Dynamic Access Privilege Adjustment for Separated Employees

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems fail to effectively manage user access to organizational resources during changes in employment status, leading to potential security risks as users may engage in high-risk activities before their departure, such as data exposure or malicious actions.

Innovation Solution

A computer security system dynamically modifies user access privileges based on anticipated changes in employment status, allowing low-risk operations before the effective date of the change and restricting high-risk activities, and further revoking access upon the change becoming effective, using data records and keyword/taxonomy analysis to determine sensitive data and filter communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user is allowed to perform all operations during normal employment, then productivity and ease of operation are maintained, but security risk increases when employment status changes

Engineering Contradiction:
ImprovesecurityVSAvoidaccess privilege
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts user access privileges based on employment status changes. When a user's employment status changes (e.g., termination, resignation), the system automatically modifies their access rights in real-time, transitioning from static access control to dynamic adaptation. This resolves the contradiction by making security flexible without permanently restricting operational ease during normal employment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of access privilege levels based on employment status events. By detecting employment status changes and automatically adjusting access parameters (from full access to restricted access), the system maintains high productivity during normal operations while ensuring security when employment status changes occur.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If access privileges are restricted before employment status change, then security risk is reduced, but productivity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by detecting employment status changes and automatically adjusting access privileges before the user can engage in high-risk activities. By proactively monitoring employment status events and pre-restricting access accordingly, the system prevents security incidents without requiring manual intervention or affecting normal operations until the status change occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring employment status changes and automatically responding by adjusting access privileges. This closed-loop feedback ensures security is maintained without unnecessarily restricting productivity, as restrictions are applied only when employment status changes are detected through the feedback channel.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual monitoring of user activities is implemented, then security risk is reduced, but device complexity and loss of time increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically detecting employment status changes and adjusting user access privileges without requiring manual security administration. The system monitors its own security-relevant events (employment status changes) and autonomously responds by modifying access controls, eliminating the need for complex manual monitoring processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary mechanism that automatically translates employment status changes into access privilege adjustments. This intermediary layer (the automated access control system) mediates between HR systems and security systems, reducing the complexity of manual monitoring while maintaining high security standards through automated event-driven responses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11979408B2Systems and methods for controlling user access to computer resources of an organization by separated employees
Publication Date: 2024.05.07 SAUDI ARABIAN OIL CO
  • US11979408B2 patent drawing
  • US11979408B2 patent drawing
  • US11979408B2 patent drawing

AI summary

In an example method, a system obtains a data record indicating an anticipated change in an employment status of a user at an organization, including a data field indicating an effective time of the anticipated change. At a first time prior to the effective time, the system modifies an access privilege of the user with respect to computer resources of the organization, including (i) allowing the user to perform first operations using the computer resources between the first time and a second time subsequent to the first time, and (ii) preventing the user from performing second operations using the computer resources starting at the first time. At the second time, the system further modifies the access privilege of the user, including preventing the user from performing the operations using the computer resources starting at the second time.