Dynamic Access Control via Confidence Determination Machine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems fail to continuously monitor user and terminal confidence levels after initial authentication, leaving internal resources vulnerable to malicious behavior and data leaks.
Innovation Solution
A dynamic access control system that employs a confidence determination machine to continuously monitor user and terminal confidence levels, using an agent installed on the user terminal to collect registry data and verify state information against a security policy, allowing or denying access to an in-house resource management server based on determined confidence levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems are used, then users can access resources after initial login, but the system cannot detect or prevent malicious behavior after authentication
Solution Approach 1:
The system performs preliminary actions by registering confidence determination criteria and security policies before authentication occurs. The confidence determination machine pre-configures multiple confidence criteria (device state, user behavior patterns, network environment) and security policies that will be automatically applied during and after authentication, enabling continuous monitoring without requiring complex real-time decision-making infrastructure
Solution Approach 2:
The confidence determination machine serves as an intermediary component between the authentication system and resource management server. It receives authentication results, independently evaluates user confidence levels based on registered criteria, and provides confidence-based access decisions to the resource management server, thereby adding monitoring capability without directly complicating the core authentication or resource management systems
2Reliability
If continuous monitoring is implemented, then malicious behavior can be detected, but the system complexity and computational overhead increase
Solution Approach 1:
The monitoring function is segmented into distinct confidence criteria (device state monitoring, user behavior analysis, network environment assessment) that can be independently evaluated and weighted. Each criterion is registered separately in the confidence determination machine with its own evaluation rules, allowing the system to monitor multiple aspects of user activity without requiring a monolithic complex monitoring architecture
Solution Approach 2:
The system changes parameters by dynamically adjusting confidence levels based on monitored criteria rather than using fixed access permissions. User confidence levels are continuously updated based on changes in device state, behavior patterns, and environmental factors, allowing the system to adapt security responses to current conditions without requiring complex real-time rule evaluation
3Reliability
If confidence level verification is performed, then unauthorized access can be prevented, but the access control process becomes more complex
Solution Approach 1:
The confidence determination machine performs self-service by autonomously evaluating user confidence levels based on pre-registered criteria without requiring manual security administrator intervention for each access decision. The system automatically collects criterion data, calculates confidence levels, and provides access recommendations to the resource management server, thereby maintaining security verification while reducing operational complexity
Solution Approach 2:
The access control system transitions from static permission-based access to dynamic confidence-based access. Confidence levels are continuously updated based on real-time evaluation of registered criteria, allowing the system to automatically adjust access permissions based on current user trustworthiness without requiring complex manual permission management or rigid access rules
Data Source
AI summary
The present invention relates to a dynamic access control system based on confidence levels of a user and a user terminal, including: an agent installed in the user terminal, and configured to collect a registry generated in the user terminal; a confidence determination machine in which legitimate user information and legitimate user terminal information are registered, configured to perform identity authentication for the user and the user terminal, which request access to an in-house resource management server, and configured to perform verification on state information of the user terminal based on a security policy that is previously distributed to determine a confidence level when the identity authentication for the user and the user terminal is completed; and a terminal management server configured to transmit a registry collection result from the agent to the confidence determination machine as the state information of the user terminal.


