Secure Zone Access Control for Isolated Electronic Equipment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control methods for electronic equipment in the railroad field are inadequate for isolated or network-less equipment, as they fail to adapt access rights and do not allow for temporary access, posing security risks and requiring cumbersome identifier and authenticator changes.
Innovation Solution
A method using a user-specific computer file with a reference authenticator and access right stored on a computer medium, allowing the electronic equipment to authenticate users and grant secure zone access without a central server, utilizing a removable or virtual medium with optional signature verification and validity dates for secure and adaptable access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a shared identifier and authenticator are used for access control, then the access control method is simple to implement, but it cannot adapt access rights for specific users and does not support temporary access
Solution Approach 1:
The patent segments access control by creating individual computer files for each user, where each file contains user-specific authenticators and access rights. This allows different access rights to be assigned to different users while maintaining a simple file-based implementation structure.
Solution Approach 2:
The patent implements dynamic access rights by storing validity dates in computer files, allowing access rights to be temporarily granted or revoked without changing the underlying system structure. Access rights can be dynamically adjusted by updating the computer files with new authenticators and validity periods.
2Reliability
If identifier and authenticator are changed to revoke access, then security is maintained, but the implementation becomes restrictive and cumbersome
Solution Approach 1:
The patent extracts access control data from the equipment's internal memory and stores it in external computer files on removable media. This allows access rights to be independently managed by replacing or updating computer files without modifying the equipment's internal identifier and authenticator, making access revocation simple and non-restrictive.
3Adaptability or versatility
If a central server is used for authentication, then access control is centralized and manageable, but it requires network connection and is not suitable for isolated equipment
Solution Approach 1:
The patent implements self-service authentication by storing all necessary authentication data (authenticators, access rights, validity dates) directly in computer files that are read by the equipment during the authentication process. The equipment can independently verify user credentials without needing to contact a central server, enabling isolated equipment to maintain secure access control.
4Speed
If access control data is stored in equipment memory, then access is fast and simple, but it cannot support temporary access rights without changing stored data
Solution Approach 1:
The patent implements dynamic access control by storing validity dates in computer files that are read during authentication. The system can quickly determine whether a user's access rights are currently valid by comparing the validity date with the current date, enabling temporary access rights without requiring changes to the underlying authentication data structure or slow reconfiguration processes.
Data Source
AI summary
Disclosed is a method for controlling access to a secure zone of an electronic equipment from a computer file, the equipment including a memory including a reference access right to the electronic equipment. The method includes: —acquiring a reference authenticator via the computer file; acquiring an authenticator from the user; authenticating the user by comparing the authenticator from the user with the reference authenticator; acquiring an access right via the computer file when, at the end of the authentication, the authenticator from the user is compliant with the reference authenticator; and opening an access session to the at least one corresponding secure zone, when the acquired access right corresponds to the reference access right in the memory.

