Dynamic Access Control via Relationship-Based Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for virtual private networks (VPNs) lack effective methods to dynamically assess user relationships and apply tailored security measures based on these relationships, leading to potential security vulnerabilities when multiple individuals share user identifications.

Innovation Solution

A method and system that utilize metadata from prior access histories and physical proximity confirmations to identify user relationships, querying a database to determine relationship data, which is then input into a rules engine to select and apply appropriate security measures, such as challenge questions, security credentials, or alerts, based on the identified relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control systems are used with shared user identifications, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the access control process into multiple evaluation stages: initial authentication, relationship data retrieval, risk assessment, and dynamic security measure application. This segmentation allows the system to maintain ease of operation for legitimate users while implementing layered security checks that address reliability concerns without creating a single point of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts security measures based on real-time relationship data and risk assessment. Instead of applying static security policies to all users, the system adapts security requirements according to the specific relationships and risks identified through metadata analysis, thereby maintaining operational ease for low-risk scenarios while enhancing security for high-risk cases.

Inventive Principle:
Principle #15Dynamics

2Reliability

If dynamic relationship assessment and targeted security measures are implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing relationship databases and pre-defining security measure templates before actual access requests occur. Relationship data is retrieved and assessed in advance, and appropriate security measures are pre-selected based on relationship types, reducing the complexity of real-time decision-making while maintaining high security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary rules engine that mediates between the access request and the security enforcement mechanisms. This intermediary component automatically evaluates relationship data, assesses risks, and selects appropriate security measures, thereby reducing the apparent complexity for end users while implementing sophisticated security logic in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security measures are applied to all access requests, then security reliability is improved, but productivity decreases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies the principle of local quality by tailoring security measures to specific access requests based on relationship data and risk assessment. Instead of uniformly applying security measures to all users, the system applies targeted security controls only where relationship analysis indicates potential risks, thereby maintaining security reliability while minimizing productivity impact for low-risk access scenarios.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial action by applying security measures selectively rather than universally. Based on the relationship assessment and risk level, the system applies only the necessary degree of security verification - from minimal checks for low-risk relationships to more stringent measures for high-risk scenarios - thereby optimizing the balance between security reliability and operational productivity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8875229B2Quantifying risk based on relationships and applying protections based on business rules
Publication Date: 2014.10.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8875229B2 patent drawing
  • US8875229B2 patent drawing
  • US8875229B2 patent drawing

AI summary

An embodiment of the invention provides a method for controlling access to a system, wherein a request to access the system and metadata of the request are received from a user, the request including a user identification. The metadata includes: information obtained from a history of prior accesses to an application access system, information obtained from a history of prior accesses to a wireless authentication system, and/or confirmation of the user identification by an entity physically proximate to the user. A database is queried with the user identification and the metadata to identify relationship data. The relationship data indicates the relationship between the individual assigned the user identification and an entity owning the system, an entity leasing the system, and/or an entity operating the system. The relationship data is input into a rules engine; and, security measure(s) are selected with the rules engine based on the relationship data.