Central Server Multi-Tiered Access Control for Computer Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a system that can provide secure, real-time control and tracking of computer devices to manage access and usage, particularly in scenarios like self-driving vehicles, prescription drug distribution, and medical device usage, to prevent theft, misuse, and ensure adherence to protocols.

Innovation Solution

A central server-based system using a control-file watchdog program to establish a secure end-to-end closed-loop system, allowing for multiple tiers of access control, secure communication, and real-time monitoring through authenticated device identity values and authorized manager hierarchies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If full access is granted to computer device capabilities, then user functionality is maximized, but security risks and potential misuse increase

Engineering Contradiction:
Improveuser functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments access control into multiple tiers (full access, limited access, no access) that can be applied to different portions of the computer device's functionality. The system divides the device's capabilities into controllable segments, allowing managers to grant specific levels of access to different users based on their needs and trust levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access control system is dynamic rather than static. Managers can modify access levels, add or remove users, and adjust limitations in real-time based on changing conditions. The system allows for dynamic reconfiguration of control parameters without requiring physical device access or reprogramming.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If limited access control is implemented, then security is improved, but device complexity and control mechanisms increase

Engineering Contradiction:
ImprovesecurityVSAvoidcontrol mechanisms
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a central server as an intermediary that handles all access control logic and authentication. This mediator manages the complexity of multi-tiered access control remotely, so the actual computer devices don't need built-in complex control mechanisms. The server acts as a centralized brain that simplifies the architecture by externalizing the control complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is designed to be universally applicable across different types of computer devices and users. The same framework can manage smartphones, laptops, IoT devices, or future autonomous vehicles. The control mechanism works with various authentication methods and can accommodate different user roles, making it a versatile solution that doesn't require device-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If real-time monitoring and control is implemented, then adherence to protocols is ensured, but system resource consumption increases

Engineering Contradiction:
Improveprotocol adherenceVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system uses periodic communication between devices and the central server rather than continuous monitoring. Devices check in at intervals to report status and receive updated instructions, which reduces constant data transmission and processing requirements. This periodic action maintains protocol adherence while conserving battery life and network resources.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system implements feedback loops where devices report their status to the server, which then sends corrective instructions if protocol violations are detected. This feedback mechanism ensures reliability by automatically correcting deviations from prescribed usage patterns, while the on-demand nature of feedback communication keeps resource consumption low compared to continuous monitoring.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11663317B2Systems, devices and methods for using a central server to provide multi-tiered access and control of a computer device
Publication Date: 2023.05.30 3D BRIDGE SOLUTIONS INC
  • US11663317B2 patent drawing
  • US11663317B2 patent drawing
  • US11663317B2 patent drawing

AI summary

Systems and methods for controlling and tracking computer devices using a secure communication path between a central server and a machine control-file watchdog program. One or more machine control-files can be generated to control, limit and track a computer device using a machine control-file watchdog program. The system sets limits on the computer device to ensure the user operating the computer device stays within a restricted set of usage limitations. The machine control-file watchdog program protects the one or more machine control-files and additionally can report on all activities performed by the computer device to the central server.