Anomaly-Based Access Control for Computing Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security risks posed by individuals with inappropriate access to computing assets is complex, especially in large organizations, due to internal and external threats ranging from negligence to malicious activities, and existing security techniques struggle to dynamically and efficiently address these risks in online computing environments.

Innovation Solution

The system calculates anomaly values for individuals or entities based on asset management data, including organizational information, communication interactions, and group memberships, to trigger automated or manual remediation actions, such as revoking access or escalating reviews, thereby mitigating security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security techniques are used to manage access rights for thousands of users and hundreds of computing resources, then access control policies can be enforced, but the complexity of granting and maintaining user access rights increases significantly

Engineering Contradiction:
Improveaccess control enforcementVSAvoidaccess rights management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that computes an anomaly score based on user behavior patterns and asset sensitivity. This intermediary layer automatically evaluates access requests against learned behavior models, reducing the manual complexity of managing access rights for thousands of users while maintaining reliable access control enforcement through automated anomaly detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual review processes are used to assess user access to critical assets, then security risks can be evaluated, but the process is time-consuming and cannot scale to large organizations

Engineering Contradiction:
Improvesecurity risk evaluationVSAvoidaccess review time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service automated access review where the anomaly detection system autonomously evaluates access requests without requiring manual reviewer intervention for every request. The system learns user behavior patterns and automatically computes anomaly scores, enabling security risk evaluation to scale to large organizations while maintaining reliable security assessment through continuous behavioral monitoring.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If access rights are granted based on organizational roles, then users can access appropriate resources for their functions, but the system cannot dynamically respond to changing security risks from insiders and outsiders

Engineering Contradiction:
Improverole-based access provisioningVSAvoiddynamic security response
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security response by continuously monitoring user behavior patterns and computing anomaly scores in real-time. The system adapts to changing security risks by learning normal behavior patterns for each user and dynamically adjusting access decisions based on deviations from these patterns, enabling the system to respond to insider threats and external attacks while maintaining ease of role-based access provisioning.

Inventive Principle:
Principle #15Dynamics

4Reliability

If comprehensive security monitoring is implemented to detect malicious activities, then security threats can be identified, but the computational resources and operational costs increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies local quality by computing anomaly scores selectively based on asset sensitivity and user behavior patterns rather than uniformly monitoring all access events. The system focuses computational resources on evaluating access requests to critical assets and users with higher anomaly risks, enabling comprehensive threat detection capability while reducing overall computational resource consumption and operational costs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11627136B1Access control for restricted access computing assets
Publication Date: 2023.04.11 AMAZON TECH INC
  • US11627136B1 patent drawing
  • US11627136B1 patent drawing
  • US11627136B1 patent drawing

AI summary

A system can determine a set of users to access an asset of a computing device. User data for a user in the set of users is obtained. The user data can specify organizational information for the user. The system can determine a value usable to regulate access to the asset. The value can be based on the organizational information for the user, and the value can be further based on other user data attributed to another user in the set of users. Based on the determined value, the system can regulate access to the asset.