Policy management device, policy management method, and program
The policy management device addresses the challenge of adjusting access control policies by allowing administrators to input allowable variation in access permissions and adjust generation engine parameters, thereby enhancing the efficiency and effectiveness of policy adjustments.
Patent Information
- Application Number
- JP2023204476
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-16
AI Technical Summary
Administrators face challenges in controlling and adjusting access control policies generated by algorithms, as these policies can output various values due to parameter settings, making it difficult for administrators to reflect their intentions effectively.
A policy management device and method that acquire input information on the allowable degree of variation in access permissions and adjust parameters used by a generation engine to generate access control policies accordingly.
Facilitates efficient adjustment of access control policies, allowing administrators to reflect their intentions more effectively and streamline the decision-making process regarding access permissions.
Smart Images

Figure 2025089697000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a policy management device, a policy management method, and a program.
Background Art
[0002] Techniques for generating access control policies that determine the availability of access to resources are evolving.
[0003] For example, Patent Document 1 discloses a policy generation device that automatically generates a policy using relationship data indicating the relationship between a plurality of elements and score data. Here, the administrator can adjust the model function inside the policy engine by inputting policy change information from the input unit.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] In machine learning, when setting a loss function, the objective is to minimize its expected value. At this time, in order to suppress overfitting, sometimes the product of the parameter L p norm and λ is added to the expected value as a regularization term and minimized. This λ is called a regularization coefficient.
[0006] An algorithm or generation engine that automatically generates a policy generates an access control policy by minimizing the expected value of the loss function or the sum of the regularization term added thereto.
[0007] Generally, an algorithm that automatically generates a policy can output various values as an access control policy because it is affected by the parameters for setting the algorithm. Therefore, it is often difficult for the administrator of the algorithm to control the output as desired and reflect their thoughts as an access control policy.
[0008] In the system described in Reference Document 1, as described above, the administrator can adjust the model function inside the policy engine. However, Reference Document 1 does not disclose how the administrator should determine how to change the access control policy. Therefore, a problem is assumed that it takes time for the administrator to make a decision regarding the access control policy.
[0009] One of the objectives to be achieved by the embodiments of the present disclosure is to provide a policy management device, a policy management method, and a program that facilitate the adjustment of an access control policy. It should be noted that this objective is only one of the multiple objectives to be achieved by the multiple embodiments disclosed herein. Other objectives or problems and novel features will be clarified from the description of this specification or the attached drawings.
Means for Solving the Problem
[0010] A policy management device according to one aspect includes: an acquisition unit that acquires input information indicating the allowable degree of variation in access permission indicated by an access control policy; a change unit that changes parameters used by a generation engine that generates the access control policy to generate the access control policy based on the input information.
[0011] A policy management method according to one aspect includes: acquiring input information indicating the allowable degree of variation in access permission indicated by an access control policy; changing parameters used by a generation engine that generates the access control policy to generate the access control policy based on the input information. A method executed by a computer.
[0012] A program according to one aspect causes a computer to obtain input information indicating an allowable degree of change in access permission indicated by an access control policy, and change parameters used by a generation engine that generates the access control policy when generating the access control policy based on the input information. This is what causes the computer to execute.
Advantages of the Invention
[0013] According to the present disclosure, it is possible to provide a policy management device, a policy management method, and a program that facilitate adjustment of an access control policy.
Brief Description of the Drawings
[0014]
Figure 1
Figure 2A
Figure 2B
Figure 3
Figure 4
Figure 5
Figure 6
Modes for Carrying Out the Invention
[0015] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the following description and the drawings in the embodiments are appropriately omitted and simplified for clarity of explanation. In the present disclosure, unless otherwise specified, when "at least any one of a plurality of items" is defined for a plurality of items, the definition may mean any one item or any plurality of items including all items.
[0016] Each drawing referred to in the embodiments is merely an example for explaining one or more embodiments. Each drawing is not associated with only one specific embodiment, but may be associated with one or more other embodiments. As can be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, embodiments that are not explicitly illustrated or described. Not all of the features or steps shown in any one drawing for explaining exemplary embodiments are necessarily essential, and some features or steps may be omitted. The order of the steps described in any drawing may be changed as appropriate.
[0017] Also, common definitions in the present disclosure will be described below.
[0018] [Explanation of Definitions] In the present disclosure, the "user" refers to all persons who may be related to access management, such as end users who execute access requests to resources at the access destination (hereinafter also referred to as access resources), and administrators who manage access control. In the present disclosure, the "access resource" refers to any access target such as information assets, applications, computer files, and devices to be accessed.
[0019] In the present disclosure, the "access attribute" refers to any element that specifies the nature of an access when there is an access to a certain access destination. Specific examples of the element include · Various data of the access source · Various data of the access destination · Data indicating other properties of the access One or more arbitrary specific information (values) related to the nature of the access, such as the above, may be included. Hereinafter, "access attributes" may also be simply referred to as "attributes".
[0020] Specific examples of various data of the access source (Subject Attributes) include information regarding the ID (Identification) of the access source, information regarding the end user, information regarding at least any one of the devices or subsystems of the access source, information regarding the IP (Internet Protocol) address of the access source, information regarding the port number, software name (e.g., application name), authentication means of the access, etc., and any one or more of them are included. Here, the information regarding the ID of the access source includes, for example, the ID of the access source (e.g., end user ID), end user name, device ID, subsystem ID, application ID, end user authentication result (authentication history) of the ID of the access source, etc., and any one or more of them are included. The information regarding the end user includes, for example, the affiliation (organization) of the end user, position, job type, end user location (or the location of the device of the access source), affiliation of the device of the access source, degree of abnormal behavior of the end user or the device of the access source, etc., and any one or more of them are included. The information regarding the device of the access source includes, for example, the version of the OS (Operating System) used by the device of the access source, manufacturer name, etc., and any one or more of them are included. The information regarding the IP address of the access source includes, for example, the IP address of the access source, the degree of risk of the IP address of the access source, etc., and any one or more of them are included. In the above, the version of the OS indicates the vulnerability in the access, and the degree of abnormal behavior indicates the possibility of an attack.
[0021] Specific examples of various data (Object Attributes) of the access destination include any one or more of information regarding the ID of the access destination, information regarding the access resource, the address of the access destination (e.g., IP address or web address), information on the OS used by the device at the access destination, the type of operation, etc. Information regarding the ID of the access destination includes, for example, any one or more of the subsystem ID of the access destination, the resource ID, the owner name of the access resource ID, etc. Information regarding the access resource includes, for example, any one or more of the organization of the access destination (the organization that owns the access resource), the type of the requested access resource, the creator, the creation date and time, and the criticality, etc. The criticality of the access resource indicates the damage assumed in the case of being attacked.
[0022] Specific examples of other data indicating the nature of the access include any one or more of the request frequency from the ID of the access source to the access resource ID, the time zone (or time) of the access, the method of the session key, the importance of the access resource for the requesting subject, the degree of traffic such as the bandwidth usage rate, the abnormality degree of the network in the access, the encryption strength of the traffic, various data regarding authentication, etc. Various data regarding authentication includes any one or more of various authentication methods (e.g., including information on the authentication strength), the device authentication result, the application authentication result, various authentication times, the number of failures of various authentications, etc. The importance of the access resource for the requesting subject indicates the usability regarding the access, and the bandwidth usage rate indicates the possibility of performance degradation when controlling multiple accesses. However, the elements shown above are merely examples, and the elements indicating attributes are not limited to these.
[0023] In the present disclosure, "combination of multiple attributes" means that there are multiple elements as shown above. For example, assuming attributes X, Y, and Z, and assuming elements X1 and X2 as different values of the same attribute X, Y1 and Y2 as different values of the same attribute Y, and Z1 and Z2 as different values of the same attribute Z. In this case, any set among "X1, Y1", "X1, Z1", "Y1, Z1", "X1, Y2", ··· "X1, Y1, Z1" ··· "X2, Y2, Z2" corresponds to the "combination of multiple attributes".
[0024] In the present disclosure, "accessibility" is information indicating at least which action for access corresponds to either approval or disapproval, or the degree to which it corresponds to approval and disapproval. For example, the accessibility may be information indicating which of approval and disapproval it corresponds to, or information indicating which of approval, prohibition, and conditional approval (additional authentication required) it corresponds to. Also, the accessibility may be indicated as a numerical value within a predetermined range. In this case, the numerical value at one end of the predetermined range corresponds to approval, the numerical value at the other end of the predetermined range corresponds to disapproval, and other numerical values indicate the degree of approval or disapproval. However, the information indicated by "accessibility" is not limited to that shown above.
[0025] Embodiment 1 [Description of Configuration] Using FIG. 1, a configuration example of the policy management device will be described. The policy management device 10 includes an acquisition unit 11 and a change unit 12, and each unit of the policy management device 10 is controlled by a hardware controller (not shown). Hereinafter, each unit of the policy management device 10 will be described.
[0026] The acquisition unit 11 acquires, as input information, information indicating the allowable degree of fluctuation in access permission indicated by the access control policy. The access control policy is an arbitrary-form model for determining access permission. The allowable degree of fluctuation in access permission is a parameter indicating how much the access permission for each state in one attribute or a combination of a plurality of attributes in the entire access control policy can be changed. Here, before and after the fluctuation in access permission, for example, the ratio of access authorization and denial in the entire access control policy may be the same or substantially the same. The ratio being substantially the same means that, for example, the fluctuation in the ratio of access authorization or denial or the number of fluctuations in the access permission state is within a predetermined threshold. The input information may be, for example, information input by an administrator via an input interface, or information automatically generated by the policy management device 10 or another device.
[0027] The modification unit 12 modifies a parameter used when the generation engine that generates the access control policy generates the access control policy based on the input information acquired by the acquisition unit 11. For example, the modification unit 12 may modify a parameter used for setting a regularization coefficient (hereinafter, also simply referred to as the regularization coefficient) that is set when the generation engine generates the access control policy based on the input information. By modifying this parameter, the regularization coefficient will change. Therefore, the occurrence or degree of so-called overfitting will change in the access control policy.
[0028] In other words, when the regularization coefficient is set large, even if the data used for generating the access control policy fluctuates slightly, the access control policy output by the generation engine hardly changes before and after the fluctuation and becomes stable. On the other hand, when the regularization coefficient is set small, even if the data used for generating the access control policy fluctuates slightly, the access control policy output by the generation engine changes greatly before and after the fluctuation. That is, diversity occurs in the output of the generation engine.
[0029] When the regularization coefficient is set to be small, the administrator can determine which access permissions should be changed in the access control policy by comparing the access control policies before and after the change of the data used for generating the access control policy. However, if the regularization coefficient is too small, even when the data used for generating the access control policy varies slightly, the change in the access control policy will become extremely large. In this case, even if the administrator compares the access control policies before and after the change of the data used for generating the access control policy, it will be impossible to determine which access permissions should be changed in the access control policy. Therefore, the administrator can set the degree of change of the regularization coefficient appropriate for the determination by inputting, as the above input information, the degree to which changes in access permissions are allowed in the access control policy.
[0030] However, based on the input information, the change unit 12 may change parameters other than the parameter related to the setting of the regularization coefficient as parameters used when generating the access control policy.
[0031] The generation engine generates an access control policy for access using the data for generating the access control policy. When the parameters are changed by the change unit 12, the generation engine can generate the access control policy by using the changed parameters. Here, the display unit connected to the policy management device 10 may display the access permissions of the access control policy generated by the generation engine. The administrator can compare the access control policy generated before the change of the parameters with the access control policy generated after the change of the parameters by referring to the display unit. Note that the generation engine may be provided either inside or outside the policy management device 10.
[0032] Figures 2A and 2B are heatmaps showing an example of access availability of an access control policy before and after parameter changes. In Figures 2A and 2B, A and B are assumed as attributes, and A1 to A5 are assumed as elements of different values of the same attribute A, and B1 to B5 are assumed as elements of different values of the same attribute B. And in the heatmap, 25 combinations of a plurality of attributes A and B, namely, "A1, B1", "A2, B1", ··· "A5, B5" are disclosed.
[0033] For example, Figure 2A shows the access availability status for combinations of attributes in an access control policy generated by a generation engine before the change unit 12 changes the parameters of the generation engine. In Figure 2A, it is shown that among 25 combinations of attribute combinations in the access control policy, 15 combinations are approved (Allow) and 10 combinations are denied (Deny).
[0034] In Figure 2A, the combinations of "A1, B5", "A2, B4", "A3, B3", "A4, B2", "A5, B1" adjacent to the denied combinations are defined as approved for access availability. However, for the administrator, there is a need to confirm whether these combinations should really be approved combinations. In Figure 2A, these combinations are shown as "Allow?".
[0035] Figure 2B shows the access availability status for combinations of attributes in an access control policy generated by a generation engine when the change unit 12 changes the parameters of the generation engine from Figure 2A and part of the data for generating the access control policy is changed. In Figure 2B, similar to Figure 2A, it is shown that among 25 combinations of attribute combinations in the access control policy, 15 combinations are approved (Allow) and 10 combinations are denied (Deny). However, the access availability of each state in the combination of attributes is changed between Figure 2A and Figure 2B.
[0036] In FIG. 2B, the access availability in the above-mentioned sets of "A1, B5", "A2, B4", "A3, B3", "A4, B2", "A5, B1" is shown as "Allow", "Allow", "Allow", "Deny", "Deny", respectively. Therefore, the administrator can recognize that the access availability in the sets of "A4, B2" and "A5, B1" can be changed.
[0037] Note that FIG. 2B may show the access availability status for the set of attributes in the access control policy generated by the generation engine before the change unit 12 changes the parameters of the generation engine. At this time, in FIG. 2B, the sets of "A1, B4", "A2, B4", "A3, B4", "A4, B4", "A5, B4" adjacent to the authorized set are defined as denied (Deny) in terms of access availability. However, for the administrator, there is a need to confirm whether these sets should really be denied. In FIG. 2B, these sets are shown as "Deny?".
[0038] At this time, FIG. 2A shows the access availability status for the set of attributes in the access control policy generated by the generation engine when the change unit 12 changes the parameters of the generation engine and part of the data for generating the access control policy is changed, from FIG. 2B. In FIG. 2A, the access availability in the above-mentioned sets of "A1, B4", "A2, B4", "A3, B4", "A4, B4", "A5, B4" is shown as "Allow", "Allow", "Deny", "Deny", "Deny", respectively. Therefore, the administrator can recognize that the access availability in the sets of "A1, B4" and "A2, B4" can be changed.
[0039] Note that, as described above, input information indicating how much to change the access permission status of an individual set (i.e., the allowable degree of fluctuation in access permission) for the generation engine is input by the administrator, the policy management device 10, or another device from the heat map shown in FIG. 2A (or FIG. 2B). For example, when the administrator inputs the input information, the administrator may input, using quantitative information such as a numerical value or qualitative information, how much fluctuation in access permission is allowed. Qualitative information may be information that stepwise defines the allowable degree of fluctuation in words, such as "allow a lot of fluctuation," "allow little fluctuation," or "allow almost no fluctuation."
[0040] As described above, the change unit 12 changes the parameters used when the generation engine that generates the access control policy generates the access control policy using the input information acquired by the acquisition unit 11. For example, by the change unit 12 changing the parameter related to the setting of the regularization coefficient, the access control policy generated by the generation engine after the change may be in a state where the access permission status is changed compared to the previous access control policy. The degree of fluctuation in the access control policy changes according to the input information. For example, the access control policy generated by the generation engine after the change may be closer to FIG. 2A than the heat map shown in FIG. 2B (that is, closer to the access control policy before the change). On the other hand, the access control policy generated by the generation engine after the change may be more fluctuated from FIG. 2A than the heat map shown in FIG. 2B.
[0041] Note that the generation engine may be realized by a pre-trained AI (Artificial Intelligence) model such as a neural network or a monotonic neural network. This AI model is learned, for example, by inputting learning data including a plurality of sets of combinations of sample attributes and information indicating access permission as the correct label.
[0042] However, the generation engine may be implemented by any algorithm instead of the AI model. As the algorithm, for example, probability logic, fuzzy logic, linear regression, support vector machine, decision tree, monotonic regression, monotonic decision tree, etc. may be used.
[0043] [Description of the Flow] FIG. 3 is a flowchart showing an example of typical processing of the policy management device 10, and the processing of the policy management device 10 is described by this flowchart. Note that since the details of each processing are as described above, the description is omitted.
[0044] First, the acquisition unit 11 acquires input information indicating the allowable degree of change in access permission indicated by the access control policy (step S11: acquisition step). Then, the change unit 12 changes the parameters used when the generation engine that generates the access control policy generates the access control policy based on the input information (step S12: change step).
[0045] [Description of the Effect] As shown above, the change unit 12 changes the parameters used when the generation engine generates the access control policy based on the input information. The generation engine with the changed parameters can generate the access control policy. Therefore, it becomes possible for the administrator to compare the access control policies generated at each timing before and after the parameter change. That is, the policy management device 10 contributes to providing the administrator with information for determining how to change the access control policy. The administrator can recognize which part of the access control policy should be changed as a result of comparing the access control policies.
[0046] Further, the modification unit 12 may modify parameters used when the generation engine sets the regularization coefficient based on the input information. As a result, the access control policy generated by the generation engine after the modification will be in a state where the access permission status has changed compared to before. Therefore, as described above, the administrator can determine whether to change any access permissions in the access control policy by comparing the access control policies generated before and after the parameter modification.
[0047] Note that the policy management device 10 may be configured as a single computer device or as a distributed system having a plurality of computer devices. In a distributed system, the processes executed by the policy management device 10 can be shared and executed by a plurality of computer devices. That is, the acquisition unit 11 and the modification unit 12 may be distributed and mounted on two or more computer devices.
[0048] Embodiment 2 In the following Embodiment 2, a specific example of the policy management device described in Embodiment 1 is disclosed. However, the specific example of the policy management device shown in Embodiment 1 is not limited to those shown below. Also, the configurations and processes described below are examples and are not limited thereto.
[0049] [Description of Configuration] Using FIG. 4, a configuration example of the policy management system will be described. The policy management system S includes an input unit 101, a policy generation device 102, a display unit 103, and a determination unit 104. Each part of the policy management system S is controlled by a hardware controller (not shown).
[0050] The input unit 101 is composed of input interfaces such as a touch panel, a keyboard, and a mouse. The administrator of the policy management system S operates the input unit 101 to input at least one of the following information to the policy generation device 102. (A) At least one of the approval or rejection ratios in the output data 114, which is the access control policy (B) The location in the output data 114, which is the access control policy, where the access permission should be changed (C) The allowable degree of fluctuation of access permission The information in (A) to (C) is also referred to as parameter adjustment information. Hereinafter, (A) and (B) will be described. Since (C) is as described in Embodiment 1, the description thereof will be omitted.
[0051] (A) indicates that the administrator inputs quantitative information or qualitative information such as a numerical value desired by the administrator regarding at least either the approval or disapproval ratio in the entire access control policy. For example, assume that as a result of the administrator viewing the access control policy displayed on the display unit 103, the administrator determines that the approval or disapproval ratio in the entire access control policy should be increased. In this case, the administrator inputs, via the input unit 101, numerical information indicating at least either the approval or disapproval ratio shown by the access control policy. This numerical information may be information directly indicating the desired approval or disapproval ratio, or may be information indicating the increase or decrease amount from the current approval or disapproval ratio to the desired approval or disapproval ratio.
[0052] (B) indicates that in the access control policy, as the location where the access permission should be changed, the administrator inputs the information of the location desired by the administrator. Note that the administrator may further input the information of the access permission after the change regarding the location where the access permission should be changed. Alternatively, the administrator may execute the process shown in Embodiment 1, recognize which location of the access control policy should be changed, and then input the information of that location as (B).
[0053] The administrator may input at least any one of the information in (A) to (C) as a result of evaluating the access control policy initially displayed by the display unit 103. Alternatively, the administrator may input the evaluation value of the access control policy initially displayed by the display unit 103. The control unit 111 described later determines how to adjust the policy generation algorithm 112 based on the evaluation value.
[0054] The policy generation device 102 includes a control unit 111, a policy generation algorithm 112 (generation engine), input data 113, and output data 114.
[0055] The control unit 111 corresponds to the modification unit 12 according to Embodiment 1. When at least any one of the parameter adjustment information (A) to (C) is input from the input unit 101, the control unit 111 adjusts (that is, changes) the parameters of the policy generation algorithm 112 that determines the following parameters (a) to (c). (a) to (c) respectively correspond to (A) to (C). (a) The threshold for determining access permission in the access control policy (b) The range of the feature quantity with monotonic constraint in the access control policy (c) The regularization coefficient set when generating the access control policy The parameters of the policy generation algorithm 112 that determine the parameters (a) to (c) are hereinafter also referred to as determination parameters. Different from the learnable parameter θ that is changed according to learning in the access control policy, (a) to (c) are parameters that are not changed by learning. Hereinafter, parameters such as (a) to (c) that are not changed by learning are also referred to as hyperparameters α.
[0056] Details of (a) and (b) will be described later together with the descriptions of the input data 113, the policy generation algorithm 112, and the output data 114. Since (c) is as described in Embodiment 1, the description thereof is omitted.
[0057] In the learning stage, the policy generation algorithm 112 executes learning by taking in the input data 113 as learning data (sample data). As a result of executing learning, the policy generation algorithm 112 generates and outputs the output data 114, which is an access control policy. The policy generation algorithm 112 is configured using an AI model.
[0058] Note that even when learning has been performed using learning data in the past, if the decision parameters are adjusted, the policy generation algorithm 112 executes learning by re-incorporating the input data 113 as learning data. As a result of executing the learning again, the policy generation algorithm 112 generates and outputs the output data 114, which is an access control policy.
[0059] The input data 113 includes a set of attributes related to access (attribute vector) x and an action y for that access. The action y is information on a value indicating approval or disapproval. For example, when the action y is approval, the action y may be "1", and when the action y is disapproval, the action y may be "0". However, the examples of the possible values of the action y are not limited to this.
[0060] As an example, the input data 113 is represented as a set of learning data shown below.
Number
Number
[0061] In the learning stage, the policy generation algorithm 112 optimizes the learnable parameter θ of the access control policy according to the input data 113. The policy generation algorithm 112 generates, as output data 114 (i.e., the access control policy), a function f that determines an action from an attribute vector defined by the optimized learnable parameter θ. θ,α The function f θ,α is a function that determines an action y from a set of attributes x, and the learnable parameter θ and the hyperparameter α are used as parameters for the determination. When the policy generation algorithm 112 is configured as an ABAC-based algorithm, the output data 114 may be denoted as the function f θ,α (t, c).
[0062] For example, when the access control policy is composed of a neural network, the hyperparameter α includes at least one of parameters such as a threshold value for determining access permission in the access control policy and the number of ensembles. When the access control policy is composed of a decision tree, the hyperparameter α includes, for example, a parameter of the depth of the decision tree. When the access control policy is composed of a rule-based system, the hyperparameter α includes, for example, a parameter of the number of rules. When the access control policy is composed of an ensemble tree, the hyperparameter α includes, for example, the number of ensembles. When the access control policy is an ABAC-based model using the above-mentioned monotonically constrained variables, the hyperparameter α includes at least one of parameters such as (a) to (c) and the number of ensembles.
[0063] Assume that (a) a threshold value for determining access permission in the access control policy in the hyperparameter α is th. As an example, when the data to be determined is input to f θ,α (t, c) and the value of f θ,α (t, c) is greater than the threshold value th, the access control policy determines approval as an action, and f θ,αWhen the value of (t, c) is less than or equal to the threshold th, the access control policy determines denial as the action. However, the object of comparison with the threshold th does not have to be the value of (t, c). The access control policy may be a set of multiple data, where each data is the data obtained by modifying different parts of the data to be determined, and is input and set to f θ,α (t, c). The access control policy may calculate the average value of the multiple f θ,α (t, c) values obtained in this way, and determine whether access is allowed by comparing this average value with the threshold th. θ,α (t, c) values obtained in this way, and determine whether access is allowed by comparing this average value with the threshold th.
[0064] Also, the range of the feature quantity with monotonic constraint in the (b) access control policy indicates the range of the variable c with monotonic constraint. For example, the range of the feature quantity is represented by the following formula.
Number
[0065] Considering the above, when the access control policy is an ABAC-based model, the hyperparameter α is represented in the following format, for example.
Number
[0066] Merely using the policy generation algorithm 112, the administrator cannot adjust the hyperparameter α of the access control policy. However, in this embodiment, the administrator can adjust the hyperparameter α by operating the input unit 101 to input at least one of the parameter adjustment information (A) to (C). The administrator can input information from the input unit 101 based on a plurality of viewpoints necessary for determining the access control policy.
[0067] Specifically, the decision parameters in the policy generation algorithm 112 are adjusted by the control unit 111 according to the parameter adjustment information (A) to (C) input from the input unit 101 as described above. After the decision parameters are adjusted, the policy generation algorithm 112 can generate an access control policy by performing learning again using the adjusted decision parameters and the input data 113. At this time, the hyperparameter α of the access control policy generated by the policy generation algorithm 112 after adjustment will be a changed value compared to before adjustment.
[0068] Note that the control unit 111 adjusts the decision parameters based on the parameter adjustment information using, for example, any of the following methods. (i) The control unit 111 refers to a pre-created correspondence list of input information (which is sample data) and decision parameters, identifies the decision parameters corresponding to the actually input input information, and determines them as the decision parameters to be used in the policy generation algorithm 112. (ii) The control unit 111 inputs the actually input input information to a pre-learned AI model, obtains the decision parameters output from the AI model, and determines the obtained decision parameters as the decision parameters to be used in the policy generation algorithm 112. (iii) The control unit 111 identifies the decision parameter corresponding to the actually input input information by referring to the correspondence list of the input information, which is sample data, and the decision parameter created in advance. The control unit 111 sets the identified parameter as the initial value of the function to be calculated, and performs black box optimization to determine the decision parameter to be used in the policy generation algorithm 112. (iv) The control unit 111 identifies the decision parameter corresponding to the actually input input information by referring to the correspondence list of the input information, which is sample data, and the decision parameter created in advance. The control unit 111 sets the identified parameter as the initial value of the function to be calculated, and performs LLM (Large Language Models) to determine the decision parameter to be used in the policy generation algorithm 112.
[0069] Note that the correspondence list of the input information, which is sample data, and the decision parameter may be created based on, for example, the information of the decision parameter actually generated based on the input information in the past. Also, the AI model used in (ii) is pre-trained by inputting learning data including a plurality of sets of input information as samples and information indicating the decision parameter as the correct label. To summarize, it can be said that (i) to (iv) change the decision parameter by using the information of the set of the sample information and the decision parameter corresponding to the sample information.
[0070] Furthermore, when the evaluation value of the access control policy is input from the administrator, the control unit 111 may estimate which of the parameters (a) to (c) to adjust (that is, how to adjust the decision parameter) based on the evaluation value.
[0071] The display unit 103 visualizes for the administrator by displaying the access control policy generated by the policy generation algorithm 112. The display unit 103 may be composed of an interface such as a display or a touch panel, or may be composed of a printer or the like that visualizes information by printing. However, the policy management system S may notify the administrator of the access control policy using other methods such as voice instead of or in addition to the display unit 103.
[0072] In the access control policy, the display unit 103 displays the access permission status for one attribute or a set of multiple attributes in the access control policy using characters, symbols, pictures, etc. The display unit 103 may show the access permission status in the access control policy, for example, in the heat map format shown in Embodiment 1. The heat map may use different colors for the color indicating the case where access is authorized and the color indicating the case where access is denied. That is, the color of the heat map may change according to whether access is permitted or not. However, the display format of the access control policy is not limited to the heat map.
[0073] In addition, each time the policy generation algorithm 112 generates an access control policy, the display unit 103 can display the generated access control policy. Therefore, the display unit 103 can display the access control policies generated by the policy generation algorithm 112 before and after the control unit 111 adjusts the determination parameters. Also, the display unit 103 may simultaneously display the access control policies generated before and after the control unit 111 adjusts the determination parameters. Furthermore, when the determination parameters are adjusted multiple times, the display unit 103 may simultaneously display three or more access control policies. Specifically, the display unit 103 may display the access control policy generated at the timing before the adjustment of the determination parameters and the access control policy generated at the timing when the determination parameters are adjusted for the nth time (n is any integer greater than or equal to 1). This makes it easier for the administrator to compare the access control policies before and after the adjustment of the determination parameters. However, the display unit 103 may display by printing a plurality of access control policies on the same sheet of paper.
[0074] When the administrator determines that the access control policy displayed as feedback after adjustment on the display unit 103 is inappropriate, the administrator operates the input unit 101 to input at least any one of the parameter adjustment information in (A) to (C). Thereby, the administrator can readjust the hyperparameter α of the access control policy. The access control policy generated after the adjustment is displayed on the display unit 103. The administrator can adjust the hyperparameter α and cause the adjusted access control policy to be displayed on the display unit 103 until the desired access control policy is displayed on the display unit 103.
[0075] When the manager determines that the access control policy displayed on the display unit 103 is appropriate, the manager operates the input unit 101 to input the determined appropriate access control policy into the determination unit 104. The determination unit 104 determines the input access control policy as the access control policy to be applied. The determination unit 104 may output the determined access control policy to, for example, a PDP (Policy Decision Point). The PDP uses the output access control policy to determine whether to authorize or deny the access when access is made to the system to be subject to access approval / denial.
[0076] [Description of the Flow] FIG. 5 is a flowchart showing an example of typical processing of the policy management system S, and the processing of the policy management system S is described by this flowchart. Note that since the details of each process are as described above, the description will be omitted as appropriate.
[0077] First, the manager inputs parameter adjustment information including at least any one of (A) to (C) via the input unit 101. The control unit 111 acquires the input parameter adjustment information (step S21).
[0078] The control unit 111 adjusts the decision parameters of the policy generation algorithm 112 using the parameter adjustment information (step S22). The method for adjusting the decision parameters is as described above.
[0079] The control unit 111 causes the policy generation algorithm 112 to perform learning using the adjusted decision parameters (step S23). As a result of the learning, the policy generation algorithm 112 outputs output data 114 (access control policy) generated by using the input data 113 (step S24). The display unit 103 displays the output access control policy (step S25).
[0080] In addition, when the administrator determines that the access control policy displayed on the display unit 103 in step S25 is not as desired, the administrator operates the input unit 101 to re-enter the parameter adjustment information. As a result, the processes in steps S21 to S25 are executed again.
[0081] In addition, when the administrator determines that the access control policy displayed on the display unit 103 in step S25 is as desired, the administrator operates the input unit 101 to input the access control policy determined to be appropriate into the determination unit 104. As a result, the access control policy is determined.
[0082] [Description of Effects] Generally, an algorithm that automatically generates a policy can output various values as an access control policy due to the influence of the parameters for setting the algorithm. Therefore, it is often difficult for the administrator of the algorithm to control the output as desired and reflect their thoughts as the access control policy.
[0083] On the other hand, in the policy management system S according to the present embodiment, the administrator can input so as to reflect their intention regarding how to change the access control policy. The control unit 111 of the policy management system S automatically sets the parameters of the policy generation algorithm 112 according to the input. As a result, the administrator can generate an access control policy in which their intention is reflected, for example, regarding the above (A) to (C).
[0084] The policy management system S can visualize the generated access control policy for the administrator. Since the administrator can grasp the feedback that is the result of the adjustment, the adjustment can be performed efficiently.
[0085] In addition, the administrator may input numerical information indicating at least either the ratio of approval or disapproval in the access control policy. Based on the numerical information, the control unit 111 can change the decision parameter used when setting a threshold value for determining access permission in the (a) access control policy. Thereby, the policy management system S can freely let the administrator determine how strict or lenient the access permission in the access control policy should be. Therefore, the policy management system S can provide a system that is easy for the administrator to operate.
[0086] In addition, the administrator may input information indicating a location where the access permission should be changed in the output data 114 which is the (B) access control policy. Based on the information, the control unit 111 can change the decision parameter used when setting the range of the feature quantity with monotonic constraints in the (b) access control policy. Thereby, the policy management system S can freely let the administrator determine the detailed change points in the access control policy. Therefore, the policy management system S can provide a system that is easy for the administrator to operate.
[0087] In addition, based on the information input by the administrator, the control unit 111 may change the decision parameter used in the policy generation algorithm 112 by using information of a set of sample information and the parameter corresponding to the sample information. Thereby, the control unit 111 can accurately change the decision parameter based on the pre-determined information. Therefore, the policy management system S contributes to generating an accurate access control policy.
[0088] Specifically, the control unit 111 may change the decision parameters used in the policy generation algorithm 112 based on the information input by the administrator, using the method of black box optimization technology. Thereby, even when the generated access control policy is complex, the control unit 111 can maintain high accuracy of the generated access control policy.
[0089] As another example, the control unit 111 may change the decision parameters used in the policy generation algorithm 112 based on the information input by the administrator, using the method of LLM. Thereby, even when the generated access control policy is large-scale, the control unit 111 can maintain high accuracy of the generated access control policy.
[0090] Further, the display unit 103 may display the access control policy generated using the adjusted decision parameters as a heat map whose color changes according to the access permission. Thereby, the policy management system S can assist the administrator in generating a desired access control policy by clearly showing the generated access control policy to the administrator.
[0091] Similar to the policy management device 10, the policy management system S may be configured as a single computer device or as a distributed system having a plurality of computer devices.
[0092] In the above-described embodiments, the present disclosure has been described in terms of the hardware configuration, but the present disclosure is not limited thereto. The present disclosure can also be realized by causing a processor in a computer to execute a computer program for the processing of each device constituting the policy management device 10 or the policy management system S described in the above embodiments.
[0093] FIG. 6 is a block diagram showing an example of the hardware configuration of an information processing apparatus (in other words, a computer) in which the processing of the system or apparatus shown in each embodiment is executed. Referring to FIG. 6, the information processing apparatus 90 includes a signal processing circuit 91, a processor 92, and a memory 93.
[0094] The signal processing circuit 91 is a circuit for processing signals in accordance with the control of the processor 92. Note that the signal processing circuit 91 may include a communication circuit that receives signals from a transmission device.
[0095] The processor 92 is connected to the memory 93 and performs the processing of the apparatus described in the above embodiments by reading and executing a computer program from the memory 93. As an example of the processor 92, one of a CPU (Central Processing Unit), MPU (Micro Processing Unit), FPGA (Field-Programmable Gate Array), DSP (Demand-Side Platform), and ASIC (Application Specific Integrated Circuit) may be used, or a plurality of them may be used in parallel.
[0096] The memory 93 is composed of a volatile memory, a non-volatile memory, or a combination thereof. The number of memories 93 is not limited to one, and a plurality of them may be provided. Note that the volatile memory may be, for example, a RAM (Random Access Memory) such as a DRAM (Dynamic Random Access Memory) or an SRAM (Static Random Access Memory). The non-volatile memory may be, for example, a ROM (Read Only Memory) such as a PROM (Programmable Random Only Memory) or an EPROM (Erasable Programmable Read Only Memory), a flash memory, or an SSD (Solid State Drive).
[0097] Memory 93 is used to store one or more instructions. Here, the one or more instructions are stored in memory 93 as a program. The processor 92 can perform the processing described in the above embodiments by reading and executing these programs from memory 93.
[0098] In addition to being provided outside the processor 92, the memory 93 may include one built into the processor 92. Further, the memory 93 may include storage located away from the processor that constitutes the processor 92. In this case, the processor 92 can access the memory 93 via an I / O (Input / Output) interface.
[0099] As described above, the one or more processors included in each device in the above embodiments execute one or more programs including a group of instructions for causing a computer to perform the algorithms described with reference to the drawings. By executing the programs, the information processing described in each embodiment can be realized.
[0100] The program includes a set of instructions or software code that causes a computer to perform one or more functions described in the embodiments when loaded into the computer. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, the computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD), or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disk (DVD), Blu-ray Disc, or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage, or other magnetic storage devices. The program may be transmitted on a transitory computer-readable medium or a communication medium. By way of example and not limitation, the transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals. The transitory computer-readable medium or communication medium can supply the program to the computer via wired communication channels such as electric wires and optical fibers, or wireless communication channels.
[0101] Some or all of the above embodiments may be described as follows, but are not limited thereto. Also, some or all of the elements (e.g., configurations and functions) described in Supplementary Notes 2 to 8 that are subordinate to Supplementary Note 1 may be subordinate to Supplementary Notes 9 and 10 in the same subordinate relationship as Supplementary Notes 2 to 8. Thus, some or all of the elements described in any supplementary note can be applied to various hardware, software, recording means for recording software, systems, and methods. (Supplementary Note 1) an acquisition unit that acquires input information indicating the allowable degree of variation in access availability indicated by an access control policy; a modification unit that modifies parameters used by a generation engine that generates the access control policy to generate the access control policy based on the input information; A policy management device. (Appendix 2) The modification unit changes the parameter used for setting the regularization coefficient set by the generation engine when generating the access control policy based on the input information. The policy management device according to Appendix 1. (Appendix 3) The input information further includes numerical information indicating at least one of the ratios of access authorization or denial indicated by the access control policy. The modification unit further changes the parameter used when setting a threshold for the generation engine to determine access permission in the access control policy based on the numerical information. The policy management device according to Appendix 1 or 2. (Appendix 4) The input information further includes change information indicating locations where access permission should be changed in the access control policy. The modification unit further changes the parameter used when setting the range of the feature quantity with monotonic constraints in the access control policy by the generation engine based on the change information. The policy management device according to any one of Appendices 1 to 3. (Appendix 5) The modification unit changes the parameter used in the generation engine based on the input information by using information on a set of sample information and the parameter corresponding to the sample information. The policy management device according to any one of Appendices 1 to 4. (Appendix 6) The modification unit changes the parameter used in the generation engine based on the input information by using the method of black box optimization technology. The policy management device according to any one of Appendices 1 to 5. (Appendix 7) The modification unit changes the parameter used in the generation engine based on the input information by using the method of LLM (Large Language Models). The policy management device according to any one of Supplementary Notes 1 to 5. (Supplementary Note 8) The apparatus further includes a display unit that displays, as a heat map whose color changes according to whether access is permitted or not, an access control policy generated using the parameter changed by the change unit. The policy management device according to any one of Supplementary Notes 1 to 7. (Supplementary Note 9) Obtain input information indicating the allowable degree of variation in access permission indicated by the access control policy, Based on the input information, change a parameter used by a generation engine that generates the access control policy when generating the access control policy. A policy management method executed by a computer. (Supplementary Note 10) Obtain input information indicating the allowable degree of variation in access permission indicated by the access control policy, Based on the input information, change a parameter used by a generation engine that generates the access control policy when generating the access control policy. A program for causing a computer to execute the above.
[0102] Although the present disclosure has been described with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure. And each embodiment can be combined with other embodiments as appropriate.
Description of Reference Numerals
[0103] 10 Policy management device 11 Acquisition unit 12 Change unit S Policy management system 101 Input unit 102 Policy generation device 103 Display unit 104 Determination unit 111 Control unit 112 Policy generation algorithm 113 Input data 114 Output data
Claims
1. An acquisition unit that acquires input information indicating the allowable degree of variation in access availability indicated by an access control policy; A change unit that changes a parameter used when a generation engine that generates the access control policy generates the access control policy based on the input information. A policy management device.
2. The change unit changes the parameter used for setting a regularization coefficient set when the generation engine generates the access control policy based on the input information. The policy management device according to claim 1.
3. The input information further includes numerical information indicating at least one of the ratios of access authorization or denial indicated by the access control policy. The change unit further changes a parameter used when setting a threshold value for determining access availability in the access control policy by the generation engine based on the numerical information. The policy management device according to claim 1 or 2.
4. The input information further includes change information indicating a location where access availability is to be changed in the access control policy. The change unit further changes a parameter used when setting a range of a feature quantity with monotonic constraints in the access control policy by the generation engine based on the change information. The policy management device according to claim 1 or 2.
5. The change unit changes the parameter used in the generation engine based on the input information by using information of a pair of sample information and a parameter corresponding to the sample information. The policy management device according to claim 1 or 2.
6. The modification unit changes the parameters used in the generation engine based on the input information using the method of black box optimization technology. The policy management device according to claim 1 or 2.
7. The modification unit changes the parameters used in the generation engine based on the input information using the method of LLMs (Large Language Models). The policy management device according to claim 1 or 2.
8. The policy management device further includes a display unit that displays the access control policy generated using the parameters changed by the modification unit as a heat map whose color changes according to the access permission. The policy management device according to claim 1 or 2.
9. Obtain input information indicating the allowable degree of variation in access permission indicated by the access control policy, Based on the input information, change the parameters used by the generation engine that generates the access control policy when generating the access control policy. A policy management method executed by a computer.
10. Obtain input information indicating the allowable degree of variation in access permission indicated by the access control policy, Based on the input information, change the parameters used by the generation engine that generates the access control policy when generating the access control policy. A program that causes a computer to execute this.
Citation Information
Patent Citations
Policy generation device, policy generation method, and non-transitory computer-readable medium having program stored thereon
WO2022244179A1