Dynamic Security Access Level Adjustment via User Behavior Trust Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security access control systems are static and do not adapt to changes in user behavior outside the enterprise environment, failing to dynamically adjust security access levels based on evolving user activities and risks.

Innovation Solution

A computer-implemented method and system that performs a trust evaluation to calculate a trust penalty value for users based on measured attributes, determining and applying a security access level using a predefined trust threshold, which can increase or decrease access restrictions based on observed user behavior, including social, life events, and compliance issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security access control systems are used with manual inputs, then security access levels can be maintained, but the system cannot adapt to changes in user behavior outside the enterprise environment

Engineering Contradiction:
Improveadaptability to user behavior changesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms the static security access control system into a dynamic one by continuously monitoring user behavior attributes (both internal enterprise activities and external social media activities) and automatically adjusting security access levels in real-time based on calculated trust scores, enabling the system to adapt to changing user behaviors without manual intervention

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically evaluating user trustworthiness through behavioral analysis, calculating trust penalty values, and adjusting security access levels without requiring manual security administrator intervention, thereby achieving adaptability while managing complexity through automation

Inventive Principle:
Principle #25Self-service

2Loss of information

If automated changes to security access level are based on internal events only, then implementation is straightforward, but information external to the enterprise is not utilized

Engineering Contradiction:
Improveutilization of external informationVSAvoidinformation processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The security system becomes multi-functional by integrating both internal enterprise event monitoring and external social media activity analysis into a unified trust evaluation framework, allowing the system to comprehensively assess user behavior across multiple information sources while maintaining a single coherent security access control mechanism

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If manual security administrator input is used to modify user access levels, then control is precise, but the process is time-consuming and not scalable

Engineering Contradiction:
Improveaccess control efficiencyVSAvoidsecurity access control precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system implements continuous feedback loops by monitoring user behavior attributes in real-time, calculating trust penalty values based on observed behaviors, and automatically adjusting security access levels accordingly, thereby achieving both high productivity through automation and precise control through systematic evaluation criteria

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10635794B2Determine security access level based on user behavior
Publication Date: 2020.04.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10635794B2 patent drawing
  • US10635794B2 patent drawing
  • US10635794B2 patent drawing

AI summary

Examples of techniques for determining security access based on user behavioral measurements are disclosed. In accordance with aspects of the present disclosure, a computer-implemented method is provided. The method may comprise performing a trust evaluation to calculate a trust penalty value for a user based on a plurality of measured user attributes. The method may further comprise determining, by a processing device, a security access level based on a predefined trust threshold and the trust penalty value for the user. The method may also comprise applying the security access level to the user.