IP Library Granted Patent US 11,410,478
Granted Patent B2
US 11,410,478 · App. 17/048,363 · Granted Aug 9, 2022

Visualization and management of access levels for access control based al hierarchy

Inventors: Blanca Florentino Liano (Cork, IE); Ankit Tiwari (South Windsor, CT); Jakub Potocki (Cork, IE); Ed Gauthier (Fairport, NY); John Marchioli (Fairport, NY)
Assignee: CARRIER CORPORATION
G07C9/00309G07C9/27H04L63/105G06F2221/2113G06F2221/2141G07C2209/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,410,478
App. No.
17/048,363
Granted
Aug 9, 2022
Kind
B2
Abstract

A method of operating an access control system containing one or more hierarchies, each of the one or more hierarchies includes one or more access levels is provided. The method including: computing one or more hierarchies; and assigning a primary access level of the one or more access levels within a primary hierarchy of the one or more hierarchies to a first credential; and determining that access levels vertically below the primary access level in the primary hierarchy are implicitly assigned to the first credential when assigning the primary access level of the one or more access levels within the primary hierarchy of the one or more hierarchies to the first credential.

Claims (68)

1. A method of operating an access control system containing one or more hierarchies, each of the one or more hierarchies includes one or more access levels, the method comprising:

computing one or more hierarchies; and

assigning a primary access level of the one or more access levels within a primary hierarchy of the one or more hierarchies to a first credential; and

determining that access levels vertically below the primary access level in the primary hierarchy are implicitly assigned to the first credential when assigning the primary access level of the one or more access levels within the primary hierarchy of the one or more hierarchies to the first credential,

wherein the method further comprises at least one of:

(1) identifying sensitive access levels in each of the one or more hierarchies, and

prioritizing the sensitive access levels for defining and enforcing access level policies, or

(2) splitting an access level located proximate a vertical top portion of a hierarchy into multiple access levels each having a limited number of access controls.

2. The method of claim 1 , wherein computing one or more hierarchies further comprises at least one of:

removing duplicate access levels within each of the one or more hierarchies;

removing unassigned access levels within each of the one or more hierarchies;

removing redundant access levels across each of the one or more hierarchies;

combining two or more access levels within a hierarchy if the access levels are always assigned together within the hierarchy; and

splitting over assigned access levels within each of the one or more hierarchies.

3. The method of claim 1 , further comprising:

receiving an access request at a first access control, the access request including the first credential;

determining which access levels are assigned to the first credential;

determining that at least one access level assigned to the first credential is authorized to actuate the first access control; and

actuating the first access control when it has been determined that credentials are authorized to actuate the first access control.

4. The method of claim 3 , wherein the first access control is a door lock operably connected to a door and actuating the first access control unlocks the door.

5. The method of claim 1 , further comprising:

receiving an access request at a first access control, the access request including the first credential;

determining which access levels are assigned to the first credential;

determining that none of the access levels assigned to the first credential are not authorized to actuate the first access control; and

maintaining the access control in a non-actuated position.

6. The method of claim 1 , further comprising:

identifying access levels proximate a vertical top portion of each of the one or more hierarchies.

7. The method of claim 1 , further comprising:

identifying groups of credentials that are assigned to one or more access levels proximate a vertical top portion of one or more hierarchies.

8. The method of claim 1 , further comprising:

detecting usage of access controls at each of the one or more access levels for each of the one or more hierarchies; and

recommending removal of access levels from a credential located proximate a vertical top portion each of the one or more hierarchies in response to usage by the credential.

9. The method of claim 1 , further comprising:

recommending an access level proximate a vertical bottom portion of a hierarchy for a new credential.

10. A computer program product tangibly embodied on a computer readable medium, the computer program product including instructions that, when executed by a processor, cause the processor to perform operations comprising:

computing one or more hierarchies;

assigning a primary access level of the one or more access levels within a primary hierarchy of the one or more hierarchies to a first credential; and

determining that access levels vertically below the primary access level in the primary hierarchy are implicitly assigned to the first credential when assigning the primary access level of the one or more access levels within the primary hierarchy of the one or more hierarchies to the first credential,

wherein the operations further comprise at least one of:

(1) identifying sensitive levels in each of the one or more hierarchies; and

prioritizing the sensitive access levels for defining and enforcing access level policies, or

(2) splitting an access level located proximate a vertical top portion of a hierarchy into multiple access levels each having a limited number of access controls.

11. The computer product of claim 10 , wherein computing one or more hierarchies further comprises at least one of:

removing duplicate access levels within each of the one or more hierarchies;

removing unassigned access levels within each of the one or more hierarchies;

removing redundant access levels across each of the one or more hierarchies;

combining two or more access levels within a hierarchy if the access levels are always assigned together within the hierarchy; and

splitting over assigned access levels within each of the one or more hierarchies.

12. The computer product of claim 10 , wherein the operations further comprise:

receiving an access request at a first access control, the access request including the first credential;

determining which access levels are assigned to the first credential;

determining that at least one access level assigned to the first credential are authorized to actuate the first access control; and

actuating the first access control when it has been determined that credentials are authorized to actuate the first access control.

13. The computer product of claim 12 , wherein the first access control is a door lock operably connected to a door and actuating the first access control unlocks the door.

14. The computer product of claim 10 , wherein the operations further comprise:

receiving an access request at a first access control, the access request including the first credential;

determining which access levels are assigned to the first credential;

determining that none of the access levels assigned to the first credential are not authorized to actuate the first access control; and

maintaining the access control in a non-actuated position.

15. The computer product of claim 10 , wherein the operations further comprise:

identifying access levels proximate a vertical top portion of each of the one or more hierarchies.

16. The computer product of claim 10 , wherein the operations further comprise:

identifying groups of credentials that are assigned to one or more access levels proximate a vertical top portion of one or more hierarchies.

17. The computer product of claim 10 , wherein the operations further comprise:

detecting usage of access controls at each of the one or more access levels for each of the one or more hierarchies; and

recommending removal of access levels from a credential located proximate a vertical top portion each of the one or more hierarchies in response to usage by the credential.

18. The computer product of claim 10 , wherein the operations further comprise:

recommending an access level proximate a vertical bottom portion of a hierarchy for a new credential.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2024
From: CARRIER CORPORATION
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 069175/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2020
From: UNITED TECHNOLOGIES RESEARCH CENTRE IRELAND, LIMITED
To: UNITED TECHNOLOGIES CORPORATION
Reel/Frame 054080/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2020
From: LIANO, BLANCA FLORENTINO; POTOCKI, JAKUB
To: UNITED TECHNOLOGIES RESEARCH CENTRE IRELAND, LIMITED
Reel/Frame 054080/0714 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2020
From: TIWARI, ANKIT
To: CARRIER CORPORATION
Reel/Frame 054080/0772 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2020
From: UNITED TECHNOLOGIES CORPORATION
To: CARRIER CORPORATION
Reel/Frame 054102/0764 →