Access Relationship Management System for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing complex and unintended access relationships in large computing environments is challenging due to the creation of accidental chains of trust, which can lead to unintended access to resources and difficulties in maintaining security and compliance with policies.
Innovation Solution
A method and apparatus for determining chains of access relationships and creating direct access relationships based on the determined chains, allowing for selective replacement of chained access relationships with direct ones, taking into account various criteria such as security credentials, data traffic, and policy compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If chains of access relationships are allowed to form naturally between entities, then access flexibility and connectivity are improved, but system complexity and security management difficulty increase
Solution Approach 1:
A centralized access relationship management system is introduced as an intermediary between entities. This mediator discovers, manages, and optimizes access relationships centrally, transforming the complex many-to-many relationships into manageable structured data that can be analyzed and optimized without increasing individual entity complexity
Solution Approach 2:
The system changes the parameter of access relationship structure by identifying and creating direct access relationships to replace indirect chains. By modifying the topological structure of access relationships (changing from multi-hop chains to direct connections), the system reduces complexity while preserving access flexibility
2Reliability
If direct access relationships are created between entities, then security management and compliance are improved, but the number of access relationships and configuration complexity increase
Solution Approach 1:
The system performs preliminary discovery and analysis of access relationship chains before creating direct relationships. By pre-identifying which chains should be replaced and which entities need direct access, the system avoids ad-hoc configuration and ensures security compliance is built into the structure from the beginning
Solution Approach 2:
The access relationship management system automatically discovers chains, analyzes them, and creates optimized direct relationships without manual intervention. This self-service approach reduces configuration complexity by eliminating the need for administrators to manually configure each access relationship while maintaining security compliance
3Adaptability or versatility
If chained access relationships are used between entities, then indirect access paths are provided, but unintended access and security risks increase
Solution Approach 1:
The system continuously discovers and monitors access relationship chains, providing feedback on which chains exist and whether they should be replaced. This feedback loop enables the system to identify unintended access paths and convert them to controlled direct relationships, eliminating security risks while maintaining necessary access flexibility
Solution Approach 2:
The system takes the potentially harmful chained access relationships and converts them into beneficial direct relationships. By discovering the chains and creating direct access paths, the system transforms the security risk of unintended indirect access into the benefit of controlled, visible, and manageable direct access
Data Source
AI summary
The disclosure relates to methods and apparatuses for controlling access relationships between entities in a computerized system. A chain of access relationships from a first entity via at least one intermediate entity to a second entity is determined. At least one direct access relationship is then created between the first entity and the second entity based on information of the determined chain of access relationships.


