On-Board Access Control for Disconnected Vehicle Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for providing access control in disconnected environments, such as on-board vehicles, face challenges in authenticating and authorizing devices and users without continuous connectivity to ground-based networks, as they rely on external access control servers and cloud services.
Innovation Solution
A system that includes on-board data storage devices and an authorization and authentication service to authenticate and authorize client applications locally, with synchronized access control information via wireless links to remote data storage, allowing for access control even when disconnected from external networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing access control systems use external servers and cloud services for authentication, then access control functionality can be provided, but the system cannot operate in disconnected environments such as during flight
Solution Approach 1:
The patent divides the access control system into separate functional components: local on-board authentication/authorization services, data storage devices for credentials, and synchronization mechanisms. This segmentation allows the system to operate independently on the vehicle while maintaining ability to synchronize with external systems when connected.
Solution Approach 2:
The system performs preliminary actions by pre-synchronizing access control data and credentials to on-board storage devices before disconnection occurs. This allows authentication and authorization to continue operating with cached credentials during disconnected periods without requiring real-time external server access.
2Adaptability or versatility
If the system stores access control information locally on the vehicle, then it can operate without external connectivity, but the system complexity increases with on-board storage and synchronization infrastructure
Solution Approach 1:
The patent implements universal data storage devices that serve multiple functions: storing access control credentials, caching synchronization data, and providing offline authentication capabilities. This multi-functionality reduces the need for separate dedicated components for each function.
Solution Approach 2:
The system introduces a synchronization service as an intermediary that manages data exchange between on-board storage and external servers. This mediator handles the complexity of bidirectional synchronization, conflict resolution, and data consistency, isolating the complexity from both the authentication service and external systems.
3Stability of the object's composition
If the system synchronizes access control data bidirectionally between on-board and remote systems, then data consistency is maintained, but the synchronization process becomes more complex with conflict resolution requirements
Solution Approach 1:
The synchronization service implements feedback mechanisms by monitoring the state of both on-board and remote data stores, detecting changes, and triggering appropriate synchronization actions. This feedback loop ensures data consistency while providing structured control over the synchronization process.
Solution Approach 2:
The system employs dynamic synchronization strategies that adapt to connection status, data change states, and conflict conditions. The synchronization process can operate in different modes (full sync, incremental sync, conflict resolution) based on real-time system state, reducing unnecessary complexity in stable conditions.
Data Source
AI summary
Techniques for providing access control in environments that may become disconnected, as a whole, from other networks (e.g., on-board a vehicle) may include locally storing access control information within the dis-connectable environment, and locally providing discovery and authentication/authorization services. Local services and/or applications may be registered and authenticated and client applications may be authenticated and/or authorized to one or more locally provided services and/or applications even when the environment is in a disconnected state. Local access control information may be synchronized with source access control information stored externally to the environment (e.g., on the ground). These techniques may easily support different dis-connectable environments that are provided by an environment service provider, as well as support different sets of locally provided public and/or private services and/or applications and different sets of client applications across the different environments.


