Automated Data Bucket Access Policy Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data buckets face challenges in maintaining security while allowing access to authorized entities, with frequent changes in personnel and teams leading to manual intensive operations and outdated access policies, resulting in unsecure data buckets and inefficient systems.

Innovation Solution

An automated policy generator analyzes usage data and access logs to determine access requirements, creating and updating access policies to provide minimal required access, using filter algorithms to extract and aggregate entity lists and apply them to policy templates, ensuring improved security and adaptability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual operations are used to manage access policies, then flexibility in handling personnel changes is possible, but the operation becomes intensive and time-consuming

Engineering Contradiction:
Improvemanual access policy managementVSAvoidtime for manual policy updates
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system automatically generates access policies by analyzing usage data and access logs without requiring manual intervention. The policy generator autonomously identifies entities that accessed the data bucket and creates appropriate access policies based on this analysis, eliminating the need for manual policy management operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of access logs and usage data to identify access patterns and entities before policies are needed. By pre-processing the access log data and maintaining an updated understanding of entity access requirements, the system prepares the information needed for rapid policy generation when personnel changes occur

Inventive Principle:
Principle #10Preliminary action

2Stability of the object's composition

If access policies are not frequently updated, then system stability is maintained, but security is compromised due to outdated policies

Engineering Contradiction:
Improveaccess policy stabilityVSAvoiddata bucket security
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The system periodically analyzes access logs and automatically updates access policies at regular intervals or when triggered by specific events. This periodic action ensures policies remain current with actual usage patterns while maintaining system stability through systematic, scheduled updates rather than ad-hoc changes

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system continuously monitors access logs and usage data to provide feedback on actual access patterns. This feedback loop enables the policy generator to detect changes in access requirements and automatically adjust policies accordingly, ensuring security remains aligned with actual usage while maintaining stability through data-driven adjustments

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive access policies are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improvedata bucket securityVSAvoidaccess policy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential access information from comprehensive access logs, identifying specific entities and their access patterns. By filtering and extracting only the necessary policy-relevant data rather than processing all access log details, the system generates focused access policies that provide security without unnecessary complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments access policies by entity type and access pattern, creating modular policy statements that can be independently managed. By dividing the access control system into discrete entity-based policies rather than a single comprehensive policy, the system achieves thorough security coverage while maintaining manageable complexity through organized, separable policy components

Inventive Principle:
Principle #1Segmentation

4Productivity

If automated policy generation is implemented, then productivity is improved, but resource consumption increases

Engineering Contradiction:
Improvepolicy generation efficiencyVSAvoidcomputational resources
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system performs partial analysis of access logs, focusing only on the portions of data necessary for policy generation rather than processing all available log data. By analyzing only the relevant subset of access logs and usage data needed to identify entities and their access patterns, the system achieves automated policy generation productivity while consuming fewer computational resources than a complete analysis would require

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10831906B1Techniques for automatic bucket access policy generation
Publication Date: 2020.11.10 CAPITAL ONE SERVICES LLC
  • US10831906B1 patent drawing
  • US10831906B1 patent drawing
  • US10831906B1 patent drawing

AI summary

Various embodiments are generally directed to techniques for generating updating, and/or validating one or more aspects of an access policy for a data bucket, such as based on usage data corresponding to the data bucket, for instance. Some embodiments are particularly directed to automatically generating, updating, and/or validating an access policy for a data bucket based on analysis of log data corresponding to the data bucket. In some embodiments, log data comprising access records to a data bucket may be analyzed to determine access requirements for a set of entities. In some such embodiments, the access requirements for the set of entities may then be used to generate an access policy for the data bucket.