Role-Based Access Control for Shared RFID Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current RFID data sharing across enterprises/organizations faces challenges in authorization and access control, particularly due to differences in data warehousing and data mining practices, leading to complexity and increased costs in managing user access.

Innovation Solution

Implementing a role-based access control system using a common standard interface, such as the Electronic Product Code Information Service (EPCIS), which allows enterprises/organizations to share sensor-related data while restricting access based on standardized roles, reducing the need for individual assessments and ensuring consistent access policies across participating entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual access assessments are performed for each user accessing RFID data across enterprises, then data security is maintained, but system complexity and management costs increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal role-based access control model where standardized roles (manufacturer, retailer, logistics provider, regulator) define access permissions across multiple enterprises. This universal framework eliminates the need for individual user assessments while maintaining security, as each role comes with pre-defined access rights to specific RFID data types and operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the access control parameter from individual user characteristics to role-based parameters. By defining access rights based on organizational roles rather than individual users, the system simplifies management while maintaining security. The standardized roles serve as parameters that automatically determine access levels without requiring case-by-case assessments.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If enterprises implement customized data sharing arrangements for RFID information, then specific data needs are met, but interoperability and consistency across the supply chain deteriorate

Engineering Contradiction:
Improvedata sharing flexibilityVSAvoiddata sharing consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent establishes a universal data sharing framework based on standardized roles that can serve multiple enterprises across the supply chain. This framework provides both flexibility and consistency by allowing any enterprise to adopt the same role definitions and access patterns, ensuring interoperability while adapting to different organizational needs through role selection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables enterprises to copy and adopt standardized role definitions and access control configurations from a established framework. Rather than creating customized arrangements from scratch, enterprises can replicate proven role-based models, ensuring consistency across the supply chain while maintaining the ability to adapt to specific needs through role selection and configuration.

Inventive Principle:
Principle #26Copying

3Loss of information

If comprehensive RFID data is shared across all participating enterprises, then supply chain visibility is improved, but data security and access control become more difficult to manage

Engineering Contradiction:
Improvesupply chain visibilityVSAvoidaccess control management
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The standardized role-based model provides a universal solution for managing comprehensive data sharing. Each role (manufacturer, retailer, logistics provider, regulator) has pre-defined access rights that enable supply chain visibility while automatically enforcing security constraints. This eliminates the need for complex custom access control arrangements while maintaining both visibility and security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service access control where the standardized role definitions automatically determine access permissions without requiring manual intervention for each data access request. The role-based framework self-regulates data sharing across enterprises, providing comprehensive visibility while simplifying access control management through automated permission enforcement based on organizational role.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8555398B2Role-based access to shared RFID data
Publication Date: 2013.10.08 SAP SE
  • US8555398B2 patent drawing
  • US8555398B2 patent drawing
  • US8555398B2 patent drawing

AI summary

An electronic product code information service (EPCIS) interface is provided, where the EPCIS interface is capable of allowing one or more accessing applications residing on a variety of systems and associated with a plurality of enterprises/organizations to receive EPC-related data. One or more roles of an entity attempting to receive EPC-related data through the interface may be identified. A query may be performed to generate a result set within an extent permitted by access authorization associated with the identified roles of the entity.