Authorization Policy Optimization via Log Feature Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems face challenges in performing fine-grained authorization policy optimization due to coarse granularity, limiting their ability to effectively manage and optimize data access rights and authentication processes.
Innovation Solution
An authorization policy optimization method and apparatus that utilizes a computing device to receive an authorization policy, extract log information features, generate an optimization model, perform reasonableness prediction, and optimize the policy based on predicted values, enabling fine-tuned data access control and improved authentication operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If complete authentication logs are generated for coarse-grained analysis, then basic statistics collection and analysis can be performed, but fine authorization policy optimization cannot be achieved due to excessively coarse granularity
Solution Approach 1:
The patent segments authentication logs into multiple granularity levels: coarse-grained logs for overall statistics and fine-grained logs for detailed policy optimization. This segmentation allows the system to maintain both comprehensive monitoring capability and precise optimization capability without generating excessive complexity, as each granularity level serves a specific purpose in the authorization policy optimization process
2Loss of information
If coarse-grained log analysis is used, then basic authentication statistics can be obtained, but obvious problems can only be found and resolved while fine authorization policy optimization cannot be performed
Solution Approach 1:
The patent performs preliminary action by pre-processing authentication logs to extract and store key features at multiple granularity levels before policy optimization is needed. This includes pre-computing both coarse-grained statistics and fine-grained authentication patterns, so that when policy optimization is required, the system can immediately access prepared fine-grained information without performing complex real-time analysis, thus improving productivity while preserving detailed information
Data Source
AI summary
An authorization policy optimization method being performed by a computing device comprising at least one processor, includes receiving an authorization policy to be used to perform an authentication on a data access right of a user, obtaining authorization log information of a first preset authorization policy, from the authorization policy, extracting a log information feature, from the authorization log information, generating an authorization policy optimization model, using the log information feature, performing a policy reasonableness prediction on the authorization policy, using the authorization policy optimization model, to obtain a predicted reasonableness value corresponding to the authorization policy, and performing an optimization processing on the authorization policy, based on the predicted reasonableness value.


