Physical Security Policy Integration for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing physical security systems lack seamless integration with network and IT systems, leading to non-uniform policy enforcement and compliance across disparate systems, as they operate independently without real-time correlation of physical security data and events with network and IT systems.

Innovation Solution

An integrated physical security management system that normalizes and maps physical security data and events to network and IT systems using a rules-based policy engine, enabling real-time enforcement of security policies across both domains through a standardized data format and interfaces with network equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple physical security systems from different vendors are integrated, then system versatility and coverage are improved, but data representation standards become non-uniform and policy enforcement becomes inconsistent

Engineering Contradiction:
Improvesystem integration capabilityVSAvoiddata representation uniformity
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The patent introduces a normalization layer as an intermediary component that sits between disparate physical security systems and the policy enforcement engine. This normalization layer translates data from various vendor-specific formats into a unified standard format, enabling consistent policy enforcement across heterogeneous systems without requiring changes to the original systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the data representation parameters by transforming different vendor-specific data formats into a standardized normalized format. This parameter transformation allows the same policy enforcement mechanism to work uniformly across all integrated systems regardless of their original vendor-specific representations.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If physical security systems operate independently from network and IT systems, then system simplicity is maintained, but real-time security policy enforcement and risk mitigation are compromised

Engineering Contradiction:
Improvesystem architecture simplicityVSAvoidsecurity policy enforcement effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges physical security systems with network and IT systems by integrating them into a unified policy-based architecture. The physical security systems, network devices, and IT systems all interact through a common policy enforcement point that uses normalized data formats, enabling real-time correlation and coordinated security responses across all domains.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal policy enforcement framework that handles multiple types of security events and systems through a single integrated architecture. The same policy engine and normalized data format serve physical security, network security, and IT security functions, providing multi-functionality that improves reliability while maintaining manageable complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If real-time integration of physical security data with network systems is implemented, then security policy enforcement uniformity is improved, but data processing complexity and system resource requirements increase

Engineering Contradiction:
Improvepolicy enforcement uniformityVSAvoiddata processing complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary normalization of data from physical security systems before it reaches the policy enforcement engine. By pre-processing and standardizing the data format in advance, the system reduces the processing burden during real-time policy enforcement operations, making uniform policy application more efficient despite the complexity of integrating multiple data sources.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9111088B2Policy-based physical security system for restricting access to computer resources and data flow through network equipment
Publication Date: 2015.08.18 HID GLOBAL CORP
  • US9111088B2 patent drawing
  • US9111088B2 patent drawing
  • US9111088B2 patent drawing

AI summary

Embodiments are directed to systems and methods for integration and normalization of physical security data, states and events to and from disparate physical security systems to maintain in real-time rules based policy state information to enforce physical security policies uniformly across network and information technology (IT) systems. Moreover it pertains specifically to such apparatus for providing an integration platform, methods and processes for normalizing data from physical security systems, to maintain physical security states, mapping to network access and either directly affecting the network equipment through standard programming commands or providing interfaces for network equipment and IT applications to query and determine physical security access states thus enforcing rules in real-time based on security systems data and events.