Adaptive Access Control Policies for Dynamic Permission Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing and managing least privilege security policies is challenging, especially in complex systems with multiple users and resources, due to mismatched client capabilities and changing user permissions, leading to potential security risks and inefficiencies.

Innovation Solution

A system that uses adaptive access management through web service API requests, monitoring user activity, and dynamically adjusting permissions based on recorded activity data and metadata, applying adaptive policies to grant or deny access to computing resources, and requiring additional authentication when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static permission policies are granted to clients, then clients can perform required actions, but clients may retain unnecessary permissions that increase security risk

Engineering Contradiction:
ImprovesecurityVSAvoidpermission management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic permission policies that automatically adjust client access rights based on monitored activity patterns. The system observes client behavior over time and modifies permissions to match actual usage, transforming static permission assignments into adaptive, living policies that reduce security risks while maintaining operational ease.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where client activity is continuously monitored and fed back into the permission management system. This feedback mechanism enables the system to learn from actual usage patterns and automatically adjust permissions, resolving the contradiction between security and operational ease by making permission management self-regulating.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If comprehensive permissions are granted to maintenance clients, then essential functions can be performed, but supporting systems may be broken by unnecessary changes

Engineering Contradiction:
Improveclient capabilityVSAvoidsystem risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of client activity patterns before granting or modifying permissions. By monitoring and understanding what actions clients actually need to perform their maintenance functions, the system can pre-configure appropriate permission levels that enable essential work while preventing access to unrelated systems that could cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different permission levels to different clients based on their specific roles and observed activity patterns. Instead of uniform comprehensive permissions, each client receives tailored access rights localized to their specific maintenance needs, enabling them to perform essential functions while limiting exposure to systems they don't need to access.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If permission policies are manually managed in complex systems, then access control can be implemented, but the complexity of multiple users and resources makes it difficult

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements self-service permission management where the system automatically monitors client activity, analyzes patterns, and adjusts permissions without manual intervention. This self-service approach handles the complexity of multiple users and resources automatically, making access control easy to maintain despite system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically changes permission parameters based on observed client behavior and system conditions. Rather than manually configuring static parameters, the system automatically adjusts permission parameters in response to changing conditions, reducing the operational burden of managing complex multi-user systems.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If clients are given broad access rights, then they can be more efficient, but credentials may be stolen or used improperly with no value

Engineering Contradiction:
Improveclient efficiencyVSAvoidcredential security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements dynamic permission adjustment that responds to changing conditions including security events. When credentials are compromised or abnormal activity is detected, the system automatically reduces permissions while maintaining client efficiency for legitimate operations, resolving the contradiction between productivity and credential security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates security feedback mechanisms that monitor client activity for signs of credential compromise. When suspicious patterns are detected, the feedback loop triggers automatic permission reductions, maintaining client efficiency for legitimate work while protecting against stolen or misused credentials.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11509658B1Adaptive access control policies
Publication Date: 2022.11.22 AMAZON TECH INC
  • US11509658B1 patent drawing
  • US11509658B1 patent drawing
  • US11509658B1 patent drawing

AI summary

A set of parameters for a set of permissions are determined based at least in part on previous requests to access a set of resources by a principal or user. The set of permissions are updated based at least in part on the set of parameters such that the set of parameters cause different requests to have different authentication requirements. The updated set of permissions is enforced to control access to computing resources such as the set of resources.