Cloud Credentialing for Service Tool Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service tools for accessing equipment controllers lack effective credential management, especially in networked/wireless environments, where physical presence is not required, leading to potential unauthorized access and inadequate access control.

Innovation Solution

A cloud-based credentialing service that verifies user information through a networked server, providing access credentials with time constraints and customizable access levels, ensuring secure and controlled access to equipment controllers via service tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If networked/wireless service tools are used to replace physically connected service tools, then ease of operation and remote access capability are improved, but security control and access management deteriorate

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A cloud-based credentialing service is introduced as an intermediary between the service tool and the equipment controller. The service tool obtains credentials from the cloud credentialing service, which verifies user information and provides time-constrained access credentials. This mediator enables remote access while maintaining security through centralized credential management and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-programmed certificates are used to verify user credentials, then authentication capability is improved, but flexibility and adaptability to different circumstances deteriorate

Engineering Contradiction:
Improveauthentication capabilityVSAvoidflexibility to different circumstances
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The credentialing system transitions from static pre-programmed certificates to dynamic credentials generated on-demand by the cloud credentialing service. Credentials are generated based on real-time verification of user information and can be customized with different time constraints, access levels, and scope of access. This dynamic approach maintains strong authentication while adapting to different service scenarios and user requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters of credential verification by moving from fixed pre-programmed certificates to dynamically generated credentials with variable parameters including time constraints, access levels, and scope limitations. The cloud credentialing service can adjust these parameters based on the specific service situation, user role, and equipment type, providing both strong authentication and flexibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3435268B1Service tool credential management
Publication Date: 2021.11.24 OTIS ELEVATOR CO
  • EP3435268B1 patent drawingFigure 1
  • EP3435268B1 patent drawingFigure 2
  • EP3435268B1 patent drawingFigure 3

AI summary

A service tool credential management system includes a storage medium operable to store a plurality of instructions and at least one processor configured to execute the instructions to send a credential request (204) to a networked server to access an equipment controller with a service tool (22). The at least one processor is further configured to execute the instructions to receive an access credential (206) responsive to the credential request (204) and utilizing one or more fields of the access credential (206) during interactions with the equipment controller to enable a level of access for the service tool (22) to the equipment controller corresponding to the access credential (206).