Command-Level Access Control for Secure Device Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for wireless networks and cloud services are inefficient in managing access for shared devices, leading to undesirable sharing scenarios and security concerns.

Innovation Solution

A device command-based security model that allows owners to grant limited access to third-party users by restricting the set of electronic commands available, with options for time-based and location-based controls, using a system that includes a register of devices, guest users, device permissions, and authentication modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control systems are used for wireless networks and cloud services, then device sharing is simplified, but security and management efficiency deteriorate due to undesirable sharing scenarios

Engineering Contradiction:
Improvedevice sharingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control into device-level and command-level authorization. Instead of treating device access as a single unit, it divides control into granular electronic commands, allowing owners to permit specific operations while denying others, thus enabling secure device sharing with precise control over what third-party users can do.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic access control where authorization is not static but can be modified in real-time. Owners can adjust command-level permissions, add or remove authorized commands, and control access based on time-based and location-based criteria, allowing flexible security management that adapts to changing sharing scenarios.

Inventive Principle:
Principle #15Dynamics

2Reliability

If granular command-level access control is implemented, then security and management efficiency improve, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal access control framework that works across multiple device types and cloud services through a common electronic command interface. The system provides multi-functional capabilities including device-level authorization, command-level granularity, time-based controls, location-based controls, and dynamic permission modification, all within a single integrated platform that reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If time-based and location-based controls are added, then access management precision improves, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidaccess control system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple control dimensions (device-level authorization, command-level granularity, time-based controls, and location-based controls) into a unified access control system. Instead of implementing separate systems for each control type, it integrates them into a single framework where all controls work together synergistically, managing precision while controlling complexity through consolidation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3178209B1Device access controls
Publication Date: 2019.12.18 GOOGLE LLC
  • EP3178209B1 patent drawingFigure 1
  • EP3178209B1 patent drawingFigure 2
  • EP3178209B1 patent drawingFigure 3

AI summary

A computer-implemented method includes identifying a set of electronic commands for operation of an electronic device, identifying a guest user, and designating permissions for the guest user, command-by-command, in the set of electronic commands for operating the electronic device. A designated permission for an electronic command in the set of electronic commands includes either granting the guest user access to the electronic device with a privilege of using the electronic command to operate the electronic device, or denying the guest user access to the electronic device and the privilege of using the electronic command to operate the electronic device.