Composite Activity Graphs for Dynamic Access Grant Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in comprehensively managing user access rights due to the dynamic nature of organizational structures, diverse data sources, and evolving regulatory landscapes, leading to vulnerabilities in data access control.

Innovation Solution

A data management server that provides adaptive security applications, including access graphs and risk monitoring, to streamline data access management, identify high-risk activities, and automate decision-making processes, thereby enhancing security posture and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional role-based access control methods are used, then implementation is simple, but they fall short of adequately addressing nuanced needs of modern enterprises with diverse data sources and dynamic organizational structures

Engineering Contradiction:
Improveadaptability to nuanced enterprise needsVSAvoidaccess control system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control into multiple independent components: access graphs representing data relationships, activity graphs representing user behaviors, risk assessments for individual access requests, and policy engines. This segmentation allows each component to be optimized independently while collectively providing nuanced adaptability to enterprise needs without overwhelming system-wide complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic access control where permissions are not static but continuously adjusted based on real-time risk assessments, user activity patterns, and contextual factors. Access decisions adapt dynamically to changing organizational structures, data sensitivity levels, and user behaviors, enabling the system to address nuanced enterprise needs while maintaining manageable complexity through automated adaptation.

Inventive Principle:
Principle #15Dynamics

2Reliability

If granular control over data access is maintained to address dynamic organizational structures, then security is improved, but managing access rights becomes a daunting task

Engineering Contradiction:
Improvedata access securityVSAvoidaccess rights management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service mechanisms where access control decisions are automatically made by the system based on pre-defined policies, risk assessments, and activity analysis. The automated access control engine evaluates each access request independently, adjusting permissions in real-time without requiring manual intervention for each decision, thereby maintaining high security through granular control while significantly reducing the operational burden on administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors user activities, data access patterns, and organizational changes, feeding this information back into the risk assessment and access decision-making processes. This feedback loop enables the system to automatically adjust access permissions in response to changing conditions, maintaining reliable security control while reducing manual management efforts through automated responsive adjustments.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If comprehensive monitoring of user access rights is implemented, then security vulnerabilities are reduced, but system complexity and computational requirements increase

Engineering Contradiction:
Improvesecurity vulnerabilitiesVSAvoidmonitoring system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements risk-based monitoring where the depth and scope of monitoring activities are adjusted based on assessed risk levels. High-risk users, sensitive data accesses, and anomalous behaviors receive comprehensive monitoring, while low-risk routine operations receive minimal monitoring. This partial monitoring approach effectively reduces security vulnerabilities by focusing resources on critical areas while avoiding the excessive complexity and computational overhead of uniform comprehensive monitoring across all operations.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The monitoring system applies different levels of surveillance and analysis to different users, data types, and access contexts based on their specific risk profiles. Sensitive data repositories receive enhanced monitoring, while less critical data receives standard monitoring. This localized quality approach reduces overall system complexity by concentrating monitoring resources where they are most needed rather than implementing uniform complex monitoring across the entire system.

Inventive Principle:
Principle #3Local quality

4Speed

If real-time access decisions are made based on risk assessment, then security response time is improved, but computational processing requirements increase

Engineering Contradiction:
Improveaccess decision speedVSAvoidcomputational processing energy
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary risk assessments and establishes baseline risk profiles for users, data, and contexts before actual access requests occur. Pre-computed risk scores, policy rules, and activity patterns are prepared in advance, enabling the system to make real-time access decisions by comparing current requests against pre-established criteria rather than performing full risk assessments from scratch for each request, thus achieving fast response times with reduced computational energy consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the depth and complexity of risk assessment parameters based on contextual factors such as user trust levels, data sensitivity, and request patterns. For low-risk scenarios, simplified parameter evaluation is used requiring minimal computational energy, while high-risk scenarios trigger more comprehensive parameter analysis. This adaptive parameter changing enables real-time decision-making speed while optimizing computational energy usage by avoiding unnecessary complex processing for routine operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250307361A1Composite activity graph based access grant and revocation
Publication Date: 2025.10.02 OLERIA CORP
  • US20250307361A1 patent drawing
  • US20250307361A1 patent drawing
  • US20250307361A1 patent drawing

AI summary

A data management system establishes connections with access control systems which are delegated by a domain to control data access and maintain data access history associated with the domain. The system receives a group access permission of a set of data resources to a group of named entities and heterogeneous sets of metadata related to the data access history and generates graph objects. The graph objects include named entity nodes and resource nodes. The named entity node represents a named entity associated with an organization, and the resource node represents a data resource. The system traverses access paths that connect the named entity node and the resource node determines a utilization level of a set of access paths. Based on the utilization level, the system revokes the set of access paths, thereby revoking an access permission of the set of named entity in the group to the specific data resource.