Central Server Multi-Tiered Access Control for Computer Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a system that can provide secure, real-time control and tracking of computer devices to manage access and usage, particularly in scenarios like self-driving vehicles, prescription drug distribution, and medical device usage, to prevent theft, misuse, and ensure adherence to protocols.
Innovation Solution
A central server-based system using a control-file watchdog program to establish a secure end-to-end closed-loop system, allowing for multiple tiers of access control, secure communication, and real-time monitoring through authenticated device identity values and authorized manager hierarchies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full access is granted to computer device capabilities, then user functionality is maximized, but security risks and potential misuse increase
Solution Approach 1:
The patent segments access control into multiple tiers (full access, limited access, no access) that can be applied to different portions of the computer device's functionality. The system divides the device's capabilities into controllable segments, allowing managers to grant specific levels of access to different users based on their needs and trust levels.
Solution Approach 2:
The access control system is dynamic rather than static. Managers can modify access levels, add or remove users, and adjust limitations in real-time based on changing conditions. The system allows for dynamic reconfiguration of control parameters without requiring physical device access or reprogramming.
2Object-affected harmful factors
If limited access control is implemented, then security is improved, but device complexity and control mechanisms increase
Solution Approach 1:
The patent introduces a central server as an intermediary that handles all access control logic and authentication. This mediator manages the complexity of multi-tiered access control remotely, so the actual computer devices don't need built-in complex control mechanisms. The server acts as a centralized brain that simplifies the architecture by externalizing the control complexity.
Solution Approach 2:
The access control system is designed to be universally applicable across different types of computer devices and users. The same framework can manage smartphones, laptops, IoT devices, or future autonomous vehicles. The control mechanism works with various authentication methods and can accommodate different user roles, making it a versatile solution that doesn't require device-specific customization.
3Reliability
If real-time monitoring and control is implemented, then adherence to protocols is ensured, but system resource consumption increases
Solution Approach 1:
The system uses periodic communication between devices and the central server rather than continuous monitoring. Devices check in at intervals to report status and receive updated instructions, which reduces constant data transmission and processing requirements. This periodic action maintains protocol adherence while conserving battery life and network resources.
Solution Approach 2:
The system implements feedback loops where devices report their status to the server, which then sends corrective instructions if protocol violations are detected. This feedback mechanism ensures reliability by automatically correcting deviations from prescribed usage patterns, while the on-demand nature of feedback communication keeps resource consumption low compared to continuous monitoring.
Data Source
AI summary
Systems and methods for controlling and tracking computer devices using a secure communication path between a central server and a machine control-file watchdog program. One or more machine control-files can be generated to control, limit and track a computer device using a machine control-file watchdog program. The system sets limits on the computer device to ensure the user operating the computer device stays within a restricted set of usage limitations. The machine control-file watchdog program protects the one or more machine control-files and additionally can report on all activities performed by the computer device to the central server.


