Building PII Mask Templates for Attribute-Level Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponential increase in data produced by building management systems (BMS) devices necessitates effective analysis and management of private information, which existing systems struggle to manage efficiently, particularly in terms of attribute-level access control and storage requirements.

Innovation Solution

A building system that utilizes mask templates to selectively mask private information based on access values, such as role, device type, and geographic location, reducing the need for user-specific access tables and enabling efficient attribute-level protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used to manage private information in building management systems, then access control functionality is provided, but storage requirements and processing power increase exponentially with the number of entities and access permissions

Engineering Contradiction:
Improveaccess controlVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments access control into template-based rules that can be independently stored and applied. Instead of storing complete access matrices for all user-entity pairs, the system divides access control into reusable templates that define access patterns, significantly reducing the storage required to manage access permissions across numerous entities and users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal mask templates that can be applied across multiple entities and user types. A single template can serve multiple access control scenarios, allowing the system to manage diverse access requirements with a limited set of reusable templates, thereby reducing both storage requirements and processing overhead.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional access control methods are used to manage private information in building management systems, then access control functionality is provided, but processing power requirements increase to handle user-specific access tables

Engineering Contradiction:
Improveaccess controlVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent performs preliminary action by pre-defining access control rules in mask templates that can be directly applied to entities. This eliminates the need for real-time computation of access permissions from user-specific tables, as the templates already contain the processed access logic ready for immediate application, significantly reducing processing power requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by replicating mask templates across multiple entities rather than creating unique access tables for each user-entity pair. This allows the system to efficiently manage access control by copying and applying the same template logic repeatedly, reducing both processing power and storage requirements compared to maintaining separate access tables for every combination.

Inventive Principle:
Principle #26Copying

3Quantity of substance

If mask templates are used for attribute-level access control, then storage requirements and processing power are reduced, but system complexity increases due to template management

Engineering Contradiction:
Improvestorage requirementsVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling automatic selection and application of appropriate mask templates based on entity attributes and user context. The system autonomously determines which template to apply without requiring manual configuration for each access scenario, reducing the operational complexity of managing templates while maintaining the storage efficiency benefits.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If user-specific access tables are maintained for each entity, then fine-grained access control is achieved, but the system becomes difficult to maintain and extend with new entities

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem extensibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent achieves universality by designing mask templates that can be applied across diverse entity types and user contexts. This allows the system to maintain fine-grained access control through template attributes while simultaneously being highly extensible, as new entities can inherit and apply existing templates without requiring custom access table configurations, thus improving both ease of operation and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12400035B2Building system with smart entity personal identifying information (PII) masking
Publication Date: 2025.08.26 JOHNSON CONTROLS TECHNOLOGY CO
  • US12400035B2 patent drawing
  • US12400035B2 patent drawing
  • US12400035B2 patent drawing

AI summary

A building system for operating a building and managing private building information includes a processing circuit configured to receive a request for information for a building entity of a building entity database. The processing circuit is configured to select one of the mask templates from the entity database based on access values associated with the requesting device and a relational link between the building entity and the mask templates, retrieve private information for the building entity in response to a reception of the request for the information, and generate a masked information data structure based on the private information and the one of the mask templates.