Data Access Control Using Dual Identifier Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for controlling access to data from electrical installations lack secure mechanisms to prevent unauthorized access when a user changes, particularly in the transition between communication gateways and management units, compromising the security of confidential data.

Innovation Solution

A method that involves exchanging frames between management units and relay platforms with unique identifiers, comparing access parameters, and using temporal counters to authorize access only when identifiers match and within a predetermined time frame, ensuring secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the system allows access to data using only the management unit identifier, then ease of operation is improved, but security deteriorates as former users can continue accessing data after user changes

Engineering Contradiction:
Improveease of data accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access control mechanism is segmented into two distinct identifier components: the management unit identifier (first identifier) and the communication gateway identifier (second identifier). This segmentation allows the system to verify both the management unit's identity and the current gateway's identity, preventing former users from accessing data even if they know the management unit identifier, while maintaining ease of operation for authorized users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The communication gateway acts as an intermediary element in the access control process. By incorporating the gateway's identifier into the access verification mechanism, the system introduces a dynamic layer of security that automatically updates when gateways change. This intermediary approach maintains ease of operation for legitimate users while inherently preventing unauthorized access by former users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system implements strict access control verification, then security is improved, but device complexity increases due to additional identifier comparison steps

Engineering Contradiction:
Improvedata securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system performs self-service by automatically obtaining both identifiers, comparing them, and making access authorization decisions without requiring external intervention or complex manual verification processes. The relay platform autonomously handles the identifier comparison and access control logic, achieving high security while keeping the system relatively simple.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the verification parameter from a single static identifier to a combination of two identifiers with different roles (management unit identifier and communication gateway identifier). This parameter change enables robust security verification while maintaining system simplicity, as the comparison logic remains straightforward despite involving multiple parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system stores and processes multiple identifiers for each frame, then security is improved, but loss of time increases due to additional processing steps

Engineering Contradiction:
Improveaccess control securityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by obtaining and storing both identifiers during the initial frame exchange process between the management unit and relay platform. This preliminary capture of identifier information eliminates the need for time-consuming retrieval operations during access verification, as both identifiers are already available in the stored frame data for immediate comparison.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10148652B2Method for controlling access to data relating to an electrical installation, associated computer programme and information medium
Publication Date: 2018.12.04 SCHNEIDER ELECTRIC IND SAS
  • US10148652B2 patent drawing
  • US10148652B2 patent drawing
  • US10148652B2 patent drawing

AI summary

A controlling access to data exchanged between a management unit of a respective electrical installation and a relay platform, each management unit has a first identifier which is linked to a global network by a gateway having a second identifier between each management unit and the platform, for each frame, obtaining the first identifier, receiving the platform of a request to access the data exchanged, the request including an access parameter and a third identifier of an element originating the transmission of the request, determining the first identifier on which the access parameter depends, comparing the third identifier with the second identifier exchanged by the management unit having the first determined identifier, authorizing access, for the communication terminal, to the data exchanged by the management unit having the first determined identifier, if, in the comparison step, the second and third identifiers are identical.