Dynamic Access Control for Building Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control systems face security risks due to overpermissioning, where users are granted access to all areas, leading to unauthorized access and increased security concerns, and manual management of access control lists is time-consuming and error-prone.

Innovation Solution

An improved access control system that assigns users a primary set of access allowances and allows users to request permission to access specific zones dynamically, with the access control server making decisions based on criteria such as time, behavior patterns, and zone characteristics, rather than relying on aggregate roles or manual lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are granted access to all areas (overpermissioning), then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access permissions into granular zones and time periods instead of providing blanket access. Users are assigned specific zone access rights for defined time windows, dividing the monolithic access control into manageable segments that balance convenience and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts access permissions based on user role, time of day, and zone characteristics. Access rights are not static but change according to contextual parameters, allowing the system to be permissive when safe and restrictive when necessary, thus resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If manual management of access control lists is used, then adaptability is improved, but productivity is worsened

Engineering Contradiction:
ImproveadaptabilityVSAvoidproductivity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system enables self-service access request functionality where users can autonomously request access to zones they need. This eliminates the need for manual administrator intervention for each access request, significantly improving productivity while maintaining adaptability through automated approval workflows based on predefined criteria.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access control policies are pre-configured with criteria and approval workflows before runtime. The system performs preliminary setup of access rules, time windows, and zone definitions, allowing rapid response to access requests without manual intervention during operation, thus improving productivity while preserving adaptability.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If aggregate roles are used for access control, then device complexity is reduced, but measurement precision is worsened

Engineering Contradiction:
Improvedevice complexityVSAvoidmeasurement precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent implements local quality by assigning different access permissions to different zones based on their specific security requirements and characteristics. Instead of treating all areas uniformly through aggregate roles, each zone can have tailored access criteria, time windows, and approval workflows, achieving precise control without excessive system complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12165454B2Access request mode for access control devices
Publication Date: 2024.12.10 SARGENT MANUFACTURING COMPANY
  • US12165454B2 patent drawing
  • US12165454B2 patent drawing
  • US12165454B2 patent drawing

AI summary

Techniques for controlling access to zones of a building. The techniques include determining with a computing device configured to regulate access to a zone of the building, at a time and responsive to a request to access the zone of the building received via an access control interface, whether a user is allowed to access the zone of the building; and in response to the computing device determining that the user is not allowed to access the zone at the time, receiving, via the access control interface, a request to permit access to the zone at the time; determining, with the computing device and at the time, whether to permit access to the zone based on one or more criteria; and outputting a result of determining whether to permit access to the zone.