Dynamic Security Grading for Online Service Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses providing online services face challenges in ensuring the security of users' computer systems, as they lack direct control over users' security measures, and existing solutions are not effective in non-corporate settings where mandating security requirements may deter customers and cannot alter remote users' settings without permission.

Innovation Solution

A computer system that grades users based on the security of their own systems through a series of test modules, allowing differential access and educating users on security practices, with users choosing which modules to complete and thus controlling their security improvements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security requirements are mandated for users, then system security is improved, but user access and customer relations deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts access levels based on real-time security assessments of user systems. Instead of a static mandatory access control model, the system continuously evaluates user security posture and adapts access rights accordingly, allowing flexible security management that responds to changing security conditions without arbitrarily blocking users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback loop where security assessments of user systems continuously inform access control decisions. Users receive feedback about their security status and are guided through improvement processes, creating a collaborative security enhancement model rather than a punitive mandatory compliance approach.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If automated security checks are implemented, then security assessment is improved, but user education and awareness deteriorate

Engineering Contradiction:
Improvesecurity assessmentVSAvoiduser education
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system introduces an intermediary layer between automated security assessment and access control. This intermediary component provides educational feedback to users about their security status, explaining assessment results and guiding them through improvement processes. The intermediary ensures that automated assessment doesn't replace user education but rather enhances it through structured feedback.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security protocols are imposed on users, then system security is improved, but user burden and frustration increase

Engineering Contradiction:
Improvesystem securityVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security improvement process is segmented into manageable modules or steps rather than presenting users with a monolithic complex set of requirements. The system breaks down security improvements into discrete, actionable tasks that users can complete progressively, reducing the perceived complexity and burden while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameters of security requirements based on individual user needs and risk profiles. Instead of applying uniform security protocols to all users, the system adjusts security expectations and requirements according to the specific security posture, usage patterns, and risk assessment of each user, thereby reducing unnecessary burden on low-risk users while maintaining security for high-risk scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8726353B2Secure computer use system
Publication Date: 2014.05.13 ZAMA INNOVATIONS LLC
  • US8726353B2 patent drawing
  • US8726353B2 patent drawing

AI summary

Methods and apparatus for ensuring the computer security of users of a computer system are described. A user is allocated a security grading relating to how secure their computer system (2) is, for instance in terms of anti-virus software, firewalls and up-to-date security patches. Methods and apparatus (10, 12) for providing a security grading of a user's computer system are also disclosed. Users without a security grading or with low level security grading may then be accorded only basic access to the data or functionality of another computer system (8), for instance such as on-line banking services or the like. This ensures therefore that those users that take responsibility for their own security are allowed full access without undue security protocols whereas users without proper security do not have so much access.