Dynamic Access Control for Heterogeneous Cloud Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In heterogeneous information technology infrastructure environments, existing access control systems face challenges in dynamically adjusting access privileges based on user activity, leading to potential security risks such as theft, tampering, and unauthorized modifications of cloud-based services.
Innovation Solution
An infrastructure security server that authenticates users and monitors their activity over time, dynamically adjusting access privileges using a policy-based automation module and machine learning algorithms to revoke or grant access, ensuring Just Enough Privileges (JEP) and reducing security risks through centralized management across multiple authorization systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control systems use static privilege assignment, then system complexity is reduced, but security reliability deteriorates due to inability to dynamically respond to user activity changes
Solution Approach 1:
The patent implements dynamic access control by continuously monitoring user activity and automatically adjusting privileges in real-time based on observed behavior patterns. The system transitions from static role-based access control to a dynamic model where privileges are granted or revoked based on current user activity, thereby improving security reliability without requiring complete system redesign.
Solution Approach 2:
The system employs machine learning algorithms that enable the access control mechanism to autonomously analyze user behavior patterns and make automated privilege adjustment decisions. This self-service capability reduces the need for complex manual intervention while maintaining high security standards, effectively resolving the contradiction between security reliability and system complexity.
2Reliability
If the system monitors user activity continuously, then security reliability improves through dynamic privilege adjustment, but loss of time increases due to processing overhead
Solution Approach 1:
The system implements periodic monitoring and evaluation of user activity rather than continuous real-time analysis. By sampling user behavior at intervals and using machine learning to predict privilege requirements based on these periodic observations, the system maintains security reliability while significantly reducing processing time overhead compared to continuous monitoring approaches.
3Ease of operation
If the system grants extensive access privileges to users, then ease of operation improves, but object-generated harmful factors increase due to potential unauthorized modifications
Solution Approach 1:
The system dynamically adjusts user privileges based on monitored activity patterns, granting elevated access only when user behavior indicates legitimate need. This dynamic approach allows extensive operational ease when users require full access while automatically restricting privileges to prevent unauthorized modifications, thereby resolving the contradiction between ease of operation and prevention of harmful factors.
4Adaptability or versatility
If the system implements activity-based access control with machine learning, then adaptability improves for heterogeneous environments, but device complexity increases due to multiple authorization systems
Solution Approach 1:
The patent implements a universal machine learning-based access control framework that can operate across heterogeneous cloud-based services and authorization systems. This multi-functional approach allows the same core algorithm to adapt to different environments and service types, improving adaptability while avoiding the need for separate complex authorization mechanisms for each system.
Data Source
AI summary
A method, a system and/or an apparatus of activity based access control in heterogeneous information technology infrastructure is disclosed. The infrastructure security server authenticates that a user is authorized to access a set of heterogeneous cloud-based services using at least one heterogeneous authorization system. The method monitors an activity of the user when accessing any of the set of heterogeneous cloud-based services over a period of time using a processor and a memory. The method dynamically adjusts access privileges to the set of heterogeneous cloud-based services. The adjustment to the access privileges includes a revocation of access to the user to a particular service of the set of heterogeneous cloud-based services and/or dynamically granting of access to the user to the particular service of the set of heterogeneous cloud-based services.


