Dynamic Role-Based Security Configuration for Software Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems are inadequate in determining user roles based on software usage, leading to overly rigid security configurations that fail to account for individual user needs and behaviors, resulting in constricted access and potential security risks.

Innovation Solution

A system that uses a processor to detect software applications and usage data on client computing devices, identifies user roles, and applies dynamic security configurations based on expected behaviors, allowing for personalized access control and alerting mechanisms to manage security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rigid security configurations are applied to all users, then security protection is maintained, but user access flexibility and productivity are reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser access flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security configurations that automatically adjust based on detected user roles and behaviors. Instead of rigid fixed configurations, the system dynamically modifies access permissions, software installation rights, and resource allocations according to real-time user role identification and behavioral analysis, resolving the contradiction between security protection and access flexibility

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters such as access levels, permission scopes, and resource restrictions based on detected user roles and behavioral patterns. By continuously monitoring and updating these parameters according to user behavior norms, the system maintains security while enabling flexible access for authorized users

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If uniform security policies are applied to all users, then implementation simplicity is maintained, but adaptability to individual user needs is reduced

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to user needs
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system performs self-service by automatically detecting user roles, analyzing behaviors, and applying appropriate security configurations without manual administrator intervention. The automated role detection and behavioral analysis mechanisms enable the system to adapt to individual user needs while maintaining simple implementation through self-adjustment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes security parameters dynamically based on detected user roles and behaviors. The system automatically adjusts access permissions, software rights, and resource allocations according to real-time role identification, providing adaptability to individual user needs while maintaining implementation simplicity through automated parameter modification

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If automated role detection is implemented, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service automated detection mechanisms that autonomously identify user roles and apply security configurations without external intervention. By using built-in role detection algorithms and behavioral analysis, the system achieves precise access control while managing complexity through self-contained operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs feedback mechanisms where the system continuously monitors user behaviors, compares them against detected roles, and adjusts configurations accordingly. This closed-loop feedback enables precise access control by constantly refining role detection and configuration application based on observed user behavior patterns

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11700264B2Systems and methods for role-based computer security configurations
Publication Date: 2023.07.11 IVANTI INC
  • US11700264B2 patent drawing
  • US11700264B2 patent drawing
  • US11700264B2 patent drawing

AI summary

An apparatus includes a processor operatively coupled to a memory. The processor detects a software application installed on a client computing device, and/or usage data. Detected usage data is associated with a current user of the client computing device and with the software application. The processor identifies a user role for the current user based on the software application and/or usage data. The processor applies a security configuration to the client computing device based on the user role. The security configuration limits access by the current user to a portion of the software application. The processor sends an identifier of the user role to an administrative server for storage in an Active Directory (AD) database.