Profile-Based Access Pathways for Dynamic PACS Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing physical access control systems (PACS) face challenges in efficiently managing dynamic access permissions, particularly in large and expanding enterprises, leading to cumbersome administration, potential errors, and the need for more intelligent access control solutions that can handle complex scenarios like tailgating and dynamic building conditions.

Innovation Solution

A PACS system with an access control request manager that utilizes a reachability graph and profile-based access pathways, learning from historical access events to suggest optimal permission assignments based on user profiles and building topology, automating the permission management process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static permissions are used in PACS, then access decisions are made quickly and reliably, but the system cannot adapt to dynamic access needs and requires manual permission management which consumes time and introduces errors

Engineering Contradiction:
Improveaccess decision reliabilityVSAvoidpermission management adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static permissions to dynamic pathways by computing optimal access routes based on user profiles and building topology. The access pathways learning module continuously learns from historical access events and updates the reachability graph, enabling the system to adapt permission assignments dynamically while maintaining reliable access control decisions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically computes optimal access pathways and suggests permission assignments without manual intervention. The access request manager module autonomously analyzes the reachability graph, determines required permissions, and generates suggestions, eliminating the need for manual permission management while maintaining system reliability.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual permission assignment is performed for each access request, then complete access control is achieved, but administrative time and potential errors increase significantly

Engineering Contradiction:
Improveaccess control completenessVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically computing optimal access pathways and generating permission suggestions. The access request manager module autonomously processes access requests, queries the reachability graph, determines required permissions, and presents suggestions to administrators, dramatically reducing administrative time while maintaining complete access control through automated verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-computing the reachability graph and learning access patterns from historical events before processing new requests. This preliminary preparation enables rapid automated permission suggestions without compromising the completeness of access control, as the graph structure already encodes all necessary spatial and permission relationships.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If a unique access pathway is defined for each cardholder, then access control precision is improved, but the system becomes insufficient for users with different profiles who need different pathways

Engineering Contradiction:
Improveaccess control precisionVSAvoidprofile-based pathway adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by tailoring access pathways to specific user profiles and attributes. Instead of a single universal pathway, the access pathways learning module learns and stores multiple profile-based pathways in the reachability graph, allowing the system to provide precise access control customized to each user's characteristics, department, clearance level, and other profile attributes.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically selects appropriate pathways based on user profiles rather than using fixed unique pathways. The access request manager module queries the reachability graph with user-specific attributes and receives context-aware pathway suggestions, enabling the system to adapt to different user needs while maintaining precise access control for each profile type.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If the PACS system manually defines permission pathways, then access control accuracy is maintained, but the complexity of managing permissions in large and expanding enterprises increases

Engineering Contradiction:
Improvepermission assignment accuracyVSAvoidpermission management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically computing permission pathways and generating accurate permission suggestions. The access request manager module autonomously queries the reachability graph, analyzes user profiles, determines optimal pathways, and suggests precise permission assignments, eliminating manual permission management complexity while maintaining high accuracy through automated verification against the learned access patterns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback from historical access events to continuously improve permission assignment accuracy. The access pathways learning module learns from actual access patterns and updates the reachability graph, providing feedback that refines future pathway computations and permission suggestions, thereby maintaining accuracy while reducing management complexity through data-driven automation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3590102B1Access control request manager based on learning profile-based access pathways
Publication Date: 2026.02.18 CARRIER CORP
  • EP3590102B1 patent drawingFigure 1
  • EP3590102B1 patent drawingFigure 2
  • EP3590102B1 patent drawingFigure 3

AI summary

An access control request manager based on learning profile based access pathways in a physical access control system (PACS). The access control request manager including an access pathways learning module configured to determine an reachability graph associated with each resource in the PACS, and a permissions request module, the permissions request module including an access request user interface configured to permit a user or an administrator, to provide a request for a permission to permit the user access to, or revoke the user's access to, a resource in the PACS. The permissions request module determines if the requested permission is already granted to the user, computes a pathway to reach the requested resource based on the reachability graph, suggests a permission, if needed, required to satisfy the request based on the computed pathway, and if approved, adds the suggested permission to any permissions granted to the user.