Dynamic Access Control System for Shared Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control methods require significant manual effort and are prone to errors, leading to potential vulnerabilities and insider threats as they struggle to dynamically manage evolving access needs in large organizations.

Innovation Solution

A dynamic access control system that assesses user, resource, and environment risk levels using machine learning techniques to determine access permissions on a case-by-case basis, reducing the reliance on static policies and minimizing manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access control policies are used to manage employee access needs, then access control can be implemented, but significant time and effort are required for monitoring and updating policies

Engineering Contradiction:
Improveaccess control securityVSAvoidtime for monitoring and updating policies
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service access control where the access control server automatically monitors employee access needs, evaluates risk levels, and updates policies without requiring manual intervention from security personnel. The system serves itself by continuously gathering data from multiple sources, calculating risk scores, and dynamically adjusting access permissions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of policy updates with an automated electronic system that uses machine learning algorithms and risk evaluation models to dynamically adjust access control policies. This substitution eliminates the need for security personnel to manually monitor and update policies while maintaining or improving security reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If manual updates to access-control policies are performed, then access needs can be accommodated, but errors are introduced by security personnel

Engineering Contradiction:
Improveability to accommodate access needsVSAvoidsecurity policy accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously collects feedback from multiple data sources including employee roles, resource sensitivity levels, and observed access patterns. This feedback is processed through risk evaluation algorithms that automatically adjust access control policies, eliminating human error while maintaining adaptability to changing access needs.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent dynamically changes access control parameters based on calculated risk levels. Instead of manual policy updates, the system automatically adjusts access permissions by changing parameters such as allowed resources, time restrictions, and authentication requirements based on real-time risk assessment.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If conventional access control methods are used, then basic security can be maintained, but the organization remains vulnerable to insider attacks and data theft

Engineering Contradiction:
Improvebasic security maintenanceVSAvoidvulnerability to insider attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system transitions from static access control policies to dynamic policies that continuously adapt based on real-time risk assessment. Access permissions are not fixed but change dynamically based on employee behavior patterns, resource sensitivity, and environmental factors, making the system more resilient to insider threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary risk assessment and evaluation before granting access to sensitive resources. By calculating risk levels in advance based on employee profiles, resource sensitivity, and access patterns, the system can prevent potential insider attacks before they occur rather than reacting after incidents happen.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9807094B1Systems and methods for dynamic access control over shared resources
Publication Date: 2017.10.31 GEN DIGITAL INC
  • US9807094B1 patent drawing
  • US9807094B1 patent drawing
  • US9807094B1 patent drawing

AI summary

The disclosed computer-implemented method for dynamic access control over shared resources may include (1) detecting an attempt by a user to access a resource via a computing environment, (2) identifying a risk level of the user attempting to access the resource, (3) identifying a sensitivity level of the resource, (4) identifying a risk level of the computing environment through which the user is attempting to access the resource, (5) determining an overall risk level for the attempt to access the resource based at least in part on (A) the risk level of the user, (B) the sensitivity level of the resource, and (C) the risk level of the computing environment, and then (6) determining, based at least in part on the overall risk level, whether to grant the user access to the resource via the computing environment. Various other methods, systems, and computer-readable media are also disclosed.