Dynamic Security Restriction Management for IT Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems in IT environments face challenges in managing access restrictions effectively, leading to unnecessary vulnerability during off-peak hours when fewer staff members are present, as they cannot differentiate between periods of need and idle time, making systems susceptible to breaches.

Innovation Solution

A security system that continuously monitors the presence of a pre-specified set of users in a defined environment, removing access restrictions when the specified users are present and reinstating them when they are not, thereby ensuring secure access only when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access restrictions are maintained continuously to ensure security, then security reliability is improved, but system availability deteriorates during periods when users are present and need access

Engineering Contradiction:
ImprovesecurityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security system dynamically adjusts access restrictions based on real-time detection of user presence. The system transitions between secured and accessible states depending on whether the pre-specified set of users is detected in the environment, making the security measure adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors the environment for user presence and uses this feedback to automatically adjust security restrictions. When users are detected, access is granted; when they leave, restrictions are reinstated, creating a closed-loop control system that responds to environmental conditions.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If access restrictions are removed during off-peak hours to improve availability, then system accessibility is improved, but security vulnerability increases

Engineering Contradiction:
Improveaccess availabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic security management where restrictions are temporarily suspended only when needed - specifically when the pre-specified set of users is present. This eliminates the need for continuous access restrictions while maintaining security during periods when no authorized users are present.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security system automatically manages its own access control based on environmental conditions without requiring manual intervention. It self-adjusts between secured and accessible states based on whether authorized users are detected, eliminating the need for external security management during off-peak hours.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If continuous monitoring of user presence is implemented to optimize security, then security management precision is improved, but system complexity increases

Engineering Contradiction:
Improveuser presence detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts and monitors only the critical factor needed for security decisions - the presence of the pre-specified set of users - rather than tracking all possible environmental variables. This focused monitoring approach reduces complexity while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The monitoring system automatically detects user presence and triggers appropriate security actions without requiring complex manual control or intervention. The system self-manages the entire process from detection to access control adjustment, simplifying operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10348733B2Managing security restrictions on a resource in a defined environment
Publication Date: 2019.07.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10348733B2 patent drawing
  • US10348733B2 patent drawing
  • US10348733B2 patent drawing

AI summary

Approaches described herein manage security restrictions on a resource in a defined environment to provide authorization and access. Specifically, a security system maintains a security restriction on the resource (e.g., an information technology (IT) account of a user, or an apparatus) in a defined environment. The presence of a plurality of users is continuously monitored throughout the defined environment and, based on a detection of a pre-specified set of users from the plurality of users in the defined environment, the security restriction is managed (e.g., removed or maintained). In one embodiment, the system allows access to the resource by removing the security restriction on the resource. The security restriction on the resource may be reinstated in the case that the pre-specified set of users from the plurality of users is no longer present in the defined environment.