Dynamic Security Friction for Atypical Access Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems fail to effectively manage access rights, leading to increased security risks as users accumulate unnecessary access permissions, which can be exploited by malicious entities, especially when access is not regularly reviewed or revoked.

Innovation Solution

Implementing a system that introduces security friction for atypical resource access requests by varying the level of authentication methods based on the degree of atypicality, using factors like elapsed time between requests, to deter unauthorized access and enhance detection of malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If access rights are granted to individuals for job functions, then productivity and ease of operation are improved, but security risks increase as users accumulate unnecessary access permissions over time

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts access control based on current context rather than using static permissions. It evaluates the user's current job responsibilities, location, time, and device to determine appropriate access rights in real-time, allowing the same user to have different effective permissions at different times without requiring manual re-provisioning

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors and evaluates access requests against current organizational data, user profiles, and security policies. It provides real-time feedback by granting or denying access based on whether the request aligns with the user's current job functions and organizational security requirements

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If IT personnel re-provision access rights periodically, then security risks are reduced, but productivity and ease of operation deteriorate due to access restrictions and re-provisioning overhead

Engineering Contradiction:
Improvesecurity riskVSAvoidaccess efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system automatically manages access rights without requiring manual IT intervention. It self-adjusts permissions based on organizational changes, project completions, and role transitions by continuously evaluating access requests against current user profiles and job responsibilities, eliminating the need for periodic re-provisioning cycles

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If strict access control is implemented for sensitive resources, then security risk is reduced, but ease of operation deteriorates due to additional authentication requirements

Engineering Contradiction:
Improvesecurity riskVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements dynamic authentication that adapts to the specific context of each access request. It evaluates factors such as user location, time of day, device security state, and requested resource sensitivity to determine the appropriate level of authentication required, applying stricter controls only when necessary rather than uniformly to all access attempts

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11025638B2System and method providing security friction for atypical resource access requests
Publication Date: 2021.06.01 FORCEPOINT LLC
  • US11025638B2 patent drawing
  • US11025638B2 patent drawing
  • US11025638B2 patent drawing

AI summary

A method, system and computer-usable medium for providing security friction to a request for access to a resource based on whether the access request is atypical. In certain embodiments, a request to access the resource based on a user identity is received electronically. The system determines whether the request is typical or atypical. If the request is typical, access to the requested resource is granted. However, if the request is atypical, access to the requested resource is only allowed if the correct information is provided in response to one or more access control methods that provide an amount of security friction that would otherwise not have been asserted if the resource request was typical. In certain embodiments, an elapsed time between access requests based on the user identity is used to determine whether the access request is atypical.