Dynamic Permission Grouping for Accurate Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing user permissions in large, complex organizations are inefficient, inaccurate, and impractical, often leading to overly broad access privileges and unnecessary security exposure, while removing these privileges can result in unintended loss of access to necessary data or services.

Innovation Solution

A method and system for dynamically refining access rules by collecting initial permissions, generating user groups based on actual access events, and updating permissions to ensure only authorized users have access to specific data elements or services, using a system that includes a permissions input unit, access event tracker, initial and modified user group generators, and modified permissions generator to manage permissions dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing permission management systems are used in large organizations, then permissions can be assigned to users, but the systems become inefficient, inaccurate, and impractical, leading to overly broad access privileges

Engineering Contradiction:
Improveaccess control accuracyVSAvoidpermission management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates user groups and refines permissions based on actual access events without requiring manual intervention. The permission management system self-adjusts by analyzing access patterns and automatically creating modified user groups, eliminating the need for complex manual permission configurations while improving accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors actual access events and uses this feedback to refine permissions. Access events are collected, analyzed, and used to generate modified user groups that better reflect actual needs, creating a closed-loop system that improves accuracy over time without increasing complexity.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If permissions are broadly assigned to ensure access, then users can access necessary data, but security exposure increases due to overly broad privileges

Engineering Contradiction:
Improveuser access capabilityVSAvoidsecurity exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts permissions based on actual access patterns rather than using static, predetermined permission sets. User groups are continuously refined and modified based on real access events, allowing the system to maintain ease of operation while reducing security exposure by eliminating unnecessary broad privileges.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system proactively creates user groups and assigns permissions before actual access needs arise. By analyzing historical access events and predicting future needs, the system pre-configures appropriate permissions that balance ease of operation with security, preventing both over-restriction and excessive broadness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual permission review processes are implemented, then access control accuracy can improve, but the process becomes time-consuming and resource-intensive

Engineering Contradiction:
Improveaccess control precisionVSAvoidpermission management time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically performs the permission review and refinement process without human intervention. It self-analyzes access events, generates user groups, and updates permissions autonomously, achieving high measurement precision while eliminating the time loss associated with manual review processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors, analyzes, and updates permissions without interruption. The useful action of permission refinement is performed continuously based on ongoing access events, eliminating the discontinuous, periodic nature of manual reviews and both improving precision and reducing time loss.

Inventive Principle:
Principle #20Continuity of useful action

4Object-affected harmful factors

If permissions are removed to reduce security exposure, then security improves, but unintended loss of access to necessary data occurs

Engineering Contradiction:
Improvesecurity exposureVSAvoidaccess availability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system uses feedback from actual access events to guide permission modifications. By analyzing what users actually need to access, the system can remove excessive privileges while maintaining necessary access, ensuring that security improvements do not result in unintended loss of access to required data.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies partial permission modifications rather than blanket removals. By analyzing specific access patterns, it makes targeted adjustments to permissions, removing only the excessive portions while preserving necessary access rights, thus balancing security with access availability.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12526284B2Method and system for automated permissions management
Publication Date: 2026.01.13 VARONIS SYSTEMS INC
  • US12526284B2 patent drawing
  • US12526284B2 patent drawing
  • US12526284B2 patent drawing

AI summary

A system and method for dynamically refining access rules for governing control of access by multiple users to data elements or services (DEOSs) stored in or accessed through at least one access controllable network element (ACONE), including collecting initial permissions to the DEOSs, receiving and periodically updating notifications of actual access events of the multiple users to the DEOSs, generating initial user groups for the multiple users, generating for each of the initial user groups, based at least partially on the notifications of actual access events, a list of users who have accessed at least one of the DEOSs, based at least partially on the lists, generating modified user groups, based at least partially on the modified user groups, generating modified permissions, and based on the modified permissions, updating the initial permissions to the DEOSs, thereby enabling only the users in particular modified user groups to access particular DEOSs.