Dynamic Access Authorization via Multi-Dimensional Policy Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems in cloud computing environments lack flexibility and protection, making it difficult to manage and customize access effectively, especially in managing secrets and permissions across multiple resources.

Innovation Solution

Implementing a policy-defined access control system that uses configurable and multi-dimensional policies stored as declarative documents, such as YAML, JSON, or XML files, to dynamically manage access permissions, rotate secrets, and enforce zero-trust secret management, allowing for granular control and automation of access decisions based on predefined policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If current access control systems are used in cloud computing environments, then basic access management is provided, but flexibility and protection for managing secrets and permissions are insufficient

Engineering Contradiction:
Improveflexibility in managing accessVSAvoidprotection of secrets
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments access control into multiple dimensions including identity attributes, resource attributes, time-based constraints, and action types. Policies are divided into discrete rules that can be independently configured and evaluated, allowing granular control over secret access while maintaining security through structured permission evaluation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multi-dimensional policy variables including identity dimensions (user, group, role), resource dimensions (type, location, sensitivity), temporal dimensions (time of day, duration), and action dimensions (read, write, rotate). This dimensional expansion enables flexible access management while maintaining strong security controls through comprehensive policy evaluation across all dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Extent of automation

If manual access control management is implemented, then basic permission control is achieved, but automation and dynamic adjustment of access decisions are limited

Engineering Contradiction:
Improveautomation of access decisionsVSAvoidcomplexity of policy configuration
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The system enables self-service access control where policies automatically evaluate access requests against predefined multi-dimensional criteria and execute decisions without manual intervention. The automated policy engine continuously monitors and adjusts access permissions based on changing conditions, reducing operational complexity while maintaining high automation levels.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where access decisions and policy evaluations are continuously monitored and fed back into the system. This enables dynamic policy adjustment based on actual usage patterns, security events, and changing business requirements, allowing the system to automatically optimize access control while simplifying ongoing management.

Inventive Principle:
Principle #23Feedback

3Reliability

If static access permissions are used, then simple permission management is maintained, but dynamic rotation of secrets and adaptive security control are not achieved

Engineering Contradiction:
Improvesecurity of access controlVSAvoidcomplexity of secret management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static access permissions into dynamic secret management through time-based policy variables, rotation schedules, and conditional access rules. Secrets are automatically rotated based on predefined policies considering identity attributes, resource sensitivity, and temporal constraints, enhancing security while managing complexity through automated dynamic adjustment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The multi-dimensional policy framework serves multiple functions simultaneously: access authorization, secret rotation, audit logging, and security policy enforcement. This universal policy engine handles diverse secret management tasks through a single coordinated system, improving security while reducing overall system complexity through functional consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11750609B2Dynamic computing resource access authorization
Publication Date: 2023.09.05 CYBER ARK SOFTWARE LTD
  • US11750609B2 patent drawing
  • US11750609B2 patent drawing
  • US11750609B2 patent drawing

AI summary

Techniques include receiving an access notification identifying a request by an identity for access to an access-protected network resource; identifying a configurable and multi-dimensional policy defining rights of the identity to access the access-protected network resource with respect to the operation of the access-protected network resource; automatically determining, based on the configurable and multi-dimensional policy, whether to perform at least one of: permitting the identity to access the access-protected network resource; denying the identity to access the access-protected network resource; or rotating a secret associated with the identity.