Data Access Control Using Dual Identifier Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for controlling access to data from electrical installations lack secure mechanisms to prevent unauthorized access when a user changes, particularly in the transition between communication gateways and management units, compromising the security of confidential data.
Innovation Solution
A method that involves exchanging frames between management units and relay platforms with unique identifiers, comparing access parameters, and using temporal counters to authorize access only when identifiers match and within a predetermined time frame, ensuring secure data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the system allows access to data using only the management unit identifier, then ease of operation is improved, but security deteriorates as former users can continue accessing data after user changes
Solution Approach 1:
The access control mechanism is segmented into two distinct identifier components: the management unit identifier (first identifier) and the communication gateway identifier (second identifier). This segmentation allows the system to verify both the management unit's identity and the current gateway's identity, preventing former users from accessing data even if they know the management unit identifier, while maintaining ease of operation for authorized users.
Solution Approach 2:
The communication gateway acts as an intermediary element in the access control process. By incorporating the gateway's identifier into the access verification mechanism, the system introduces a dynamic layer of security that automatically updates when gateways change. This intermediary approach maintains ease of operation for legitimate users while inherently preventing unauthorized access by former users.
2Reliability
If the system implements strict access control verification, then security is improved, but device complexity increases due to additional identifier comparison steps
Solution Approach 1:
The access control system performs self-service by automatically obtaining both identifiers, comparing them, and making access authorization decisions without requiring external intervention or complex manual verification processes. The relay platform autonomously handles the identifier comparison and access control logic, achieving high security while keeping the system relatively simple.
Solution Approach 2:
The system changes the verification parameter from a single static identifier to a combination of two identifiers with different roles (management unit identifier and communication gateway identifier). This parameter change enables robust security verification while maintaining system simplicity, as the comparison logic remains straightforward despite involving multiple parameters.
3Reliability
If the system stores and processes multiple identifiers for each frame, then security is improved, but loss of time increases due to additional processing steps
Solution Approach 1:
The system performs preliminary action by obtaining and storing both identifiers during the initial frame exchange process between the management unit and relay platform. This preliminary capture of identifier information eliminates the need for time-consuming retrieval operations during access verification, as both identifiers are already available in the stored frame data for immediate comparison.
Data Source
AI summary
A controlling access to data exchanged between a management unit of a respective electrical installation and a relay platform, each management unit has a first identifier which is linked to a global network by a gateway having a second identifier between each management unit and the platform, for each frame, obtaining the first identifier, receiving the platform of a request to access the data exchanged, the request including an access parameter and a third identifier of an element originating the transmission of the request, determining the first identifier on which the access parameter depends, comparing the third identifier with the second identifier exchanged by the management unit having the first determined identifier, authorizing access, for the communication terminal, to the data exchanged by the management unit having the first determined identifier, if, in the comparison step, the second and third identifiers are identical.


