Dynamic Identity Access Control via Behavioral Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Single-Sign-On (SSO) and Identity and Access Management (IAM) technologies lack effective mechanisms for cleaning up obsolete accounts and managing access privileges dynamically, failing to adapt to changing user behavior and business needs.

Innovation Solution

A system that generates account-specific baselines using historical user behavior data, including machine learning models, to grant or deny access based on real-time user behavior analysis, enabling dynamic access control and remediation, such as deactivating accounts or suspending privileges when anomalies are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional static access control policies are used, then implementation is simple and device complexity is low, but the system cannot adapt to changing user behavior and business needs, reducing adaptability

Engineering Contradiction:
Improveadaptability to user behavior changesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control by continuously monitoring user behavior and automatically adjusting access policies in real-time. The system transitions from static predefined policies to dynamic policies that adapt to changing user patterns, device states, and environmental contexts, resolving the contradiction between adaptability and complexity through automated behavioral analysis

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates continuous feedback loops where user behavior data is collected, analyzed, and used to refine access control decisions. The monitoring component feeds behavioral patterns back to the policy enforcement mechanism, enabling the system to learn and adapt automatically, thus improving adaptability while managing complexity through closed-loop control

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive user behavior monitoring is implemented, then access control precision and security are improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improveuser behavior analysis precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct functional modules: behavior monitoring components, pattern recognition engines, policy decision points, and enforcement mechanisms. This modular segmentation allows precise behavior analysis to be implemented in discrete units, reducing overall system complexity while maintaining high measurement precision through specialized subsystems

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary components such as policy decision points and behavioral pattern buffers that mediate between raw behavior data and final access decisions. These intermediaries process and filter information, reducing the computational burden on the core system while maintaining precise behavior analysis capabilities through layered processing

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dynamic policy adjustment is implemented, then access control responsiveness to anomalies is improved, but response time and processing overhead increase

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidpolicy adjustment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing access policies and behavioral baselines before anomalies occur. Normal behavior patterns are learned and stored in advance, creating a reference framework that enables rapid anomaly detection and response. This preliminary preparation reduces processing time during actual access decisions while maintaining high reliability through pre-validated policies

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements preliminary anti-action by proactively blocking suspicious access attempts before they can cause harm. The monitoring system detects potential anomalies and pre-empts malicious actions by denying access in advance, thus improving reliability by preventing security incidents before they occur while minimizing the time loss through anticipatory security measures

Inventive Principle:
Principle #9Preliminary anti-action

4Measurement precision

If continuous monitoring and analysis of user behavior is performed, then detection of obsolete accounts and anomalies is improved, but computational resource consumption increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidcomputational resource usage
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial monitoring by focusing computational resources on critical access events and high-risk user behaviors rather than uniformly monitoring all activities. The system selectively analyzes behavior patterns that are most indicative of anomalies or obsolete account usage, achieving high detection precision while reducing overall computational resource consumption through targeted rather than exhaustive monitoring

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11381570B2Identity and access management dynamic control and remediation
Publication Date: 2022.07.05 BEIJING DIDI INFINITY TECH & DEV CO LTD
  • US11381570B2 patent drawing
  • US11381570B2 patent drawing
  • US11381570B2 patent drawing

AI summary

Identity and access management may update and remediation may be performed dynamically. Historical user behavior data may be obtained. An account specific baseline based on the historical user behavior data may be generated. An access request may be received from a current user. Current user behavior data associated with a current user may be obtained. The current user behavior data may be compared to the account specific baseline. It may be determined whether the current user behavior data satisfies the account specific baseline. If the current user behavior data satisfies the account specific baseline, an access may be granted to the current user. If the current user behavior data does not satisfy the account specific baseline, access may be denied to the current user.