Criteria-Based Timeout Protocols for Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems face challenges in dynamically adapting to sophisticated threats such as malware, session hijacking, and internal threats, as they rely on passive security measures that are inadequate for today's complex and ever-changing security climate, especially when resources are segregated across multiple application domains.

Innovation Solution

Implementing a timeout protocol by an access manager that applies criteria-based security measures across multiple resources, allowing administrators to dynamically control access by associating timeout protocols with resources based on attributes and values, thereby enhancing security flexibility and adaptability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passive security measures are used to maintain authenticated sessions, then ease of operation is improved, but security reliability deteriorates due to inability to adapt to sophisticated threats

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic timeout protocols that automatically adjust session termination based on predefined criteria such as time of day, user behavior patterns, and security events. This transforms static passive security into an adaptive system that responds to changing threat conditions while maintaining operational simplicity for users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters (timeout values, protocol activation) based on detected conditions and criteria. Administrators can define multiple timeout protocols with different parameters that are automatically applied based on the current security context, enabling flexible response to various threat scenarios without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If timeout protocols are applied to each resource individually across multiple application domains, then security precision is improved, but device complexity worsens due to management overhead

Engineering Contradiction:
Improvesecurity precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a centralized timeout protocol management system that serves multiple application domains and resources simultaneously. A single timeout protocol can be applied across numerous resources by referencing their attributes, eliminating the need to configure each resource individually while maintaining precise security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer (the access manager with timeout protocol engine) that sits between the security policies and individual resources. This intermediary handles the complexity of applying security protocols across multiple domains by automatically matching resource attributes with protocol criteria, shielding administrators from the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If criteria-based timeout protocols are implemented across multiple application domains, then adaptability to threats is improved, but difficulty of detecting and measuring worsens due to complex criterion evaluation

Engineering Contradiction:
ImproveadaptabilityVSAvoiddifficulty of detecting and measuring
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The timeout protocol system automatically evaluates resource attributes against predefined criteria without requiring manual detection or measurement intervention. The access manager autonomously determines which protocols apply to which resources based on attribute matching, reducing the burden on security personnel to manually monitor and adjust security measures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors resource attributes and security events, automatically adjusting timeout protocol application based on detected conditions. This feedback loop enables the system to adapt to new threats and patterns while maintaining transparent operation, with the access manager automatically logging and reporting protocol applications for audit purposes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9596328B2Hierarchical criteria-based timeout protocols
Publication Date: 2017.03.14 ORACLE INT CORP
  • US9596328B2 patent drawing
  • US9596328B2 patent drawing
  • US9596328B2 patent drawing

AI summary

A method of applying a timeout protocol by an access manager to a plurality of resources may include storing the timeout protocol comprising at least one criterion, and receiving a request for a first resource. Each of the resources can be segregated into separate application domains, the first resource can be associated with a first attribute, and the first attribute can be assigned a first value. The method may also include determining that the first value satisfies the at least one criterion, associating the timeout protocol with the first resource, and associating the timeout protocol with each resource that is associated with the first attribute assigned a value that satisfies the at least one criterion. The method may further include granting access to the first resource according to the timeout protocol.