Data Risk Index Scoring for Cloud Permission Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As enterprises increasingly use cloud platforms for storage and application services, managing permissions becomes complex, leading to incremental risks of unauthorized data access and data corruption, necessitating a mechanism to quantify and mitigate security risks effectively.

Innovation Solution

A system that assigns a data risk index (DRI) score to resources based on collected access data, generating a value indicative of the risk of compromise, and reports this score or alerts administrators to enable policy changes and improve security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If permissions are granted to multiple identities to access shared resources, then operational capability and service availability are improved, but security risk increases due to unauthorized data access and data corruption

Engineering Contradiction:
Improveoperational capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the permission management system by introducing identity-based risk scoring and resource-based sensitivity scoring. Each identity is evaluated individually to determine its risk level, and each resource is assessed for its sensitivity. This segmentation allows the system to grant permissions selectively based on risk profiles rather than applying uniform permission policies, thereby maintaining operational capability while reducing security risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of permission management from binary (granted/not granted) to a continuous risk score spectrum. By calculating risk scores based on identity attributes, resource sensitivity, and access patterns, the system can dynamically adjust permission levels. This parameter change enables fine-grained control where permissions can be modified based on real-time risk assessments, balancing operational needs with security requirements.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive resource access data is collected to assess security risk, then measurement precision of risk level is improved, but device complexity and data processing requirements increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the most critical features from comprehensive resource access data for risk assessment. Instead of analyzing all possible data points, the system focuses on key attributes such as identity type, resource sensitivity classification, and historical access patterns. This extraction approach maintains high measurement precision by concentrating on the most predictive features while reducing system complexity by eliminating unnecessary data processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by collecting and analyzing only the subset of data necessary for effective risk assessment. Rather than comprehensively monitoring all access data, the system selectively gathers information about critical security-relevant events and patterns. This partial data collection approach achieves sufficient measurement precision for security purposes while significantly reducing device complexity and processing requirements.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If strict permission policies are implemented to reduce security risk, then security level is improved, but operational efficiency and service availability deteriorate

Engineering Contradiction:
Improvesecurity levelVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces dynamics into permission policies by making them adaptive rather than static. Permission policies automatically adjust based on real-time risk assessments of identities and resources. When an identity's risk profile changes or when accessing sensitive resources, permissions are dynamically modified. This dynamic approach maintains high security levels by enforcing strict controls when needed while allowing operational efficiency to prevail during low-risk operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where access decisions are continuously monitored and used to adjust future permission policies. The system learns from access patterns and risk outcomes, refining its permission assignments over time. This feedback loop ensures that strict security policies are applied only when justified by observed risk factors, thereby maintaining security level while avoiding unnecessary restrictions that would harm operational efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12107879B2Determining data risk and managing permissions in computing environments
Publication Date: 2024.10.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12107879B2 patent drawing
  • US12107879B2 patent drawing
  • US12107879B2 patent drawing

AI summary

Methods, systems, apparatuses, and computer-readable storage mediums are described for assigning a security risk score to a resource. In one example, resource access data is collected for a resource. Based at least on the resource access data, a data risk index (DRI) score is generated for the resource. The DRI score comprises a value that is indicative of a level of risk that the resource will be compromised. At least one of the DRI score, an alert based at least on the DRI score, or a policy change for the resource based at least on the generated DRI score is reported to an administrator.