Dynamic Multi-User Access Control for Insider Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access control policies are ineffective in preventing misuse of access privileges by malicious insiders, leading to significant data breaches and intellectual property theft, as they rely solely on trust-based access rights without considering the organizational structure and sensitivity of information.

Innovation Solution

A system that dynamically selects a set of approvers based on the organizational structure, role hierarchy, and sensitivity of information, using a multi-user permission strategy to ensure shared responsibility and real-time approval processes, separating policy from access control mechanisms to mitigate privilege abuse and non-technical threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional trust-based access control policies are used, then ease of operation is improved, but security against malicious insiders deteriorates

Engineering Contradiction:
Improveease of access controlVSAvoidsecurity against insider threats
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the approval process by requiring multiple independent approvers instead of relying on a single trusted user. Access requests are divided into multiple approval stages, where each approver independently evaluates the request based on organizational hierarchy and sensitivity levels, preventing any single malicious insider from compromising security while maintaining operational ease through automated workflow management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts approval requirements based on real-time factors such as information sensitivity classification, user role hierarchy, and organizational structure. The number and identity of required approvers change dynamically according to the specific access request context, enabling the system to provide ease of operation for low-risk accesses while strengthening security for high-sensitive data without manual policy configuration.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple approvers are required for each access request, then security is improved, but productivity deteriorates

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess request processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-classifying information assets according to sensitivity levels and pre-defining approval workflows based on organizational hierarchy before access requests are made. This preliminary structuring allows the system to quickly route requests to appropriate approvers without real-time decision-making delays, maintaining security through multiple approvals while preserving productivity through pre-configured automated workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where approvers can quickly approve or deny requests based on pre-established criteria, and the system learns from approval patterns to optimize future routing. This feedback loop enables the system to identify low-risk requests that can be fast-tracked while maintaining rigorous multi-approver processes for high-risk accesses, balancing security requirements with productivity needs.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10671747B2Multi-user permission strategy to access sensitive information
Publication Date: 2020.06.02 UNIVERSITY OF MEMPHIS RESEARCH FOUNDATION
  • US10671747B2 patent drawing

AI summary

A system and related methods for providing greater security and control over access to classified files and documents and other forms of sensitive information based upon a multi-user, multi-modality permission strategy centering on organizational structure, thereby making authentication strategy unpredictable so to significantly reduce the risk of exploitation. Based on the sensitivity or classification of the information being requested by a user, approvers are selected dynamically based on the work environment, e.g., mobility, use of the computing device seeking access, authentication factors under applicable environmental settings, access policy, and the like.