Dynamic Access Permission Management in Distributed Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to managing access permissions in distributed computing environments are inadequate, particularly in ensuring secure and efficient provisioning of access to sensitive information and resources, as they often result in overly permissive policies and inefficient resource utilization.

Innovation Solution

An access management system that monitors API calls, adjusts access policies based on usage thresholds, revokes unnecessary access, and allows for automatic reinstatement of access when needed, utilizing a combination of access management servers, request logs, and user interfaces to manage permissions dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If access permissions are broadly granted to enable efficient resource access in distributed computing environments, then productivity and ease of operation improve, but security and reliability deteriorate due to overly permissive policies

Engineering Contradiction:
Improveresource access efficiencyVSAvoidaccess permission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic access permission management by continuously monitoring API call patterns and automatically adjusting permission levels based on observed usage. The system transitions from static, overly permissive policies to dynamic policies that adapt in real-time, granting broad access when needed for productivity while automatically restricting access when patterns indicate security risks, thus resolving the contradiction between productivity and security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where API call data is collected, analyzed, and used to automatically adjust access permissions. The monitoring component continuously observes usage patterns and feeds this information back to the permission management system, which then modifies permissions accordingly. This closed-loop feedback mechanism enables the system to maintain security while allowing efficient resource access, as permissions are continuously optimized based on actual usage rather than static initial configurations.

Inventive Principle:
Principle #23Feedback

2Reliability

If access monitoring and permission adjustment mechanisms are implemented to improve security, then reliability improves, but device complexity and administrative burden increase

Engineering Contradiction:
Improveaccess permission securityVSAvoidaccess management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the access management system autonomously monitors API calls, analyzes usage patterns, and adjusts permissions without requiring continuous human intervention. The system serves itself by automatically detecting security risks and implementing permission changes, thereby improving reliability while minimizing the increase in administrative complexity. The automation reduces the need for manual security management, offsetting the initial system complexity with operational simplicity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system manages complexity by focusing on changing key parameters (permission levels) rather than redesigning the entire access management architecture. It monitors specific API call parameters and adjusts permission parameters based on observed patterns. This targeted parameter-based approach improves security through precise control while avoiding the complexity of comprehensive system redesign, as it builds upon existing access management frameworks with layered, parameter-specific enhancements.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If continuous monitoring of API calls is performed to dynamically adjust permissions, then access control precision improves, but use of energy and computational resources increases

Engineering Contradiction:
Improveusage pattern detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial monitoring action by focusing computational resources on monitoring only the most critical API calls and parameters rather than continuously analyzing every single call. The system identifies and prioritizes monitoring of high-risk or high-value API endpoints, applying measurement precision selectively where it matters most. This partial action approach maintains accurate usage pattern detection for critical operations while reducing overall computational resource consumption by not uniformly monitoring all API calls with the same intensity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9825956B2Systems and methods for access permission revocation and reinstatement
Publication Date: 2017.11.21 NETFLIX INC
  • US9825956B2 patent drawing
  • US9825956B2 patent drawing
  • US9825956B2 patent drawing

AI summary

Provided herein are systems and methods of managing permissions for applications deployed in a distributed computing infrastructure. An exemplary system includes an access management server having a processing device, a distributed computing infrastructure in communication with the management server having a plurality of resource instances and a request log, an administration system having a security application executing thereon. The security application has access policies associated with each of a plurality of applications. The processing device of the management server: receives application request information from the request log describing requests made by a first application being monitored by the access management server. The management server receives an access policy describing a set of accessible APIs associated with the first application from the security application and determines that access to a first API of the set should be removed, and modifies the access policy to remove access to the first API.