Dynamic Access Rights Grouping for Time-Varying Networked Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control methods in networked systems with data processing, particularly in IoT environments, are complex and error-prone due to their reliance on hierarchical structures, which become cumbersome with dynamic user and device roles, and do not efficiently manage temporary access or changes in group memberships.

Innovation Solution

A method that groups objects and users based on time-varying properties using logical queries, fuzzy logic, and neural networks, allowing for dynamic and flexible access rights management without a strict hierarchical structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a hierarchical structure is used to manage access rights, then access control can be organized systematically, but the system becomes complex and error-prone when managing dynamic user and device roles

Engineering Contradiction:
Improveaccess control structureVSAvoiddynamic role management
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control by allowing object groups to be formed and modified based on time-varying properties without requiring a fixed hierarchical structure. Objects can be dynamically added to or removed from groups as their properties change, enabling flexible adaptation to evolving user and device roles while maintaining systematic organization through property-based grouping rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses time-varying properties as parameters to dynamically determine object group membership and access rights. Instead of static hierarchical assignments, access control decisions are based on changing parameters such as user roles, device states, and temporal conditions, allowing the system to adapt to dynamic scenarios while maintaining structured control through parameter-driven grouping.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If hierarchical access control is used, then systematic permission management is achieved, but temporary access and group membership changes become cumbersome

Engineering Contradiction:
Improvepermission managementVSAvoidadministrative overhead
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system establishes preliminary grouping rules based on time-varying properties that automatically determine object group membership. Instead of manually adjusting hierarchies when roles change, the rules are pre-configured to automatically assign objects to appropriate groups based on their current properties, eliminating the need for time-consuming administrative interventions when temporary access or role changes occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Objects automatically determine their own group membership based on their time-varying properties and the predefined grouping rules. The system self-adjusts access control configurations without requiring administrator intervention for routine changes, reducing administrative overhead while maintaining systematic permission management through property-driven automatic grouping.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If role-based access control with additional hierarchical levels is used, then large numbers of users and groups can be managed, but the system remains dependent on strict hierarchical structures

Engineering Contradiction:
Improvenumber of users and groupsVSAvoidhierarchical structure
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the access control system into independent object groups based on time-varying properties rather than nesting them in hierarchical levels. Each group is formed independently based on specific property criteria, allowing the system to manage large numbers of users and objects through parallel, non-hierarchical groupings that reduce structural complexity while maintaining scalable organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from managing access control along the hierarchical dimension (levels and sublevels) to organizing objects along the property dimension (time-varying characteristics). This dimensional shift allows large numbers of users and groups to be managed through property-based categorization rather than hierarchical nesting, reducing structural complexity while maintaining scalability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3878197B1Controlling access rights in a networked system with data processing
Publication Date: 2025.12.31 SAMSON AG
  • EP3878197B1 patent drawingFigure 1
  • EP3878197B1 patent drawingFigure 2
  • EP3878197B1 patent drawingFigure 3

AI summary

The invention relates to a method for the computer-aided administration of authorizations or access rights in a networked system with data processing. The method involves subdivision or grouping of objects (O1,..., Ot) in the system such as files, devices, application programs etc. into object groups. Membership of an object group determines whether an access right to an object (O1,..., Ot) is granted to a user (N1,..., N,) or refused. The object groups are formed with the aid of rules which relate to at least one property of the objects (O1,..., Ot), particularly a property that varies over time. Assignment of the objects (O1,..., Ot) to an object group is continuously updated, so that it is only possible to access objects (O1,..., Ot) with specified properties. As a result, administration of the access rights is more reliable and also easier, as hierarchical organizational structures are not required. The method is particularly suitable for security-critical systems such as supply systems for district heat, natural gas, power or water, or process engineering machinery and equipment.