Dynamic Access Control for Heterogeneous Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous information technology infrastructure environments, existing access control systems face challenges in dynamically adjusting access privileges based on user activity, leading to potential security risks such as theft, tampering, and unauthorized modifications of cloud-based services.

Innovation Solution

An infrastructure security server that authenticates users and monitors their activity over time, dynamically adjusting access privileges using a policy-based automation module and machine learning algorithms to revoke or grant access, ensuring Just Enough Privileges (JEP) and reducing security risks through centralized management across multiple authorization systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control systems use static privilege assignment, then system complexity is reduced, but security reliability deteriorates due to inability to dynamically respond to user activity changes

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control by continuously monitoring user activity and automatically adjusting privileges in real-time based on observed behavior patterns. The system transitions from static role-based access control to a dynamic model where privileges are granted or revoked based on current user activity, thereby improving security reliability without requiring complete system redesign.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs machine learning algorithms that enable the access control mechanism to autonomously analyze user behavior patterns and make automated privilege adjustment decisions. This self-service capability reduces the need for complex manual intervention while maintaining high security standards, effectively resolving the contradiction between security reliability and system complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If the system monitors user activity continuously, then security reliability improves through dynamic privilege adjustment, but loss of time increases due to processing overhead

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic monitoring and evaluation of user activity rather than continuous real-time analysis. By sampling user behavior at intervals and using machine learning to predict privilege requirements based on these periodic observations, the system maintains security reliability while significantly reducing processing time overhead compared to continuous monitoring approaches.

Inventive Principle:
Principle #19Periodic action

3Ease of operation

If the system grants extensive access privileges to users, then ease of operation improves, but object-generated harmful factors increase due to potential unauthorized modifications

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized modifications
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system dynamically adjusts user privileges based on monitored activity patterns, granting elevated access only when user behavior indicates legitimate need. This dynamic approach allows extensive operational ease when users require full access while automatically restricting privileges to prevent unauthorized modifications, thereby resolving the contradiction between ease of operation and prevention of harmful factors.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If the system implements activity-based access control with machine learning, then adaptability improves for heterogeneous environments, but device complexity increases due to multiple authorization systems

Engineering Contradiction:
Improveadaptability to heterogeneous environmentsVSAvoidcomplexity of authorization systems
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal machine learning-based access control framework that can operate across heterogeneous cloud-based services and authorization systems. This multi-functional approach allows the same core algorithm to adapt to different environments and service types, improving adaptability while avoiding the need for separate complex authorization mechanisms for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10454934B2Activity based access control in heterogeneous environments
Publication Date: 2019.10.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10454934B2 patent drawing
  • US10454934B2 patent drawing
  • US10454934B2 patent drawing

AI summary

A method, a system and/or an apparatus of activity based access control in heterogeneous information technology infrastructure is disclosed. The infrastructure security server authenticates that a user is authorized to access a set of heterogeneous cloud-based services using at least one heterogeneous authorization system. The method monitors an activity of the user when accessing any of the set of heterogeneous cloud-based services over a period of time using a processor and a memory. The method dynamically adjusts access privileges to the set of heterogeneous cloud-based services. The adjustment to the access privileges includes a revocation of access to the user to a particular service of the set of heterogeneous cloud-based services and/or dynamically granting of access to the user to the particular service of the set of heterogeneous cloud-based services.