A framework for access provisioning in physical access control systems

US2020028877A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2020028877-A1
Application numberUS-201816489905-A
CountryUS
Kind codeA1
Filing dateFeb 28, 2018
Priority dateMar 1, 2017
Publication dateJan 23, 2020
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A framework for access provisioning in a physical access control system (PACS). The framework includes a permissions request interface, the permissions request interface configured to permit a user or an administrator to request for a permission to access/revoke access to a resource, a permissions recommendation module communicating with the permissions request interface to receive the request and recommending a permission to be assigned to, or removed from, the user. The framework also includes a permissions validation module operable to ensure that the permission to be assigned to or to be removed does not violate an existing access control policy, that the permission to be assigned permits access to all permitted resources, or that the permission to be removed from the user denies access to all revoked resources and an approval workflow identification module identifying an approval required to assign or remove the permission.

First claim

Opening claim text (preview).

1 . A framework for access provisioning in a physical access control system (PACS), the framework comprising: a permissions request interface, the permissions request interface configured to permit a user or an administrator to provide a request for a permission to access/revoke access to a resource in the PACS; a permissions recommendation module, the permissions recommendation module in operable communication with the permissions request interface to receive the request, the permissions recommendation module recommending a permission to be assigned to, or removed from, the user based on at least one of an attribute presented by the user, a static permission assigned to other users, and a used permission of other users; a permissions validation module in operable communication with the permissions recommendation module, the permission validation module operable to ensure that at least one of the permission to be assigned to or to be removed from the user does not violate an existing access control policy, that the permission to be assigned to the user is sufficient for reaching all permitted resources, and that the permission to be removed from the user denies access to all revoked resources; and an approval workflow identification module operably connected to the permission validation module, the approval workflow identification module identifying an approval process required to assign or remove the permission. 2 . The framework for access provisioning in a (PACS) of claim 1 wherein the permission is to be assigned to, or removed from, the user based on at least one of an attribute presented by the user, a static permission assigned to other users, and a used permission of other users. 3 . The framework for access provisioning in a (PACS) of claim 2 wherein the recommending a permission is based on existing access control policies for users with a selected attribute. 4 . The framework for access provisioning in a (PACS) of claim 2 wherein the recommending a permission is based on static permissions for users with a similar attribute. 5 . The framework for access provisioning in a (PACS) of claim 2 wherein the recommending a permission is based on a used permission for users with a similar attribute. 6 . The framework for access provisioning in a (PACS) of claim 2 , wherein the attribute is specific to the user. 7 . The framework for access provisioning in a (PACS) of claim 2 , wherein the attribute is generic to a group of users. 8 . The framework for access provisioning in a (PACS) of claim 1 , wherein the attribute is at least one of a user's role, a user's department, a badge type, a badge/card ID. 9 . The framework for access provisioning in a (PACS) of claim 1 , further including an administrator at least one of, reviewing, adding to, and removing from the recommended permission and presenting accepted recommended permissions to the permissions validation module. 10 . The framework for access provisioning in a (PACS) of claim 1 , further including the permissions validation module ensuring that the permission to be assigned to the user is sufficient for reaching all permitted resources, or that the permission to be removed from the user denies access to all revoked resources. 11 . The framework for access provisioning in a (PACS) of claim 10 , further including the permissions validation module generating a report identifying any violations of access to permitted resources based on the permission or any access to revoked resources based on revoked permissions. 12 . The framework for access provisioning in a (PACS) of claim 1 , wherein not violating an existing access control policy includes ensuring that users with a selected attribute do not have the permissions to access a selected resource with another selected attribute. 13 . The framework for access provisioning in a (PACS) of claim 11 , further including the permissions validation module generating a report identifying any access control policy violations. 14 . The framework for access provisioning in a (PACS) of claim 11 , wherein the permissions validation module is invoked by an administrator. 15 . The framework for access provisioning in a (PACS) of claim 1 wherein the approval workflow identification module identifies a manager of a resource to approve a recommended permission. 16 . The framework for access provisioning in a (PACS) of claim 15 wherein the approval workflow identification module identifies user information required to complete the approval. 17 . The framework for access provisioning in a (PACS) of claim 15 wherein the approval workflow identification module at least one of, identifies authorized approvers for verifying the identified user information and invokes an external workflow engine and configures it with the identified user information. 18 . A physical access control system (PACS) with a framework for access provisioning, the physical access control system comprising: a user, the user having a credential including user information stored thereon, the user presenting the credential to request access to a resource protected by a door; a reader in operative communication with the credential and configured to read user information from the credential; a controller executing a set of access control permissions for permitting access of the user to the resource, the permissions generated with a framework for access provisioning, the framework comprising: a permissions request interface, the permissions request interface configured to permit a user or an administrator to provide a request for a permission to access/revoke access to a resource in the PACS; a permissions recommendation module, the permissions recommendation module in operable communication with the permissions request interface to receive the request, the permissions recommendation module recommending a permission to be assigned to, or removed from, the user based on at least one of an attribute presented by the user, a static permission assigned to other users, and a used permission of other users; a permissions validation module in operable communication with the permissions recommendation module, the permission validation module operable to ensure that at least one of the permission to be assigned to or to be removed from the user does not violate an existing access control policy, that the permission to be assigned to the user is sufficient for reaching all permitted resources, and that the permission to be removed from the user denies access to all revoked resources; and an approval workflow identification module operably connected to the permission validation module, the approval workflow identification module identifying an approval required to assign or remove the permission, wherein the controller is disposed at the door to permit access to the resource via the door. 19 . The physical access control system of claim 18 , wherein the credential is at least one of a badge, a magnetic card, an RFID card, a smart card, a FOB, and a mobile device. 20 . A method of access provisioning in a physical access control system (PACS), the method comprising: a receiving a request from at least one of a user and an administrator to provide a permission to access or revoke a permission access to a resource in the PACS; recommending a permission to be assigned to, or removed from, the user based on at least one of an attribute presented by the user, a static permission assigned to other users, and a used permission of other users; validating tha

Assignees

Inventors

Classifications

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Tools and structures for managing or administering access control systems · CPC title

  • with central registration · CPC title

  • Access control comprising means for the enrolment of users · CPC title

  • operated by interacting with a central unit · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2020028877A1 cover?
A framework for access provisioning in a physical access control system (PACS). The framework includes a permissions request interface, the permissions request interface configured to permit a user or an administrator to request for a permission to access/revoke access to a resource, a permissions recommendation module communicating with the permissions request interface to receive the request …
Who is the assignee on this patent?
Carrier Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jan 23 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).