Dynamic Access Control via Confidence Determination Machine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems fail to continuously monitor user and terminal confidence levels after initial authentication, leaving internal resources vulnerable to malicious behavior and data leaks.

Innovation Solution

A dynamic access control system that employs a confidence determination machine to continuously monitor user and terminal confidence levels, using an agent installed on the user terminal to collect registry data and verify state information against a security policy, allowing or denying access to an in-house resource management server based on determined confidence levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used, then users can access resources after initial login, but the system cannot detect or prevent malicious behavior after authentication

Engineering Contradiction:
Improvesecurity protectionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by registering confidence determination criteria and security policies before authentication occurs. The confidence determination machine pre-configures multiple confidence criteria (device state, user behavior patterns, network environment) and security policies that will be automatically applied during and after authentication, enabling continuous monitoring without requiring complex real-time decision-making infrastructure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The confidence determination machine serves as an intermediary component between the authentication system and resource management server. It receives authentication results, independently evaluates user confidence levels based on registered criteria, and provides confidence-based access decisions to the resource management server, thereby adding monitoring capability without directly complicating the core authentication or resource management systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous monitoring is implemented, then malicious behavior can be detected, but the system complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring function is segmented into distinct confidence criteria (device state monitoring, user behavior analysis, network environment assessment) that can be independently evaluated and weighted. Each criterion is registered separately in the confidence determination machine with its own evaluation rules, allowing the system to monitor multiple aspects of user activity without requiring a monolithic complex monitoring architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters by dynamically adjusting confidence levels based on monitored criteria rather than using fixed access permissions. User confidence levels are continuously updated based on changes in device state, behavior patterns, and environmental factors, allowing the system to adapt security responses to current conditions without requiring complex real-time rule evaluation

Inventive Principle:
Principle #35Parameter changes

3Reliability

If confidence level verification is performed, then unauthorized access can be prevented, but the access control process becomes more complex

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The confidence determination machine performs self-service by autonomously evaluating user confidence levels based on pre-registered criteria without requiring manual security administrator intervention for each access decision. The system automatically collects criterion data, calculates confidence levels, and provides access recommendations to the resource management server, thereby maintaining security verification while reducing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access control system transitions from static permission-based access to dynamic confidence-based access. Confidence levels are continuously updated based on real-time evaluation of registered criteria, allowing the system to automatically adjust access permissions based on current user trustworthiness without requiring complex manual permission management or rigid access rules

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250158994A1System of access control based on confidence level of user and user terminal
Publication Date: 2025.05.15 SGA SOLUTIONS CO LTD
  • US20250158994A1 patent drawing
  • US20250158994A1 patent drawing
  • US20250158994A1 patent drawing

AI summary

The present invention relates to a dynamic access control system based on confidence levels of a user and a user terminal, including: an agent installed in the user terminal, and configured to collect a registry generated in the user terminal; a confidence determination machine in which legitimate user information and legitimate user terminal information are registered, configured to perform identity authentication for the user and the user terminal, which request access to an in-house resource management server, and configured to perform verification on state information of the user terminal based on a security policy that is previously distributed to determine a confidence level when the identity authentication for the user and the user terminal is completed; and a terminal management server configured to transmit a registry collection result from the agent to the confidence determination machine as the state information of the user terminal.