Dynamic Security Policy Generation for Organizational Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in efficiently generating and implementing security policies within organizational computing systems, balancing ease of use with effective security measures that can adapt to dynamic user needs and conditions.

Innovation Solution

A computing system that receives access requests, accesses user-customized security policies defined using organizational data, and determines policy evaluation outcomes by comparing references to organizational data with employee data records, thereby providing responses to access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security policies are implemented, then security measures are enforced, but ease of use deteriorates due to unnecessary friction in operations

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security policy system dynamically adapts to organizational data changes by automatically detecting modifications in employee records, roles, or departments and adjusting security policies in real-time. This eliminates static, rigid security configurations that create operational friction, replacing them with flexible policies that automatically align with current organizational structures while maintaining security effectiveness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically generating, evaluating, and updating security policies based on organizational data without requiring manual security administrator intervention for each change. When organizational data changes, the system autonomously detects the change, evaluates its security implications, and updates policies accordingly, reducing the operational burden on users while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

2Reliability

If security policies are manually customized for each user, then security effectiveness improves, but device complexity and time consumption increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidtime for policy generation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-establishing security policy templates and rules based on organizational structures, roles, and departments. When a new employee joins or an existing employee changes roles, the system automatically applies pre-defined security policies relevant to their position, eliminating the need for manual policy creation from scratch and significantly reducing the time required for security policy generation while maintaining effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements universal security policies that can be automatically applied across multiple users and scenarios. By creating policies based on organizational roles and departments rather than individual users, a single policy configuration serves multiple employees with similar roles, reducing the overall complexity and time required for security policy management while maintaining appropriate security controls for each user context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If security policies are frequently updated to match organizational changes, then adaptability improves, but system complexity increases

Engineering Contradiction:
Improveadaptability to organizational changesVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms that automatically monitor organizational data changes and trigger appropriate security policy updates. When changes are detected in employee records, roles, or departments, the system evaluates the security implications and automatically adjusts policies accordingly. This closed-loop feedback system enables the organization to maintain high adaptability to changes while keeping the policy management process simple and automated, eliminating the need for complex manual tracking and updating procedures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250175469A1Generating and Implementing Organizational Security Policies
Publication Date: 2025.05.29 PEOPLE CENTER INC
  • US20250175469A1 patent drawing
  • US20250175469A1 patent drawing
  • US20250175469A1 patent drawing

AI summary

Methods, systems, devices, and tangible non-transitory computer readable media for generating and implementing security policies are provided. The disclosed technology can include accessing a security request associated with generating a security policy based in part on organizational data that includes one or more organizational records. The security request can include one or more rules associated with the security policy. Based at least in part on the security request, the one or more rules that are in compliance with one or more policies associated with the organizational data can be determined. Furthermore, the security policy can be generated based at least in part on the one or more rules that are in compliance with the one or more policies. Furthermore, operations associated with implementing the security policy can be performed.