Dynamic Permission Allocation for Error Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments, existing permission management systems struggle to effectively address errors encountered by applications due to rigid permission sets that prevent appropriate responses to issues such as hardware, software, or security problems, as they restrict access and modifications needed to resolve these errors.

Innovation Solution

A control service dynamically allocates temporary permission changes based on error reports, allowing new or existing members to access and modify affected application nodes, thereby facilitating error response and resolution, including providing temporary permissions that can expire or be updated as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rigid permission sets are assigned to applications, then security and access control are maintained, but the ability to respond to and resolve errors is restricted

Engineering Contradiction:
Improveerror resolution capabilityVSAvoidpermission flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts permission sets based on error conditions. When an error is detected in an application, the system automatically generates and assigns temporary permission sets that enable error resolution actions, then removes these permissions once the error is resolved or the time period expires. This transforms static permission management into a dynamic system that adapts to operational needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes permission parameters by generating modified permission sets that include additional capabilities needed for error resolution. These permission sets have adjustable parameters such as time periods and specific access levels, allowing the system to grant precisely the right amount of access needed for error handling without permanently altering the application's baseline permissions.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If temporary permission changes are dynamically allocated, then error handling capability is improved, but permission management complexity increases

Engineering Contradiction:
Improveerror response efficiencyVSAvoidpermission management system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements self-service automation where error detection automatically triggers permission set generation and assignment without requiring manual administrator intervention. The system monitors applications, detects errors, generates appropriate permission sets, assigns them to applications, and automatically removes them after resolution or time expiration, reducing operational complexity despite the dynamic nature of permissions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback loops to monitor error conditions and automatically adjust permission allocations. When errors are detected, the system responds by granting appropriate permissions, then monitors whether the error is resolved and automatically revokes permissions accordingly. This closed-loop feedback mechanism simplifies management by making the system self-regulating.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10248807B2Enhanced permission allocation in a computing environment
Publication Date: 2019.04.02 CYBER ARK SOFTWARE LTD
  • US10248807B2 patent drawing
  • US10248807B2 patent drawing
  • US10248807B2 patent drawing

AI summary

Examples provided herein enhance the management of permissions based on error reporting in a computing environment. Enhanced permission allocation in a computing environment includes obtaining an error report for an application operating within the computing environment. Based on the error report, permission changes are identified to assist in addressing one or more reported errors. Permission changes can include new, temporary, suspended, updated, modified and/or other permissions for new and/or existing members. Some or all of the identified permission changes can then be allocated to new and/or existing members of the computing environment. Some permission changes may include temporary permissions that provide changed permissions for a limited time period. If an error is not fully addressed, additional evaluation and identification of permission changes can be conducted. Based on this further evaluation, the permission changes can then be updated.