Dynamic Enterprise Security Policy Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face challenges in managing large user populations and dynamic security policies, leading to inefficiencies and inconsistencies, particularly in handling time-sensitive and location-based access controls, and are unable to scale effectively with growing user communities.

Innovation Solution

A centralized system that evaluates security policies in real-time using XML-encoded, stateless policies with a hierarchical structure, leveraging an API interface and external rules analysis engine, allowing dynamic data retrieval and eliminating the need for executable code, thus enabling flexible and scalable access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional ACL-based access control systems are used to manage user permissions, then individual user access can be controlled, but the administrative overhead and system complexity grow exponentially as user population and system functionality increase

Engineering Contradiction:
Improveaccess control securityVSAvoidadministration overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into multiple hierarchical levels: enterprise-wide policies, application-specific policies, and resource-level policies. This segmentation allows each level to be managed independently, reducing the complexity of managing permissions across the entire system while maintaining comprehensive access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy enforcement points (PEP) as intermediaries between users and resources. These PEPs automatically evaluate policies and make access decisions, eliminating the need for manual permission management and reducing administrative overhead while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If permissions are statically granted to users and groups, then access control decisions are simple to make, but the system cannot adapt to dynamic conditions such as time, location, or user status changes

Engineering Contradiction:
Improveaccess control decision-makingVSAvoiddynamic access control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policies that automatically adjust access permissions based on real-time conditions such as user location, time of day, and current user status. The policy evaluation process dynamically retrieves relevant data and applies appropriate access rules without requiring manual intervention, thus maintaining ease of operation while achieving adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors user attributes and environmental conditions, using this feedback to automatically adjust access permissions. When user status or contextual conditions change, the policy evaluation process detects these changes and dynamically modifies access decisions, enabling the system to adapt to dynamic conditions while maintaining simple operation through automation.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple levels of access control abstraction are implemented with split administration, then specialized security management is achieved, but tracking user access permissions becomes extremely convoluted

Engineering Contradiction:
Improvesecurity managementVSAvoidpermission tracking process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy repository that stores and manages policies across all hierarchical levels. This centralized repository provides a single source of truth for all access control decisions, allowing specialized security management at each level while simplifying permission tracking through unified policy definitions and consistent evaluation rules.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If ACLs are reconfigured whenever security policy changes, then access control accuracy is maintained, but the time and resources required to update tens of thousands of ACL entries become prohibitive

Engineering Contradiction:
Improveaccess control accuracyVSAvoidpolicy update time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent pre-compiles and caches policy evaluation rules in the policy enforcement points. When policies change, only the relevant policy definitions need to be updated in the repository, and the PEPs automatically retrieve and apply the updated policies. This preliminary action of pre-compiling rules eliminates the need to reconfigure thousands of individual ACL entries, maintaining access control accuracy while dramatically reducing policy update time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7779247B2Method and system for dynamically implementing an enterprise resource policy
Publication Date: 2010.08.17 CROWDSTRIKE
  • US7779247B2 patent drawing
  • US7779247B2 patent drawing
  • US7779247B2 patent drawing

AI summary

A rules evaluation engine that controls user's security access to enterprise resources that have policies created for them. This engine allows real time authorization process to be performed with dynamic enrichment of the rules if necessary. Logging, alarm and administrative processes for granting or denying access to the user are also realized. The access encompasses computer and physical access to information and enterprise spaces.