Smart Building Device Group Access Control for Dynamic Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control mechanisms in smart buildings are complex, error-prone, and require manual updates, leading to unreliable and time-consuming management, especially when room allocations or device states change, and they fail to prevent unauthorized access to sensitive data and devices.
Innovation Solution
Implementing a method and system that automatically generates device groups based on properties such as location or tenant association, with device group access constraints that grant or deny permissions to monitoring and controlling applications, allowing for dynamic and efficient management of access rights without requiring manual updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual permission assignments are used for individual devices, then access control can be implemented, but the system becomes complex and error-prone requiring continuous manual updates
Solution Approach 1:
The patent segments the building into spatial zones (rooms, floors, building parts) and assigns permissions based on these spatial segments rather than individual devices. This segmentation allows automatic permission management when spatial allocations change, eliminating the need for manual device-by-device permission updates and reducing complexity while maintaining reliability.
Solution Approach 2:
The patent implements dynamic permission assignment that automatically adapts when spatial allocations or device assignments change. Instead of static manual configurations, the system dynamically updates permissions based on current building state, ensuring reliability without requiring continuous manual intervention and reducing operational complexity.
2Reliability
If manual updates of device permissions are performed, then access control can be maintained, but time is lost and errors may occur
Solution Approach 1:
The patent establishes permission rules in advance based on spatial zones and device groups. When changes occur in the building configuration, the system automatically applies these pre-defined rules to update permissions, eliminating the need for time-consuming manual updates and reducing errors while maintaining high reliability.
Solution Approach 2:
The patent implements a feedback mechanism where the system continuously monitors changes in spatial allocations and device assignments, then automatically adjusts permissions accordingly. This closed-loop feedback ensures accuracy without manual intervention and eliminates time loss associated with manual permission management.
3Adaptability or versatility
If third-party applications are allowed to access building devices, then functionality is enhanced, but security risks increase due to potential unauthorized access to sensitive data
Solution Approach 1:
The patent applies the principle of local quality by granting third-party applications permissions specific to their functional requirements and confined to particular spatial zones. Instead of universal access, each application receives precisely scoped permissions limited to the minimum necessary areas and devices, enhancing functionality while mitigating security risks through localized access control.
Data Source
Figure 1A~1B
Figure 2A~2B
Figure 3A~3B
AI summary
A method for monitoring and/or controlling devices of a smart building, the method comprising: - generating a plurality of device groups, wherein each device group includes one or more devices of the smart building and is defined to include all devices of the smart building that satisfy one or more properties; - providing one or more device group access constraints for a monitoring and/or controlling application, wherein the monitoring and/or controlling application is configured for monitoring and/or controlling at least one device of the smart building, wherein each device group access constraint is associated with a device group of the plurality of device groups and specifies a grant or refusal of permission for the monitoring and/or controlling application to access said device group; --receiving, from the monitoring and/or controlling application, a request to access a first device group of the plurality of device groups; - granting or refusing, by a permission control unit of the smart building, the monitoring and/or controlling application permission to access the first device group based on one or more device group access constraints associated with the first device group; and - if said access to the first device group is granted, monitoring and/or controlling at least one device of the first device group via an execution of the monitoring and/or controlling application.