Global Access Control Mesh for Proximity-Based Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise onboarding processes for new employees are inefficient and costly, particularly in granting and revoking access to various resources and spaces, and do not adequately support remote and mobile workers, leading to a stressful experience that affects employee confidence and productivity.

Innovation Solution

A Global Control Access Platform (GCAP) that implements a dynamic access control system based on proximity, automatically granting and revoking access permissions to resources and spaces based on an individual's role within a team, using a mesh configuration that associates teams with access permissions, and dynamically updates these permissions based on team activities and learning mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual access control processes are used for each resource and location, then access permissions can be individually managed, but the time and effort required for onboarding new employees increases significantly

Engineering Contradiction:
Improveaccess control processVSAvoidonboarding time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges multiple individual access control processes into a single unified automated system. Instead of manually managing access to each resource separately, the system combines all access control operations into one integrated workflow that automatically provisions access across multiple resources when a new employee joins, thereby reducing onboarding time while maintaining individualized access management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary actions by pre-configuring access permissions and resource associations before new employees arrive. Access policies, resource mappings, and permission sets are established in advance, so that when a new employee is onboarded, access is automatically granted immediately without requiring manual configuration during the onboarding process.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple different processes are used per item or location requiring access, then specific access requirements can be met, but the complexity of managing access control increases

Engineering Contradiction:
Improveaccess permission configurationVSAvoidaccess control system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control system that can handle multiple different resource types and access scenarios through a single multi-functional platform. The system provides adaptable permission configurations for various resources (workspaces, applications, files, devices) while maintaining a unified management interface, thereby reducing system complexity while preserving the ability to meet specific access requirements for each item or location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access is granted manually to each resource, then security control can be maintained, but the cost and effort of access management increases

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service access management by automatically provisioning and revoking access permissions based on predefined policies and resource associations. When a new employee joins or an existing employee's role changes, the system automatically grants or revokes access to appropriate resources without requiring manual security review for each individual resource, thereby maintaining security control while significantly improving access management efficiency and reducing operational costs.

Inventive Principle:
Principle #25Self-service

4Reliability

If access permissions are manually revoked when employees leave or transfer, then security is maintained, but the burden on multiple users who issued access increases

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess revocation process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically revokes access permissions when employees leave, transfer, or have their roles changed, eliminating the manual burden on multiple users who previously had to individually revoke access. The centralized system tracks all access grants and automatically reverses them according to policy, maintaining security control while making the revocation process effortless and eliminating operational burden on individual users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12418542B2Global control access platform
Publication Date: 2025.09.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12418542B2 patent drawing
  • US12418542B2 patent drawing
  • US12418542B2 patent drawing

AI summary

A method for providing controlled access to resources in an enterprise begins by defining a “mesh” that associates a workplace team to a set of one or more workplace resources. The team has a role that, with respect to the resources, has a set of access permissions. An individual that is not then associated with the workplace team, e.g., in the given role, is assigned a physical or virtual token that represents the individual in the workplace environment. In response to detecting that the token is in physical or logical proximity to a member of the workplace team, the permissions are then automatically extended to the token. The resources are then accessible using the token. When the individual possessing the token is no longer in proximity, the access permissions are automatically revoked. The scope of the mesh configuration may be dynamically updated based on tracking activities of the workplace team.