Self-Provisioning Access Controller for IT Interoperability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems face challenges such as cumbersome de-provisioning processes for terminated employees, reliance on proprietary protocols, and limited interoperability with IT infrastructure, which hinder flexibility and cost-effectiveness in managing access to secured areas.

Innovation Solution

The introduction of self-provisioning access controllers that utilize a distributed network to manage access policies and credentials, allowing for real-time decision-making and event reporting without proprietary communication protocols, and enabling integration with existing IT infrastructure for enhanced flexibility and interoperability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control systems with centralized control panels are used, then access decisions can be made centrally, but the system becomes complex and difficult to integrate with existing IT infrastructure

Engineering Contradiction:
ImproveInteroperability with IT infrastructureVSAvoidSystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the access control system into distributed access control devices that operate independently rather than relying on a centralized control panel. Each access control device contains local credential verification capabilities, separating the system into autonomous units that can function independently and reduce overall system complexity while improving interoperability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Access control devices are designed to self-provision by automatically discovering and integrating with existing IT infrastructure components such as directories and authentication services. The devices autonomously configure themselves without requiring complex manual setup, reducing deployment complexity while maintaining versatility.

Inventive Principle:
Principle #25Self-service

2Productivity

If access control systems require manual de-provisioning of credentials, then security can be maintained, but the process becomes time-consuming and labor-intensive

Engineering Contradiction:
ImproveCredential management efficiencyVSAvoidDe-provisioning time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements automatic credential de-provisioning by monitoring credential usage and automatically revoking access when credentials are reported lost or stolen. This feedback mechanism eliminates manual intervention, reducing both the time required for de-provisioning and labor costs while maintaining security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary credential verification and validation before granting access, and automatically handles credential revocation in advance when security events are detected. This proactive approach prevents unauthorized access and eliminates the need for manual de-provisioning processes.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If proprietary communication protocols are used in access control systems, then system reliability can be maintained, but interoperability with other systems is limited

Engineering Contradiction:
ImproveInteroperabilityVSAvoidCommunication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The access control devices are designed with multi-functional communication capabilities, supporting multiple communication protocols and standards simultaneously. This universality allows the system to interface with various IT infrastructure components and other security systems while maintaining reliable communication through protocol-specific optimization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces standardized communication interfaces and protocol translation layers that act as intermediaries between different systems. These mediators enable seamless interoperability between access control devices and diverse IT infrastructure components while maintaining the reliability of communications through standardized protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2981884B1Self-provisioning access control
Publication Date: 2021.01.20 AVIGILON ANALYTICS CORP
  • EP2981884B1 patent drawingFigure 1A
  • EP2981884B1 patent drawingFigure 1B
  • EP2981884B1 patent drawingFigure 1C

AI summary

A processor-implemented access control method includes receiving credential and policy directory information to configure an access controller to allow self- provisioning of the access controller through periodic, automated query of the directory by the access controller; acquiring from the directory, credential and policy information for one or more individuals who may require access; storing in a local cache the acquired credential and policy information; receiving an access request to allow an individual access; comparing the access request to the credential and policy information in the cache; and when the comparison indicates a match, granting the individual access.