Building Access Rights Management via Segmented Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing access rights to operating and control data in buildings lack a centralized solution for uniform and secure access, often requiring manual management by authorized personnel and limited to individual systems or components, with no efficient way to grant selective remote access while ensuring data security and role-based access.
Innovation Solution
A system comprising a first server for building authorization and a second server for communication release, with an authentication database storing user-specific access rights, allowing users to register centrally and access multiple buildings with a single identity, separating authentication from access rights management, and providing role-based user interfaces for secure and uniform data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access rights are managed individually for each system or component by authorized personnel, then data security is maintained, but access efficiency and uniformity across multiple buildings deteriorate
Solution Approach 1:
The system segments access management into two independent modules: authentication (handled by the authentication server) and authorization (handled by the building authorization service). This segmentation allows each module to specialize in its function, improving both security and efficiency. The authentication server verifies user identities centrally, while the authorization service manages building-specific access rights, eliminating the need for manual management at each building while maintaining security.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between users and building systems. This intermediary centralizes identity verification and coordinates with building authorization services to grant access. The intermediary handles the complex coordination of authentication and authorization, simplifying the access process for users while maintaining robust security controls across multiple buildings.
2Reliability
If manual management of access rights is performed by authorized personnel, then security control is maintained, but time consumption and operational complexity increase
Solution Approach 1:
The system enables self-service access management where users can autonomously authenticate themselves through the authentication server using their credentials. The automated authentication process eliminates the need for manual intervention by authorized personnel in routine access granting, significantly reducing time consumption. Security control is maintained through automated verification against centralized authentication and authorization databases.
Solution Approach 2:
The patent implements automated authentication and authorization processes that accelerate the access grant/revoke cycle. The system rapidly verifies user identities and checks authorization rights against building-specific data, enabling quick access decisions without manual intervention. This acceleration maintains security control while dramatically reducing the time required for access management operations.
3Ease of operation
If centralized authentication is implemented, then access uniformity across buildings is improved, but system complexity and data management burden increase
Solution Approach 1:
The system divides centralized authentication into separate functional components: the authentication server handles identity verification, while the authorization database manages building-specific access rights. This segmentation reduces the burden on any single system component and simplifies data management. The authentication server provides uniform access control across all buildings, while the authorization service handles building-specific configurations independently.
Solution Approach 2:
The patent extracts the authentication function from individual building systems and centralizes it in a dedicated authentication server. This extraction simplifies the overall system architecture by removing authentication complexity from each building while maintaining centralized control. The authentication server provides uniform access control across multiple buildings, while building-specific authorization data remains managed locally by the authorization service.
4Reliability
If selective remote access is granted to specific persons, then data security is maintained, but access flexibility and remote capability are limited
Solution Approach 1:
The system implements dynamic access rights management where authorization is not static but can be adjusted based on user roles, building types, and specific data requirements. The authorization database stores building-specific access rights that can be selectively granted or modified. This dynamic approach maintains data security through controlled access while providing flexibility for remote access to authorized personnel across different buildings and roles.
Solution Approach 2:
The authentication server provides universal access control functionality across multiple buildings and different types of users. A single authentication mechanism serves all users regardless of their specific building or role, providing access flexibility. The building authorization service complements this by providing multi-functionality in managing different authorization levels and building-specific requirements, enabling secure remote access for diverse user needs.
Data Source
AI summary
Method for operating a system for managing access rights to operating and/or control data from buildings or building complexes (5), in which a communication enabling service running on a first server (3) enables communication by a user who is logged on with an identity with the buildings or building complexes (5) which are stored for said user in a list (4) if the identity of said user matches an identity that is stored in the list (4), and, when the communication has been enabled by the communication enabling service, a building authorization service running on a second server (2) enables specific access rights for the user to operating and/or control data from the building or building complex (5) on the basis of access rights that are stored in an authorization database (20).
