network devices, with a security policy module determining authorized actions and context analysis for accurate command execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple users and network devices coexist in the same area, then the network becomes more versatile and functional, but the relationships between user permissions and network devices become confusing and ambiguous
Solution Approach 1:
The patent introduces an intermediary system consisting of a camera, processor, and display that mediates between the user and the network devices. This intermediary visualizes permission relationships by displaying user interface elements overlaid on the camera view, making the complex permission structure transparent and easy to understand without altering the actual network functionality.
Solution Approach 2:
The patent adds a visual dimension to the permission management system by overlaying graphical user interface elements on the camera view. This dimensional transformation converts abstract permission relationships into visible, spatially-contextualized information, allowing users to perceive permission structures in three-dimensional space rather than through complex text-based menus.
2Ease of operation
If voice commands are used for device control, then hands-free operation is achieved, but command ambiguity increases when multiple devices are present
Solution Approach 1:
The visualized user interface elements act as an intermediary that disambiguates voice commands by providing spatial context. When a user speaks a command, the system can associate the command with specific devices based on the visualized interface elements visible in the camera view, thereby maintaining hands-free operation while improving command precision through visual-disambiguation.
Solution Approach 2:
The system provides visual feedback by displaying user interface elements that indicate which network devices are currently accessible and visible to the user. This feedback mechanism allows the voice command system to accurately identify the intended target device by referencing the visually-present interface elements, thus resolving ambiguity while maintaining ease of voice-based operation.
3Reliability
If comprehensive security policies are implemented, then network security is improved, but the complexity of managing user permissions increases
Solution Approach 1:
The patent employs an intermediary visualization system that translates complex security policies into simple visual indicators. The camera and processor analyze the user's view and display overlaid interface elements that represent permission relationships, thereby maintaining comprehensive security policies while presenting them in a simplified, manageable format that reduces administrative complexity.
Solution Approach 2:
The patent utilizes visual differentiation through color or graphical changes to represent different permission levels and device states. By encoding permission information in visual attributes such as color, transparency, or icon styling, the system maintains comprehensive security policies while presenting them through intuitive visual cues that simplify management and understanding.
Data Source
AI summary
A computer system controls access to network devices. One or more user interface elements associated with one or more network devices that are within a view of a user are displayed to the user via an augmented reality display. Input from the user is received comprising instructions to execute a command at a network device of the one or more network devices. The user is determined, according to a security policy, to be authorized to execute the command at the network device. In response to determining that the user is authorized to execute the command, the command is executed at the network device. Embodiments of the present invention further include a method and program product for controlling access to network devices in substantially the same manner described above.


