Dynamic Access Control via Relationship-Based Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems for virtual private networks (VPNs) lack effective methods to dynamically assess user relationships and apply tailored security measures based on these relationships, leading to potential security vulnerabilities when multiple individuals share user identifications.
Innovation Solution
A method and system that utilize metadata from prior access histories and physical proximity confirmations to identify user relationships, querying a database to determine relationship data, which is then input into a rules engine to select and apply appropriate security measures, such as challenge questions, security credentials, or alerts, based on the identified relationships.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional access control systems are used with shared user identifications, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The system segments the access control process into multiple evaluation stages: initial authentication, relationship data retrieval, risk assessment, and dynamic security measure application. This segmentation allows the system to maintain ease of operation for legitimate users while implementing layered security checks that address reliability concerns without creating a single point of failure.
Solution Approach 2:
The system dynamically adjusts security measures based on real-time relationship data and risk assessment. Instead of applying static security policies to all users, the system adapts security requirements according to the specific relationships and risks identified through metadata analysis, thereby maintaining operational ease for low-risk scenarios while enhancing security for high-risk cases.
2Reliability
If dynamic relationship assessment and targeted security measures are implemented, then security reliability is improved, but device complexity increases
Solution Approach 1:
The system performs preliminary actions by pre-establishing relationship databases and pre-defining security measure templates before actual access requests occur. Relationship data is retrieved and assessed in advance, and appropriate security measures are pre-selected based on relationship types, reducing the complexity of real-time decision-making while maintaining high security reliability.
Solution Approach 2:
The system introduces an intermediary rules engine that mediates between the access request and the security enforcement mechanisms. This intermediary component automatically evaluates relationship data, assesses risks, and selects appropriate security measures, thereby reducing the apparent complexity for end users while implementing sophisticated security logic in the background.
3Reliability
If security measures are applied to all access requests, then security reliability is improved, but productivity decreases
Solution Approach 1:
The system applies the principle of local quality by tailoring security measures to specific access requests based on relationship data and risk assessment. Instead of uniformly applying security measures to all users, the system applies targeted security controls only where relationship analysis indicates potential risks, thereby maintaining security reliability while minimizing productivity impact for low-risk access scenarios.
Solution Approach 2:
The system implements partial action by applying security measures selectively rather than universally. Based on the relationship assessment and risk level, the system applies only the necessary degree of security verification - from minimal checks for low-risk relationships to more stringent measures for high-risk scenarios - thereby optimizing the balance between security reliability and operational productivity.
Data Source
AI summary
An embodiment of the invention provides a method for controlling access to a system, wherein a request to access the system and metadata of the request are received from a user, the request including a user identification. The metadata includes: information obtained from a history of prior accesses to an application access system, information obtained from a history of prior accesses to a wireless authentication system, and/or confirmation of the user identification by an entity physically proximate to the user. A database is queried with the user identification and the metadata to identify relationship data. The relationship data indicates the relationship between the individual assigned the user identification and an entity owning the system, an entity leasing the system, and/or an entity operating the system. The relationship data is input into a rules engine; and, security measure(s) are selected with the rules engine based on the relationship data.


