Dynamic Access Control Rules for Emergency Override Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing context-sensitive access control systems burden system administrators with manual access requests during emergencies, delaying technical problem resolution and affecting computing environment performance.

Innovation Solution

A system that dynamically updates access rulesets based on user data properties and machine learning, identifying common characteristics among users granted overrides to automatically grant access, reducing the need for manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access requests are processed during emergencies, then access control security is maintained, but system performance deteriorates and administrative delays increase

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service access control by automatically analyzing user data, identifying common characteristics among users who need access during emergencies, and dynamically generating access rules without requiring manual administrator intervention. This maintains security through automated rule-based control while eliminating administrative bottlenecks that degrade system performance during emergencies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of user data and emergency access patterns before emergencies occur, building a foundation of user characteristics and access requirements. During emergencies, this pre-analyzed data enables rapid automatic rule generation, maintaining security while avoiding the performance degradation caused by real-time manual processing.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual access requests are processed during emergencies, then individual access decisions are controlled, but time consumption increases

Engineering Contradiction:
Improveaccess decision controlVSAvoidadministrative delays
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The access control system performs self-service by automatically generating rules based on analyzed user characteristics, eliminating the time-consuming manual review process while maintaining controlled access decisions. The system autonomously identifies users with common characteristics and applies consistent rules, preserving operational control without administrative time delays.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes access control parameters by automatically adjusting rules based on emergency contexts and user data analysis. This enables rapid adaptation to different emergency scenarios without manual parameter adjustment, reducing time losses while maintaining controlled access decisions through automated parameter optimization.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If static access rules are used, then system simplicity is maintained, but adaptability to different contexts deteriorates

Engineering Contradiction:
Improveaccess ruleset structureVSAvoidcontext sensitivity
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static access rules to dynamic rule generation by continuously analyzing user data and emergency contexts. Rules are automatically adjusted based on identified user characteristics and situational requirements, enabling context sensitivity while maintaining relative system simplicity through automated rule management rather than complex manual configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The access control system provides self-service adaptability by automatically analyzing user data patterns and generating context-specific rules without requiring complex predefined configurations. This enables the system to adapt to different emergency contexts while maintaining simplicity through automated rule generation rather than manual rule creation for each scenario.

Inventive Principle:
Principle #25Self-service

4Productivity

If automated access rules are generated without analysis, then processing speed increases, but rule accuracy deteriorates

Engineering Contradiction:
Improveruleset update speedVSAvoidaccess criteria accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary analysis of user data and access patterns before generating automated rules, ensuring accuracy is established before rapid rule deployment. This pre-analysis phase identifies meaningful user characteristics and relationships, enabling subsequent fast rule generation that maintains high accuracy while achieving rapid processing speeds during emergencies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms that continuously evaluate the effectiveness of generated access rules and refine future rule generation based on outcomes. This feedback loop ensures that automated rules maintain high accuracy by learning from past performance, while preserving fast processing speeds through optimized rule generation algorithms informed by accumulated knowledge.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12452304B2Dynamically changing access rules for context-sensitive access control
Publication Date: 2025.10.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12452304B2 patent drawing
  • US12452304B2 patent drawing
  • US12452304B2 patent drawing

AI summary

A system, method and computer program product obtains user data relating to a plurality of system users, who have previously been granted access to a resource in a context without complying with a ruleset defining criteria for automatically accessing the resource in the context. A combination of two or more user data properties having common values in user data of a subset of two or more of the plurality of system users is identified. A determination of whether the number of system users in the subset exceeds a predetermined threshold is made. If the number of system users in the subset exceeds the predetermined threshold, the ruleset is updated to include criteria based on the identified combination of two or more user data properties.