Shared Vehicle Access Policies for Operation-Level Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing shared vehicle access lack efficient methods to authenticate users and enforce access permissions, leading to potential misuse and unauthorized vehicle operations.

Innovation Solution

A method and system that utilize multiple authorization policies with distinct authentication schemes and access requirements to control vehicle operations, allowing only authorized users to perform permitted operations based on their access level and vehicle status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authorization policies with distinct authentication schemes are implemented, then security and access control precision are improved, but device complexity and system configuration difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization system is segmented into multiple independent authorization policies, each with its own authentication scheme and access requirements. This allows the system to handle different authentication methods (biometric, token-based, password) as separate, manageable units rather than one monolithic complex system, resolving the contradiction by organizing complexity into modular segments that improve security while maintaining manageability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically selects and applies appropriate authentication schemes based on the specific authorization policy being evaluated. Rather than using a fixed, single authentication method, the system adapts its authentication approach according to the user's role, vehicle type, and operational context, improving security through contextual authentication while keeping the interface relatively simple through automated policy selection.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple authorization policies with distinct authentication schemes are implemented, then security and access control precision are improved, but ease of operation and user interaction complexity increase

Engineering Contradiction:
Improveaccess control precisionVSAvoiduser interaction complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically evaluating user credentials against multiple authorization policies and selecting the appropriate authentication scheme without requiring user intervention. The system autonomously determines which authentication method to apply based on the user's identity and the vehicle's authorization requirements, improving access control precision while maintaining ease of operation through automated policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authorization policies are pre-configured with specific authentication schemes and access requirements before system operation. This preliminary configuration allows the system to quickly evaluate credentials against predetermined criteria during actual access attempts, improving access control precision through pre-established rules while simplifying user interaction by eliminating the need for users to understand or select authentication methods.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication and authorization checking is performed systematically, then security against unauthorized operations is improved, but processing time and system response delay increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authorization policies and authentication schemes are pre-configured and stored in the system before actual access attempts. This preliminary preparation allows the system to perform rapid credential evaluation against predetermined criteria during authentication, improving security through systematic checking while minimizing authentication time by eliminating the need for real-time policy creation or complex decision-making during the authentication process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process is segmented into discrete evaluation steps against individual authorization policies. Rather than performing one monolithic security check, the system evaluates credentials against multiple segmented policy rules in sequence, improving security coverage while optimizing processing time by allowing early termination when a match is found or by parallel evaluation of independent policy criteria.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12054118B2Methods for shared vehicle access
Publication Date: 2024.08.06 GEOTAB INC
  • US12054118B2 patent drawing
  • US12054118B2 patent drawing
  • US12054118B2 patent drawing

AI summary

The present systems, devices, and methods relate to managing shared vehicle access. Authorization policies are stored at a network device, and are provided to vehicle devices. Authorization policies each include an authentication scheme, a list of permitted vehicle operations, and a list of requirements to perform vehicle operations. In this way, whether even if a user is authenticated to access a vehicle, vehicle access is controlled based one whether the user is permitted to perform vehicle operations, and whether requirements are met to perform vehicle operations. This provides a flexible and robust vehicle access system. Authorization Policies are distributed to vehicle device in an Access Configuration, which can be updated.