Access Relationship Management System for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex and unintended access relationships in large computing environments is challenging due to the creation of accidental chains of trust, which can lead to unintended access to resources and difficulties in maintaining security and compliance with policies.

Innovation Solution

A method and apparatus for determining chains of access relationships and creating direct access relationships based on the determined chains, allowing for selective replacement of chained access relationships with direct ones, taking into account various criteria such as security credentials, data traffic, and policy compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If chains of access relationships are allowed to form naturally between entities, then access flexibility and connectivity are improved, but system complexity and security management difficulty increase

Engineering Contradiction:
Improveaccess flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A centralized access relationship management system is introduced as an intermediary between entities. This mediator discovers, manages, and optimizes access relationships centrally, transforming the complex many-to-many relationships into manageable structured data that can be analyzed and optimized without increasing individual entity complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of access relationship structure by identifying and creating direct access relationships to replace indirect chains. By modifying the topological structure of access relationships (changing from multi-hop chains to direct connections), the system reduces complexity while preserving access flexibility

Inventive Principle:
Principle #35Parameter changes

2Reliability

If direct access relationships are created between entities, then security management and compliance are improved, but the number of access relationships and configuration complexity increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary discovery and analysis of access relationship chains before creating direct relationships. By pre-identifying which chains should be replaced and which entities need direct access, the system avoids ad-hoc configuration and ensures security compliance is built into the structure from the beginning

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access relationship management system automatically discovers chains, analyzes them, and creates optimized direct relationships without manual intervention. This self-service approach reduces configuration complexity by eliminating the need for administrators to manually configure each access relationship while maintaining security compliance

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If chained access relationships are used between entities, then indirect access paths are provided, but unintended access and security risks increase

Engineering Contradiction:
Improveaccess path flexibilityVSAvoidunintended access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system continuously discovers and monitors access relationship chains, providing feedback on which chains exist and whether they should be replaced. This feedback loop enables the system to identify unintended access paths and convert them to controlled direct relationships, eliminating security risks while maintaining necessary access flexibility

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes the potentially harmful chained access relationships and converts them into beneficial direct relationships. By discovering the chains and creating direct access paths, the system transforms the security risk of unintended indirect access into the benefit of controlled, visible, and manageable direct access

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11700258B2Access relationships in a computer system
Publication Date: 2023.07.11 SSH COMMUNICATIONS SECURITY
  • US11700258B2 patent drawing
  • US11700258B2 patent drawing
  • US11700258B2 patent drawing

AI summary

The disclosure relates to methods and apparatuses for controlling access relationships between entities in a computerized system. A chain of access relationships from a first entity via at least one intermediate entity to a second entity is determined. At least one direct access relationship is then created between the first entity and the second entity based on information of the determined chain of access relationships.