Dynamic Permission Calculator for Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security systems for online digital platforms struggle to effectively control access to restricted data and prevent flow abuses, as malicious actors can bypass authorizations and navigate through vulnerabilities in permission and access control policies.

Innovation Solution

Implementing a dynamic permission calculator and state-based protection system that calculates permissions in real-time for each data request, using a central authorization engine and blockchain protocol to enforce granular and dynamic access controls, thereby preventing unauthorized data access and flow abuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems are used, then system simplicity is maintained, but security against sophisticated attacks deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic permission calculation that adapts to each user's specific navigation path and context. Instead of static access control lists, the system continuously evaluates the user's journey through the application, calculating permissions based on the specific sequence of pages visited and actions taken. This dynamic approach enhances security against sophisticated attacks while maintaining reasonable system complexity through automated evaluation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a permission calculator as an intermediary component between the user and the restricted data. This mediator evaluates navigation flows, authentication states, and contextual factors to determine appropriate access permissions. The intermediary layer adds security without requiring complete system redesign, as it operates as a separate evaluation module that interfaces with existing authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If static permission controls are used, then system complexity is reduced, but vulnerability to flow abuses increases

Engineering Contradiction:
Improvesystem complexityVSAvoidflow abuse vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system transitions from static permission assignments to dynamic permission calculation based on navigation flow. Each user's permission set is recalculated based on their specific path through the application, the pages they have visited, and their authentication state. This dynamic evaluation prevents flow abuses where attackers might exploit specific navigation sequences to bypass authorization, while keeping system complexity manageable through automated flow analysis.

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive risk assessment is implemented, then security detection capability is improved, but processing time increases

Engineering Contradiction:
Improvesecurity detectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary evaluation of navigation flows and authentication states as users move through the application. By continuously assessing the user's journey and maintaining an updated context model, the system prepares permission decisions in advance rather than performing comprehensive risk assessment from scratch for each data access request. This preliminary action reduces processing time while maintaining comprehensive security detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The permission calculator autonomously evaluates navigation flows and determines appropriate permissions without requiring manual security intervention. The system self-assesses risk factors based on predefined security policies and contextual information, automatically making authorization decisions. This self-service capability reduces processing time by eliminating manual review steps while maintaining comprehensive security detection through automated policy evaluation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250165632A1Data security systems for controlling access to restricted data and data processing flows to prevent compromising data and flow abuses
Publication Date: 2025.05.22 PAYPAL INC
  • US20250165632A1 patent drawing
  • US20250165632A1 patent drawing
  • US20250165632A1 patent drawing

AI summary

There are provided systems and methods for data security systems for controlling access to restricted data and data processing flows to prevent comprising data and flow abuses. A service provider, such as an electronic transaction processor for digital transactions, may provide a restricted access controller and dynamic permission calculator to enforce more granular and dynamic permissions of data access and restricted such access to prevent unauthorized access through flow abuse. To prevent malicious actors from circumventing required authorizations to data, the restricted access controller may provide permissions for data based on the particular data portion and elements, which may be determined based on the context of the data when entering the system or when requested by users. Further, permissions may be dynamically calculated when users request data instead of static permissions, which may be based on the flow, such as how the user arrives at the data being requested.