Custom Access Policy Generation via Behavioral Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote-computing services often employ generic access policies that fail to meet the specific needs of individual users and applications, as administrators lack precise knowledge of the necessary access permissions, leading to ill-suited policies.

Innovation Solution

Implementing a learning-mode system where the access manager tracks interactions of users and applications, crafting custom policies based on their behavior over time, and iteratively refining these policies with administrator feedback to ensure accurate access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If generic access policies are used for all users and applications, then device complexity and policy management overhead are reduced, but the suitability and precision of access permissions deteriorate

Engineering Contradiction:
Improvepolicy management complexityVSAvoidaccess permission precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments access policies into two categories: generic policies for common scenarios and custom policies for specific users and applications. This segmentation allows the system to maintain simplicity for most cases while providing precision when needed, resolving the contradiction between policy management complexity and access permission precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service by automatically generating custom access policies based on observed user behavior and interactions with resources. This automation eliminates the need for manual policy creation and reduces administrative overhead while providing precise, tailored access permissions, thus resolving the contradiction between policy complexity and permission precision.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If administrators manually assign different access policies to different users and applications, then access permission precision is improved, but device complexity and time consumption increase

Engineering Contradiction:
Improveaccess permission precisionVSAvoidpolicy creation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically generating custom access policies based on pre-collected behavioral data and interaction patterns. This eliminates the need for time-consuming manual policy creation while maintaining high precision in access permissions, thus resolving the contradiction between permission precision and policy creation time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring user interactions with resources and using this information to automatically refine and update access policies. This automated feedback loop provides precise access permissions without requiring manual administrator intervention, resolving the contradiction between permission precision and time consumption.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If custom policies are created for each user and application based on their specific needs, then access permission precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccess permission precisionVSAvoidpolicy management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system employs self-service automation to generate and manage custom access policies based on observed user behavior. This automation handles the complexity of creating and maintaining individualized policies without increasing manual management overhead, thus resolving the contradiction between access permission precision and policy management complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts access policy parameters based on changing user behavior patterns and resource interaction data. This automated parameter adjustment provides precise access permissions adapted to specific needs without requiring complex manual policy management, resolving the contradiction between permission precision and management complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8918834B1Creating custom policies in a remote-computing environment
Publication Date: 2014.12.23 AMAZON TECH INC
  • US8918834B1 patent drawing
  • US8918834B1 patent drawing
  • US8918834B1 patent drawing

AI summary

Techniques for crafting custom policies for entities (e.g., users, applications, etc.) based on past behavior of the entities are described herein. In one example, the techniques are implemented in a network-based environment. In this environment, a remote-computing service may include multiple different resources that provide different services to customers of the remote-computing service. For instance, the remote-computing service may provide a network-based storage service, a network-based compute service, a network-based payment service, or any other network-based resource. Users and/or applications of a particular customer may then access these resources via an interface provided by the remote-computing service. After tracking a user or application's access to these resources for a certain period of time, the remote-computing service may recommend or create a custom policy for the user or application based on the requests made by the user or application.