Hierarchical Access Level Management for Permission Database Simplification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current physical access control systems (PACS) face challenges in managing large permission databases, leading to complex and error-prone administration, increased memory consumption, and costly infrastructure requirements due to the need for frequent updates and the complexity of access level assignments, which often result in over- or under-assignment of permissions.
Innovation Solution
The method organizes access levels into a hierarchical structure, allowing for the identification of sensitive levels, prioritization, and enforcement of policies, recommending removal of unused access levels and splitting high-level access into multiple levels with limited privileges, thereby simplifying administration and reducing redundant permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access levels are organized into groups and roles to simplify administration, then ease of operation is improved, but device complexity increases due to overlapping definitions and difficulty in understanding access level relationships
Solution Approach 1:
The patent segments the permission database into hierarchical groups and roles, organizing access levels in a structured manner. This segmentation allows administrators to manage permissions at multiple levels (groups, roles, individual credentials) rather than managing individual permissions directly, simplifying administration while the hierarchical structure provides clarity through defined relationships between segments
Solution Approach 2:
The patent introduces visual analysis tools and interfaces as intermediaries between administrators and the complex access level relationships. These tools generate visual representations of access level overlaps and relationships, allowing administrators to understand and manage the complexity without directly confronting the raw data structures, thus maintaining ease of operation despite the underlying system complexity
2Reliability
If the permission database is maintained at a central server and downloaded to controllers, then reliability is improved through centralized management, but loss of time increases due to frequent downloads required for updates
Solution Approach 1:
The patent extracts only the necessary permission data from the central server database and downloads it to controllers, rather than downloading entire database updates. This extraction approach maintains reliability by keeping the central server as the authoritative source while significantly reducing update time and bandwidth requirements by transmitting only changed or relevant portions of the permission data
Solution Approach 2:
The patent implements preliminary filtering and preparation of permission data at the central server before download. Changes are identified, validated, and prepared in advance, so that when updates are transmitted to controllers, they are ready-to-apply minimal datasets rather than requiring full database synchronizations, reducing update time while maintaining consistency
3Productivity
If more powerful or larger number of controllers are installed to handle large permission databases, then productivity is improved through better performance, but loss of substance increases due to higher installation costs
Solution Approach 1:
The patent segments the permission database into hierarchical groups and roles that can be efficiently stored and processed. By organizing permissions at multiple levels (groups, roles, individual credentials) rather than maintaining flat individual permission assignments, the system reduces the overall data size and complexity that controllers must handle, enabling standard controllers to manage large enterprises without requiring expensive high-performance hardware
Solution Approach 2:
The patent creates a universal hierarchical permission structure that can be efficiently implemented on standard controllers regardless of enterprise size. The grouped and role-based organization allows the same controller architecture to scale from small to large deployments through software configuration rather than hardware upgrades, reducing installation costs while maintaining productivity through consistent performance
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of operating an access control system containing one or more hierarchies, each of the one or more hierarchies includes one or more access levels is provided. The method including: computing one or more hierarchies; and assigning a primary access level of the one or more access levels within a primary hierarchy of the one or more hierarchies to a first credential; and determining that access levels vertically below the primary access level in the primary hierarchy are implicitly assigned to the first credential when assigning the primary access level of the one or more access levels within the primary hierarchy of the one or more hierarchies to the first credential.