Dynamic Context-Based Access Control Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control management systems are error-prone and inefficient due to their limitations in performance and security, particularly in customizing access permissions and enforcing context-based access control in cloud environments.

Innovation Solution

A dynamic context-based access control mechanism that collects multiple dimensions of user and device contexts, including authentication, presence, location, and proximity, to evaluate and enforce access policies across single or distributed computing devices, enabling secure and customizable access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing access control management systems use traditional operating system abstractions for user identity and permission, then the system structure is simple and easy to implement, but the system lacks customization features and intelligence, leading to errors and inefficiency

Engineering Contradiction:
Improvecustomization featuresVSAvoidsystem structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms static access control policies into dynamic context-aware policies that automatically adapt to changing conditions. The system collects real-time context data (user behavior, device state, environmental factors) and dynamically adjusts access decisions, making the system both customizable and intelligent while maintaining manageable complexity through automated context processing.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of access control from fixed user/permission tuples to multi-dimensional context parameters including user identity, device characteristics, location, time, and behavioral patterns. This parameter expansion enables fine-grained customization without proportionally increasing system complexity, as the framework automatically processes these additional dimensions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If existing access control systems enforce permissions based on static user identities, then the enforcement point is clear and simple, but the system lacks intelligence and cannot adapt to dynamic contexts, reducing security and performance

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary context collection and analysis before making access decisions. By gathering relevant context data (user credentials, device state, environmental conditions) and evaluating it against access policies in advance, the system enhances security through comprehensive verification while managing complexity through a structured pre-evaluation framework that prevents last-minute decision-making.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback loops where access decisions are continuously refined based on observed outcomes and changing contexts. The system monitors access patterns, evaluates policy effectiveness, and adjusts context collection and decision-making processes accordingly, improving security through adaptive learning while maintaining manageable complexity through iterative refinement rather than complex upfront design.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If cloud-based services extend legacy access management systems, then the system coverage is expanded, but the inability to specify context and control access enforcement points reduces security and user confidence

Engineering Contradiction:
Improvecontext specification capabilityVSAvoidaccess control configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal context-aware access control framework that can be applied across diverse cloud services and platforms. The system provides multi-functional capabilities including context collection, policy evaluation, and access enforcement that work consistently across different service types, enabling context specification without requiring service-specific customizations that would complicate operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary context evaluation layer between legacy access management systems and cloud services. This mediator translates traditional user/permission models into context-aware decisions, adding intelligence and security while maintaining compatibility with existing systems, thereby improving ease of operation through seamless integration rather than requiring complete system replacement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10484378B2Mechanism for facilitating dynamic context-based access control of resources
Publication Date: 2019.11.19 INTEL CORP
  • US10484378B2 patent drawing
  • US10484378B2 patent drawing
  • US10484378B2 patent drawing

AI summary

A mechanism is described for facilitating context-based access control of resources for according to one embodiment. A method of embodiments, as described herein, includes receiving a first request to access a resource of a plurality of resources. The first request may be associated with one or more contexts corresponding to a user placing the first request at a computing device. The method may further include evaluating the one or more contexts. The evaluation of the one or more contexts may include matching the one or more contexts with one or more access policies associated with the requested resource. The method may further include accepting the first request if the one or more contexts satisfy at least one of the access policies.