Dynamic Permission Scoring for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current permission management systems are inadequate in ensuring secure and flexible access to systems, as they often rely on static account and password models, which can lead to excessive permissions and vulnerabilities, such as password leakage or unauthorized access due to unsafe environments.

Innovation Solution

A computer-implemented method and system that determines a permission score for users based on identity, state, and environment components, allowing for continuous and variable evaluation of user suitability for specific operations, thereby providing a flexible and secure access control mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static account and password models are used for permission management, then system implementation is simple, but security is insufficient and permission control is rigid

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static permission management into a dynamic system by continuously calculating permission scores based on user identity, device state, and environmental factors. The permission score changes in real-time according to the current situation, allowing the system to adaptively adjust access control decisions rather than relying on fixed permission assignments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces multiple variable parameters (identity component, state component, environment component) that continuously change and influence the permission score. By monitoring and re-evaluating these parameters dynamically, the system can adjust permission levels based on the current context without requiring complex reconfiguration of static access control policies.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive permission verification is performed, then security is improved, but operation efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidoperation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial verification by focusing on the most critical factors (identity, device state, environment) that have the greatest impact on security. Rather than performing exhaustive checks on every possible parameter, the system calculates permission scores based on key components, achieving effective security verification while maintaining operational efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements continuous permission score calculation in the background, updating permission levels dynamically without interrupting user operations. The system continuously monitors identity, state, and environment components and adjusts permissions in real-time, ensuring security verification is ongoing without causing operational delays.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If fixed permission levels are assigned to users, then system management is simple, but adaptability to different situations is poor

Engineering Contradiction:
Improvepermission flexibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal permission scoring framework that can evaluate multiple different factors (identity, device state, environment) through a single unified mechanism. This multi-functional approach allows the system to handle various permission scenarios and contexts using one adaptable scoring system, providing flexibility without requiring separate management mechanisms for each situation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback loops where permission scores are continuously calculated based on current identity, state, and environment information. The system receives feedback from these components and dynamically adjusts permission levels accordingly, enabling automatic adaptation to different situations without manual reconfiguration or complex policy management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11240250B2Permission management
Publication Date: 2022.02.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11240250B2 patent drawing
  • US11240250B2 patent drawing
  • US11240250B2 patent drawing

AI summary

Implementations of the present disclosure relate to methods, systems, and computer program products for permission management. In one implementation, a computer-implemented method is disclosed. In the method, a permission score may be determined for a user in response to an operation requested to a target system by the user. Whether to permit the operation may be determined based on the permission score. Here, the permission score may be determined based on an identity component of the user and at least one of following components of the user: a state component, and an environment component. In other implementations, a computer-implemented system and a computer program product for permission management are disclosed.