Context-Aware Access Control Automation for Cloud Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital resource access control systems, particularly in cloud-based unstructured information systems, face challenges in managing dynamic organizational structures, overlapping user roles, and the complexity of commercial, security, and compliance implications, leading to laborious maintenance, errors, and inflexibility in access control.

Innovation Solution

A digital resource access control system comprising an integration layer, an access orchestration engine, a context change detection engine, and an access control list automation engine that automatically updates access control lists based on user attribute changes, ensuring real-time alignment with organizational dynamics and reducing manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Access Control Lists (ACLs) are manually maintained to control digital resource access, then flexibility in managing user permissions is improved, but labor intensity and error rate increase significantly

Engineering Contradiction:
Improveflexibility in managing user permissionsVSAvoidlabor intensity and error rate
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically monitors user attribute changes and updates access control configurations without manual intervention. The context change detection engine continuously monitors user attributes and automatically triggers access control list updates when changes are detected, eliminating the need for manual maintenance while preserving flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where context changes are detected and automatically fed back to update access control configurations. The context change detection engine monitors user attributes and feeds this information back to the access control system, which automatically adjusts permissions based on the detected changes.

Inventive Principle:
Principle #23Feedback

2Device complexity

If Role-Based Access Control (RBAC) is implemented to automatically update user access when roles change, then maintenance effort is reduced, but the system becomes too rigid to handle users with multiple roles or temporary access requirements

Engineering Contradiction:
Improvemaintenance effortVSAvoidability to handle multiple roles and temporary access
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system transitions from discrete role-based parameters to continuous attribute-based parameters. Instead of treating user access as fixed role assignments, the system monitors changes in user attributes (such as department, position, location) and dynamically adjusts access controls based on these parameter changes, enabling flexible handling of multiple roles and temporary access scenarios.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system makes the access control configuration dynamic by continuously monitoring user attribute changes and automatically updating permissions in real-time. The context change detection engine tracks user attributes and dynamically adjusts access control lists as attributes change, allowing users to have multiple roles and temporary access without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If Attribute-Based Access Control (ABAC) is used to precisely match user attributes with access rules, then access control precision is improved, but the system assumes a rigid organizational structure that cannot accommodate gradual or overlapping changes

Engineering Contradiction:
Improveaccess control precisionVSAvoidability to handle fluid organizational structures
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic monitoring of user attributes and automatic adjustment of access controls based on detected changes. The context change detection engine continuously tracks user attributes and triggers automatic updates when changes are detected, allowing the system to adapt to fluid organizational structures while maintaining precise access control matching.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically detects and responds to organizational structure changes without manual intervention. The context change detection engine autonomously monitors user attributes and triggers access control updates when changes are detected, eliminating the need for manual reconfiguration while maintaining precise access control.

Inventive Principle:
Principle #25Self-service

4Reliability

If manual updates to access control configurations are performed to reflect employee changes, then system security is maintained, but human resources are consumed and errors occur

Engineering Contradiction:
Improvesystem securityVSAvoidhuman resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically maintains security by detecting user attribute changes and updating access control configurations without manual intervention. The context change detection engine continuously monitors user attributes and automatically triggers access control updates, eliminating the need for manual security maintenance while preserving system security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements automatic feedback loops where user attribute changes are detected and automatically fed back to update access control configurations. This feedback mechanism ensures system security is maintained automatically without consuming human resources or introducing manual errors.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240176513A1Digital resource access control system and method
Publication Date: 2024.05.30 TORSION INFORMATION SECURITY LTD
  • US20240176513A1 patent drawing
  • US20240176513A1 patent drawing
  • US20240176513A1 patent drawing

AI summary

A digital resource access control system and method comprising for controlling access to a digital resource stored on an information management system to reflect context of a reason for access and the circumstances of a user in a cloud environment for unstructured data.