Self-Provisioning Access Controller for IT Interoperability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems face challenges such as cumbersome de-provisioning processes for terminated employees, reliance on proprietary protocols, and limited interoperability with IT infrastructure, which hinder flexibility and cost-effectiveness in managing access to secured areas.
Innovation Solution
The introduction of self-provisioning access controllers that utilize a distributed network to manage access policies and credentials, allowing for real-time decision-making and event reporting without proprietary communication protocols, and enabling integration with existing IT infrastructure for enhanced flexibility and interoperability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional access control systems with centralized control panels are used, then access decisions can be made centrally, but the system becomes complex and difficult to integrate with existing IT infrastructure
Solution Approach 1:
The patent divides the access control system into distributed access control devices that operate independently rather than relying on a centralized control panel. Each access control device contains local credential verification capabilities, separating the system into autonomous units that can function independently and reduce overall system complexity while improving interoperability.
Solution Approach 2:
Access control devices are designed to self-provision by automatically discovering and integrating with existing IT infrastructure components such as directories and authentication services. The devices autonomously configure themselves without requiring complex manual setup, reducing deployment complexity while maintaining versatility.
2Productivity
If access control systems require manual de-provisioning of credentials, then security can be maintained, but the process becomes time-consuming and labor-intensive
Solution Approach 1:
The system implements automatic credential de-provisioning by monitoring credential usage and automatically revoking access when credentials are reported lost or stolen. This feedback mechanism eliminates manual intervention, reducing both the time required for de-provisioning and labor costs while maintaining security.
Solution Approach 2:
The system performs preliminary credential verification and validation before granting access, and automatically handles credential revocation in advance when security events are detected. This proactive approach prevents unauthorized access and eliminates the need for manual de-provisioning processes.
3Adaptability or versatility
If proprietary communication protocols are used in access control systems, then system reliability can be maintained, but interoperability with other systems is limited
Solution Approach 1:
The access control devices are designed with multi-functional communication capabilities, supporting multiple communication protocols and standards simultaneously. This universality allows the system to interface with various IT infrastructure components and other security systems while maintaining reliable communication through protocol-specific optimization.
Solution Approach 2:
The patent introduces standardized communication interfaces and protocol translation layers that act as intermediaries between different systems. These mediators enable seamless interoperability between access control devices and diverse IT infrastructure components while maintaining the reliability of communications through standardized protocols.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A processor-implemented access control method includes receiving credential and policy directory information to configure an access controller to allow self- provisioning of the access controller through periodic, automated query of the directory by the access controller; acquiring from the directory, credential and policy information for one or more individuals who may require access; storing in a local cache the acquired credential and policy information; receiving an access request to allow an individual access; comparing the access request to the credential and policy information in the cache; and when the comparison indicates a match, granting the individual access.