Policy-Based Asset Access Control via Local Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access management systems are inflexible, insecure, and difficult to scale, especially in shared asset environments where connectivity is limited or unavailable, and they struggle to enforce personalized and time-restricted access conditions, making them vulnerable to attacks and hard to integrate across multiple providers and manufacturers.

Innovation Solution

A system and method using a novel policy management data model and distributed computer communication architecture that leverages public key cryptography and white-box cryptography to establish secure communication channels, allowing policy owners to generate and enforce secure access policies independently of connectivity, with policies being tied to unique fingerprints for secure communication and enforcement by the asset itself.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional access management systems use physical keys or centralized server connections, then access can be granted to shared assets, but the systems become inflexible, require significant infrastructure, and cannot enforce personalized access conditions or time restrictions

Engineering Contradiction:
Improvepersonalized access conditionsVSAvoidinfrastructure requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The asset device autonomously enforces access policies locally without requiring continuous server connectivity. The policy module on the asset device independently evaluates access requests against stored policies and controls asset operation accordingly, enabling the system to function in offline modes while maintaining personalized access conditions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system divides access management functionality into distributed policy modules that can be stored and executed locally on the asset device. This segmentation allows the system to operate without centralized server infrastructure while still enforcing personalized access policies, resolving the contradiction between adaptability and infrastructure complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If fully connected solutions are used where assets and sharing entities connect to remote servers, then centralized policy management is possible, but connectivity requirements limit deployment in environments like underground parking structures

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidconnectivity mode flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to different connectivity modes (online, offline, partial connectivity) by switching between centralized policy updates and local policy enforcement. The asset device can receive policy updates when connected and autonomously enforce policies when disconnected, ensuring reliable access control across varying connectivity conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Access policies are pre-loaded and stored on the asset device before connectivity is needed for enforcement. This preliminary action ensures that the asset can reliably enforce personalized access conditions even when disconnected from servers, eliminating the contradiction between reliability and connectivity flexibility.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If offline solutions using Bluetooth or NFC are used, then connectivity requirements are reduced, but all users must share the same cryptographic keys creating security risks and making custom restrictions difficult

Engineering Contradiction:
Improvecustom restrictionsVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Each user receives a unique policy with customized restrictions tailored to their specific access needs, rather than sharing a common key set. The policy module on the asset device evaluates each user's unique policy locally, enabling custom restrictions while maintaining security through individualized cryptographic credentials.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces a policy module as an intermediary layer between the cryptographic key system and asset control. This policy module enables custom restrictions by evaluating user-specific policies against the asset's operation parameters, allowing differentiated access control without requiring all users to share the same cryptographic keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If centralized server-based access management is used, then policy coordination is simplified, but operational costs increase and scaling to multiple providers and manufacturers becomes difficult

Engineering Contradiction:
Improveoperational efficiencyVSAvoidinfrastructure costs
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The asset device autonomously manages access policy enforcement locally without requiring continuous server operations. This self-service capability eliminates ongoing infrastructure operational costs while maintaining efficient access control, as the policy module independently evaluates and enforces policies without server mediation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The policy management system is designed as a universal, connectivity-agnostic solution that can be deployed across multiple asset types and providers without requiring provider-specific infrastructure. The standardized policy module interface enables scaling to multiple manufacturers while maintaining operational efficiency through local enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11722529B2Method and apparatus for policy-based management of assets
Publication Date: 2023.08.08 IRDETO BV
  • US11722529B2 patent drawing
  • US11722529B2 patent drawing
  • US11722529B2 patent drawing

AI summary

A method and system for managing shared use of an asset. An asset device and an owner device accomplish an initial setup procedure to register the owner with the asset. One or more secure policies are then sent from the owner device, or another device authorized to create policies, to one or more user devices. The policies express user conditions and limitations for using the asset. Subsequently, the user device transmits the secure policy to the asset device. Once the policy has been transferred from the user device to the asset device, user associated with the user device can request use of the asset and will be granted the requested use if the requested use is permitted by the policy.