Dynamic Access Policy Adjustment for System Identities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software systems often face security risks due to over-privileged system identities, which can lead to accidental or intentional compromise of secure information, while reducing privileges aggressively can negatively impact productivity and system experience.

Innovation Solution

A method of dynamically adjusting access privileges of system identities by analyzing access logs to generate a restricted access policy, using a continuous monitoring and access management module that collects and analyzes access logs over a defined time period, performs authorization checks, and updates access policies to follow the principle of least privilege, thereby reducing unnecessary access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access privileges of system identities are reduced to follow the principle of least privilege, then security is improved, but system productivity and user experience may be negatively impacted

Engineering Contradiction:
ImprovesecurityVSAvoidsystem productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access privilege adjustment by continuously monitoring system logs and automatically modifying access policies in real-time. The system transitions from static access control to dynamic adaptation, adjusting privileges based on actual system conditions, threat levels, and user behavior patterns without requiring manual intervention or disrupting productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop by continuously collecting system logs, analyzing access patterns, and automatically adjusting access policies based on the analysis results. This closed-loop control enables the system to learn from actual usage and security events, optimizing the balance between security and productivity automatically.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If access privileges are reduced too aggressively, then security risk is minimized, but system functionality and user experience deteriorate

Engineering Contradiction:
Improvesecurity riskVSAvoidsystem functionality
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically changes access policy parameters based on analyzed system conditions. Instead of applying fixed restrictive rules, the system adjusts privilege levels, access scopes, and policy constraints as parameters that can be modified in real-time based on actual system state, ensuring optimal balance between security and functionality.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary analysis of system logs and access patterns before making policy adjustments. By pre-analyzing usage patterns and identifying legitimate access requirements, the system prepares appropriate access policies in advance that maintain functionality while reducing unnecessary privileges.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If manual access policy management is used to balance security and productivity, then flexibility is maintained, but time consumption and operational complexity increase

Engineering Contradiction:
Improvepolicy flexibilityVSAvoidtime consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs automatic self-service by autonomously analyzing logs, determining appropriate access policies, and implementing adjustments without human intervention. The system serves itself by automatically managing its own access control requirements, eliminating the time-consuming manual policy management process while maintaining flexibility through adaptive decision-making.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical policy management with automated electronic analysis and adjustment systems. Instead of human administrators manually reviewing and adjusting policies, the system uses automated log analysis, pattern recognition, and policy generation algorithms to perform the same function more efficiently and at scale.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11991184B2Dynamically adjusting access policies
Publication Date: 2024.05.21 UBER TECHNOLOGIES INC
  • US11991184B2 patent drawing
  • US11991184B2 patent drawing
  • US11991184B2 patent drawing

AI summary

A method of dynamically adjusting access privileges of system identities. A set of access logs associated with a system are analyzed in order to generate a restricted access policy for an over privileged system identity. An initial access policy of the system identity is replaced with the restricted access policy and a continuous monitoring and access management (CMAM) service is initiated. Access logs are collected for a monitoring time window and an access denied error can be extracted from the access logs. The access denied error can be compared to an ignore list and/or the access denied error can be added to the ignore list. Authorization checks can be performed to determine if the action associated with the access denied error is authorized. If the action is authorized, the access policy is adjusted to allow for performance of the action.