Context-Sensitive Security Help for Cloud Permission Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, managing granular application security is complex due to the need for precise user permissions, which existing technologies struggle to address effectively, especially for large operations where physical access to servers is lost, making sensitive data at risk from insider attacks.

Innovation Solution

A method and system that utilize a display screen interface to examine and alter permissions within a computing program, allowing users to request permission changes through a user interface, which sends requests to administrators for access to specific actions, enhancing security by providing context-sensitive security help and granular permission management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If granular permission management is implemented in cloud applications, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments permission management into discrete, granular permissions that can be individually assigned and controlled. Each permission represents a separate unit of access control, allowing administrators to precisely define what resources and actions each user can access, thereby improving security control while maintaining manageable complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of context-sensitive security help that provides guidance to users based on their current location and actions within the application. This additional layer of contextual information assists users in understanding and requesting appropriate permissions without requiring them to navigate complex security configurations directly.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If context-sensitive security help is provided through user interface, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of permission managementVSAvoidinterface complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces context-sensitive security help as an intermediary layer between the user and the complex permission management system. This mediator provides contextual guidance and information based on the user's current state, translating complex security concepts into user-friendly suggestions and explanations without exposing the underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system provides self-service capabilities by automatically analyzing user context and presenting relevant permission requests and security information. Users can initiate permission requests based on contextual suggestions without needing to manually configure complex security settings, allowing the system to serve itself in managing security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9985973B2Context sensitive security help
Publication Date: 2018.05.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9985973B2 patent drawing
  • US9985973B2 patent drawing
  • US9985973B2 patent drawing

AI summary

Embodiments of the present invention provide systems and methods for providing security in a computing environment. These systems and methods can be applied to cloud computing environments. Interfaces allow a user to request and gain user access to applications (and their equivalents) even if the applications prior to implementing the present invention do not allow the user to request or gain user access to the applications. The embodiments of this invention can operate at the granular computing level.