Dynamic Access Control System for Data Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing user access to data resources apply static permissions, making it difficult for administrators to manage and change permissions dynamically, leading to unnecessary access being granted to resources whether needed or not.

Innovation Solution

A system that displays authorized resources to users, allows them to request access, confirms the request, and applies corresponding security permissions based on user confirmation, with options for time-limited access and automatic revocation, along with features for archiving and real-time data hold management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static permissions are applied to grant users access to all approved resources concurrently, then users can access authorized resources without repeated permission changes, but administrators cannot dynamically manage and change permissions throughout the day for all users

Engineering Contradiction:
ImproveUser access convenienceVSAvoidPermission management flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms static permissions into dynamic permissions by implementing a request-based access control system. Instead of pre-defining all permissions statically, the system dynamically evaluates access requests against stored policies and current resource states, allowing permissions to adapt in real-time based on user needs and organizational rules.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If static permissions grant access to all approved resources concurrently, then users have broad access to resources, but this grants unnecessary access to resources whether needed or not

Engineering Contradiction:
ImproveResource access scopeVSAvoidSecurity risk from unnecessary access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements partial action by granting permissions on-demand rather than all-at-once. Access is granted selectively for specific resources based on actual user requests and needs, rather than providing blanket access to all approved resources concurrently. This reduces security risks while maintaining necessary access flexibility.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If administrators manually manage permissions for all users throughout the day, then permission changes can be made dynamically, but this creates significant administrative burden

Engineering Contradiction:
ImprovePermission change capabilityVSAvoidAdministrative management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing users to autonomously request access to resources based on their needs. Instead of requiring administrators to manually evaluate and grant each permission request, users can initiate access requests themselves, and the system automatically evaluates them against stored policies, significantly reducing administrative burden while maintaining control.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If time-limited access and automatic revocation are implemented, then security is enhanced by limiting access duration, but this requires additional system complexity for tracking and managing access timeframes

Engineering Contradiction:
ImproveSecurity risk from prolonged accessVSAvoidAccess tracking system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements periodic action by automatically reviewing and revoking permissions after predetermined timeframes. Instead of requiring continuous manual monitoring, the system periodically evaluates active permissions and automatically revokes those that exceed their authorized duration or are no longer needed, enhancing security while maintaining manageable system complexity.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20220272103A1Adaptive access control technology
Publication Date: 2022.08.25 DURYEA DAVID J
  • US20220272103A1 patent drawing
  • US20220272103A1 patent drawing
  • US20220272103A1 patent drawing

AI summary

A method and system for processing an access request are provided. The method includes displaying authorized resources of a user, receiving an access request for a resource based on a user selection, prompting the user to confirm the requested access for the resource, receiving a confirmation from the user for the requested access for the resource, and applying a corresponding security permission based on the received confirmation.