Access Permission Removal Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing user access rights in computer systems are inefficient and inaccurate, especially in large, complex organizations with constantly changing structures and personnel, making it difficult to ensure secure access to sensitive data while preventing disruptions.

Innovation Solution

A system that validates the removal of user access permissions by monitoring and analyzing access to storage elements within the organizational network, creating an aggregated table to identify alternative access means and residual access rights, ensuring that data access is not denied to users, and generating reports for administrators to override potential errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current techniques (access control lists, user name/password administration, biometrics, encryption) are used to manage user access rights, then data security is improved, but the system complexity and difficulty of operation increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically validates access permission removals by checking alternative access means and historical access patterns without requiring manual intervention. The access control system self-verifies proposed changes against stored access records and generates validation reports automatically, reducing the operational burden on administrators while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides feedback by validating proposed access removals against historical access data and alternative access means before implementation. It checks whether removing access would prevent legitimate users from accessing needed data and generates reports indicating potential issues, allowing administrators to make informed decisions about access changes.

Inventive Principle:
Principle #23Feedback

2Reliability

If access control lists and user permission administration are manually managed, then data security is maintained, but the time required for maintenance and the accuracy of access control decrease

Engineering Contradiction:
Improvedata securityVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically validates access permission removals by checking alternative access means and historical access patterns without requiring manual intervention. The access control system self-verifies proposed changes against stored access records and generates validation reports automatically, reducing the operational burden on administrators while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary validation before implementing access removals by checking alternative access means and historical access patterns. This pre-checking process identifies potential issues with proposed changes before they are executed, preventing time-consuming post-implementation problems and ensuring accurate access control.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If access permissions are removed without validation, then the ease of operation is improved, but the risk of data denial to users and organizational disruption increases

Engineering Contradiction:
Improveease of permission removalVSAvoiddata accessibility
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system provides feedback by validating proposed access removals against historical access data and alternative access means before implementation. It checks whether removing access would prevent legitimate users from accessing needed data and generates reports indicating potential issues, allowing administrators to make informed decisions about access changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary validation before implementing access removals by checking alternative access means and historical access patterns. This pre-checking process identifies potential issues with proposed changes before they are executed, preventing time-consuming post-implementation problems and ensuring accurate access control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8239925B2Evaluating removal of access permissions
Publication Date: 2012.08.07 VARONIS SYSTEMS INC
  • US8239925B2 patent drawing
  • US8239925B2 patent drawing
  • US8239925B2 patent drawing

AI summary

Methods and systems are provided for controlling access to a file system. A record of actual accesses by users of the file system is maintained. Before a user is removed from a set of users or before a privilege for a set of users to access a data element is removed, it is determined whether the actual recorded accesses of the user are allowed by residual access permissions that would remain after implementing the proposed removal of access permission. An error condition is generated if the proposed removal of the access permission would have prevented at least one of the actual accesses. In another aspect of the invention, the system determines if the users would have alternate access to the storage element following implementation of the proposal.