Automated Access Envelope Generation for ML Policy Accuracy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex systems like machine-learning systems, generating and managing accurate access policies that are neither too permissive nor too restrictive is challenging, especially with frequent changes in computing services and resources, leading to security and access issues in highly regulated industries.

Innovation Solution

An access policy automation service (APAS) dynamically generates and updates access envelopes based on monitored actions, adding or removing permissions to ensure appropriate access levels, by tracking user interactions and resource access, and integrating these access envelopes into a hierarchical system for role definition and policy refinement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual access policy management is used, then policy accuracy can be maintained through careful review, but the complexity of managing frequent changes in computing services and resources increases significantly

Engineering Contradiction:
Improvepolicy accuracyVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service through automated access policy generation where the access policy automation service automatically creates and updates access envelopes based on monitored actions, eliminating the need for manual policy creation and reducing management complexity while maintaining accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring actions taken by principals and using this information to dynamically update access policies. The access policy automation service receives feedback from action monitoring and automatically adjusts access envelopes to maintain appropriate access levels without manual intervention

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If access policies are made more permissive to accommodate frequent system changes, then system adaptability improves, but security risk increases

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies dynamics by making access policies dynamic rather than static. Access envelopes are automatically updated based on monitored actions and system changes, allowing the system to adapt to frequent changes while maintaining security through real-time policy adjustment rather than relying on overly permissive static policies

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters by dynamically modifying access policy parameters based on monitored actions. The access policy automation service adjusts access envelope parameters automatically in response to system changes, enabling adaptability without compromising security through parameter optimization rather than blanket permission increases

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If manual access policy updates are performed frequently to match system changes, then access control accuracy is maintained, but time consumption and operational effort increase

Engineering Contradiction:
Improveaccess control accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by proactively monitoring actions and automatically generating access policy updates before manual intervention is needed. The access policy automation service continuously monitors and preemptively adjusts access envelopes, eliminating the time-consuming manual update process while maintaining access control accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system ensures continuity of useful action through automated continuous monitoring and policy adjustment. The access policy automation service maintains continuous access control accuracy without interruption by automatically updating policies in real-time, eliminating the periodic manual updates that consume time and operational effort

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12177263B1Semi-automated role creation for governance of machine-learning systems
Publication Date: 2024.12.24 AMAZON TECH INC
  • US12177263B1 patent drawing
  • US12177263B1 patent drawing
  • US12177263B1 patent drawing

AI summary

Techniques are disclosed for automatically generating an access envelope that can be used to provide recommended access permissions and access rules for access roles. An access policy automation service may monitor actions requested by a user or system operating within a workflow from computing resources in a computing environment. The service may automatically update an access envelope associated with the user or system with permissions allowing the user or system to perform the requested actions. The envelope can then be used in a role definition to provide appropriate permission to users who may be performing similar operations.