Cloud Usage Rights Calculation for Trust-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud services face security challenges due to external access and difficulty in managing security, especially when users access resources outside secure facilities, necessitating improved user-customized usage rights management.

Innovation Solution

A calculation system that determines user-specific usage rights using analysis activity information, including log data, through natural language processing and deep learning, and an integrated system to manage and control access based on trust conditions and recommendation rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud services allow external access through various paths, then service accessibility and convenience are improved, but security vulnerabilities and risk of external intrusion increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic usage rights that are locally customized for each user based on their specific behavior patterns, trust conditions, and activity analysis. Instead of uniform access control, the system assigns different usage rights (full rights, limited rights, no rights) to different users or access scenarios, allowing secure external access where trust conditions are met while restricting access where risks are detected.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts usage rights based on real-time activity analysis and trust condition evaluation. Usage rights are not static but change according to user behavior patterns, device information, location data, and other dynamic factors. This allows the system to adapt security levels to current conditions, maintaining accessibility when safe and blocking when risky.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If users access cloud services outside secure facilities, then service flexibility and mobility are improved, but security management difficulty increases

Engineering Contradiction:
Improveservice flexibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs self-service security management by automatically analyzing user activity patterns, evaluating trust conditions, and determining appropriate usage rights without requiring manual security administrator intervention for each access decision. The AI model continuously learns from user behavior and autonomously adjusts access control policies, reducing the complexity of security management while maintaining flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where user activity information is collected, analyzed, and used to adjust usage rights. The activity analysis module monitors user behavior, and the usage right determination module uses this feedback to dynamically modify access permissions. This closed-loop system automatically adapts to changing conditions without increasing management complexity.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If usage rights are granted based on comprehensive activity analysis, then security and precision are improved, but computational complexity and processing time increase

Engineering Contradiction:
Improveusage right determination accuracyVSAvoidcalculation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex security management task into distinct functional modules: activity information collection, activity pattern analysis, trust condition evaluation, and usage right determination. Each module handles a specific aspect of the analysis, making the overall complex system manageable through modular design. The segmentation allows parallel processing and independent optimization of each component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-establishing trust conditions, activity patterns, and usage right rules before actual access decisions are needed. The AI model is pre-trained on historical data, and usage right policies are pre-configured based on analyzed patterns. When access decisions are required, the system只需 applies pre-computed rules rather than performing full analysis in real-time, reducing processing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12542784B2Calculation system of user-customized usage right for cloud security and integrated system for optimizing usage right including same
Publication Date: 2026.02.03 OKESTRO CO LTD
  • US12542784B2 patent drawing
  • US12542784B2 patent drawing
  • US12542784B2 patent drawing

AI summary

A calculation system that calculates a usage right for resources of a cloud server by a user using a cloud service according to an embodiment of the present disclosure may include: a reception module that generates analysis activity information, which is activity information generated while the user uses the cloud server, in order to determine the usage right; a right module that uses a predetermined analysis method based on the analysis activity information to calculate a corresponding right, which is the usage right corresponding to the analysis activity information and applicable only to a specific user; and a transmission module that transmits a recommendation right calculated utilizing the corresponding right through a predetermined path.