Authority Management Using User Portrait Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of traditional authority management in cloud computing using Access Control Lists (ACLs) leads to potential misuse and unauthorized access, compromising data confidentiality and integrity.

Innovation Solution

An authority management method and device that utilizes a portrait model constructed via machine learning to analyze user behavior, determining a matching degree and applying a preset early warning mechanism to adjust access authorities, including locking operations based on thresholds to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional ACL-based authority management is implemented, then access control functionality is provided, but the complexity of management increases and leads to potential misuse

Engineering Contradiction:
Improvedata securityVSAvoidACL management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a portrait model as an intermediary between user behavior and access control decisions. The portrait model analyzes user behavior patterns and generates risk assessments, which then inform ACL decisions. This mediator simplifies management by automatically evaluating user intent and risk level, reducing the complexity of manual ACL configuration while maintaining or enhancing security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where user behavior is continuously monitored, compared against the portrait model, and used to dynamically adjust access authorities. The early warning mechanism provides feedback when abnormal behavior is detected, allowing real-time adjustments to ACL settings without requiring complex manual reconfiguration, thus improving security while managing complexity.

Inventive Principle:
Principle #23Feedback

2Reliability

If detailed ACL settings are configured to improve security, then data protection is enhanced, but the ease of operation deteriorates due to complicated management

Engineering Contradiction:
Improvedata confidentialityVSAvoidACL configuration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The portrait model enables self-service authority management by automatically analyzing user behavior patterns and making access control decisions without requiring manual ACL configuration. The system serves itself by continuously learning from user behavior and autonomously adjusting access authorities, thereby enhancing data confidentiality while eliminating the operational burden of complex ACL settings.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of access control from static ACL rules to dynamic behavior-based assessments. By monitoring user behavior parameters such as access patterns, timing, and resource types, the portrait model dynamically adjusts access authorities to match actual user intent, improving data confidentiality without requiring users to manually configure complex ACL parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If early warning mechanism is applied to user access authorities, then unauthorized access is prevented, but the device complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthority management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The portrait model performs preliminary analysis of user behavior patterns before access decisions are made. By pre-establishing behavioral baselines and risk thresholds, the system can quickly evaluate new access requests against these pre-computed models, preventing unauthorized access without requiring complex real-time analysis infrastructure. The early warning mechanism is triggered based on pre-defined criteria, simplifying the overall system architecture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10965680B2Authority management method and device in distributed environment, and server
Publication Date: 2021.03.30 BEIJING BAIDU NETCOM SCI & TECH CO LTD
  • US10965680B2 patent drawing
  • US10965680B2 patent drawing
  • US10965680B2 patent drawing

AI summary

An authority management method and device in a distributed environment, and a server are provided. The method includes: obtaining usage information of a user when the user uses an object storage product, the usage information including the user's behavior, status and feature; determining a matching degree between the usage information of the user and usage information predicted by a portrait model of the user; and applying a preset early warning mechanism to the user's access authorities according to the matching degree.