Role-Based Identity Arbitration for Secure Access Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems in vehicles and buildings face challenges in efficiently and securely managing access functions based on user roles, leading to inefficiencies and potential security vulnerabilities.

Innovation Solution

A method and system for managing and orchestrating access functions in vehicles and buildings by assigning user roles, determining identification criteria, and using arbitration systems to verify user identities against these criteria, allowing access only when the identity corresponds to the assigned role.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity systems are used in vehicles and buildings, then access control can be implemented, but security vulnerabilities and operational inefficiencies occur

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments access control into role-based hierarchies where administrators, managers, and users have distinct permission levels. Each role can be assigned specific functions and access rights, allowing fine-grained control over who can perform what actions in vehicles and buildings. This segmentation resolves the contradiction by providing both security through role separation and operational efficiency through automated permission management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary arbitration system that mediates between identity verification and access granting. The arbitration system evaluates multiple identification criteria and role assignments to determine appropriate access levels, acting as a intelligent mediator that balances security requirements with operational efficiency. This intermediary layer prevents security vulnerabilities while maintaining smooth operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If access control is implemented without role-based management, then system simplicity is maintained, but security vulnerabilities arise

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent creates a universal role-based access control framework that can be applied across multiple vehicles and buildings. The system defines universal roles (administrator, manager, user) that can be consistently applied throughout the fleet and facility portfolio. This universal approach provides robust security through standardized role permissions while maintaining system simplicity through reusable role templates and centralized management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of access control from individual user permissions to role-based permissions. By parameterizing access rights around roles rather than individual users, the system achieves enhanced security through configurable role hierarchies while maintaining simplicity through parameter-driven permission management. Administrators can modify security parameters by adjusting role assignments without restructuring the entire system.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive identity verification is performed for all functions, then security is enhanced, but operational efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial identity verification based on role requirements. Not all functions require the same level of verification - the arbitration system applies identification criteria selectively based on the requested function and user role. Critical functions require comprehensive verification while routine functions use simplified verification processes. This partial action approach maintains security for important operations while preserving operational efficiency for everyday tasks.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary role assignment and permission configuration before access requests occur. User roles and associated permission sets are pre-configured and stored in the system. When access requests are made, the arbitration system quickly matches the user's pre-assigned role against the required permissions rather than performing comprehensive verification each time. This preliminary action provides security through pre-established role boundaries while achieving operational efficiency through rapid role-based decision making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250384725A1Identity Management System Based On Role
Publication Date: 2025.12.18 DENSO INTERNATIONAL AMERICA INC
  • US20250384725A1 patent drawing
  • US20250384725A1 patent drawing
  • US20250384725A1 patent drawing

AI summary

An identity management system and method for operating the same includes assigning a role for a user, requesting access for a function of an access controller, selecting identification criteria for the function, determining identification criteria for enabling the function for the role, determining an identity of the user using the identification criteria at an arbitration system and allowing access based upon identifying the user and when identity corresponds to the identification criteria for the role.