Workflow Controller Access Control for Secure Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access management in secure physical and logical domains is challenging as existing systems require manual intervention for maintenance and work tasks, leading to inefficiencies and potential security breaches.

Innovation Solution

A system and method that configures permissions for agents to access protected domains through a workflow controller, interacting with monitoring and security systems to grant necessary access based on work orders, ensuring secure and controlled access for maintenance tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access management is used for secure domains, then security control is maintained, but efficiency and productivity deteriorate due to manual intervention requirements

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service access management where the workflow controller automatically interacts with security systems to grant and revoke access permissions based on work orders, eliminating the need for manual security administrator intervention for each access request

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access permissions are configured in advance as part of the work order creation process, with the workflow controller pre-authorizing necessary access before maintenance tasks begin, rather than processing access requests reactively

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual permission configuration is required for each access request, then security precision is improved, but device complexity and operational difficulty worsen

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem operational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The workflow controller merges multiple functions including work order management, access permission configuration, and security system interaction into a single integrated system, eliminating the need for separate manual processes for each function

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The workflow controller serves multiple purposes: managing work orders, configuring access permissions for different security domains, coordinating with multiple security systems, and tracking maintenance tasks, replacing multiple specialized systems with a single multi-functional platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If extensive manual intervention is used for access management, then security monitoring is improved, but loss of time and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity monitoringVSAvoidaccess approval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The workflow controller continuously monitors the status of maintenance tasks and automatically adjusts access permissions based on real-time feedback from the security systems and task completion status, enabling dynamic and responsive access management

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system maintains continuous automated monitoring and permission management throughout the maintenance process, eliminating gaps in security oversight that would occur during manual handoffs or transitions between different management processes

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If automated workflow control is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidworkflow system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The workflow controller acts as an intermediary layer between the work order management system and the security systems, automatically translating maintenance requirements into appropriate access permissions and coordinating with security infrastructure without requiring direct complex integration between all components

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9934477B1Protected domain workflow access control system
Publication Date: 2018.04.03 AMAZON TECH INC
  • US9934477B1 patent drawing
  • US9934477B1 patent drawing
  • US9934477B1 patent drawing

AI summary

Techniques are described for providing selective access to secure physical and/or logical domains for agents that need to perform work in those domains. A work order will detail work to be performed by one or more agents, such as a technician or software agent, that will need access to protected domains to perform the work, and the tasks requiring agent access to the protected domains are controlled and completion thereof verified. Interaction with a monitoring/security system for the protected physical domains occurs to selectively allow access of the agent to the protected domain(s) as needed for the tasks. Other aspects of the disclosure are described in the detailed description, figures, and claims.