Role-Based Access Control for Shared RFID Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current RFID data sharing across enterprises/organizations faces challenges in authorization and access control, particularly due to differences in data warehousing and data mining practices, leading to complexity and increased costs in managing user access.
Innovation Solution
Implementing a role-based access control system using a common standard interface, such as the Electronic Product Code Information Service (EPCIS), which allows enterprises/organizations to share sensor-related data while restricting access based on standardized roles, reducing the need for individual assessments and ensuring consistent access policies across participating entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual access assessments are performed for each user accessing RFID data across enterprises, then data security is maintained, but system complexity and management costs increase significantly
Solution Approach 1:
The patent implements a universal role-based access control model where standardized roles (manufacturer, retailer, logistics provider, regulator) define access permissions across multiple enterprises. This universal framework eliminates the need for individual user assessments while maintaining security, as each role comes with pre-defined access rights to specific RFID data types and operations.
Solution Approach 2:
The system changes the access control parameter from individual user characteristics to role-based parameters. By defining access rights based on organizational roles rather than individual users, the system simplifies management while maintaining security. The standardized roles serve as parameters that automatically determine access levels without requiring case-by-case assessments.
2Adaptability or versatility
If enterprises implement customized data sharing arrangements for RFID information, then specific data needs are met, but interoperability and consistency across the supply chain deteriorate
Solution Approach 1:
The patent establishes a universal data sharing framework based on standardized roles that can serve multiple enterprises across the supply chain. This framework provides both flexibility and consistency by allowing any enterprise to adopt the same role definitions and access patterns, ensuring interoperability while adapting to different organizational needs through role selection.
Solution Approach 2:
The system enables enterprises to copy and adopt standardized role definitions and access control configurations from a established framework. Rather than creating customized arrangements from scratch, enterprises can replicate proven role-based models, ensuring consistency across the supply chain while maintaining the ability to adapt to specific needs through role selection and configuration.
3Loss of information
If comprehensive RFID data is shared across all participating enterprises, then supply chain visibility is improved, but data security and access control become more difficult to manage
Solution Approach 1:
The standardized role-based model provides a universal solution for managing comprehensive data sharing. Each role (manufacturer, retailer, logistics provider, regulator) has pre-defined access rights that enable supply chain visibility while automatically enforcing security constraints. This eliminates the need for complex custom access control arrangements while maintaining both visibility and security.
Solution Approach 2:
The system enables self-service access control where the standardized role definitions automatically determine access permissions without requiring manual intervention for each data access request. The role-based framework self-regulates data sharing across enterprises, providing comprehensive visibility while simplifying access control management through automated permission enforcement based on organizational role.
Data Source
AI summary
An electronic product code information service (EPCIS) interface is provided, where the EPCIS interface is capable of allowing one or more accessing applications residing on a variety of systems and associated with a plurality of enterprises/organizations to receive EPC-related data. One or more roles of an entity attempting to receive EPC-related data through the interface may be identified. A query may be performed to generate a result set within an extent permitted by access authorization associated with the identified roles of the entity.


