Decentralized Folder Access Management for Dynamic Organizations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control technologies in organizations are inefficient and impractical for managing user access rights, particularly in large, complex environments with changing structures and personnel, leading to issues with redundant access rights and orphan accounts, and a lack of effective data security.

Innovation Solution

A decentralized system for managing user data access, where storage elements have ownership attributes, allowing data owners and group owners to control access rights through a folder management application that processes requests and automatically generates proposals based on user behavior, dynamically adapting to organizational changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review and maintenance of access control lists is used, then data security can be maintained through human oversight, but the system becomes inefficient and inaccurate especially in large organizations with changing structures

Engineering Contradiction:
Improvedata securityVSAvoidaccess management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automatic monitoring of user access behavior and self-adjustment of access rights based on organizational changes. The access control system no longer requires manual intervention but automatically adapts to organizational changes, user behavior patterns, and security policies, thereby maintaining reliability while dramatically improving productivity in large organizations.

Inventive Principle:
Principle #25Self-service

2Reliability

If centralized access control management is implemented in IT departments, then security policies can be uniformly enforced, but the system becomes impractical and difficult to manage in complex organizations

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments access control management into autonomous units distributed across different organizational departments and locations. Each segment operates independently with its own access control lists and policies, allowing uniform security enforcement without requiring centralized management. This segmentation reduces system complexity while maintaining security policy consistency across the entire organization.

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional access control technologies are used, then basic security can be provided, but redundant access rights and orphan accounts cannot be effectively detected and removed

Engineering Contradiction:
Improvebasic security protectionVSAvoidredundant access rights and orphan accounts
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system continuously monitors user access behavior and organizational structure changes, then automatically adjusts access rights based on this feedback. By comparing actual access patterns against assigned permissions and organizational hierarchy, the system detects and eliminates redundant access rights and orphan accounts, preventing information loss while maintaining basic security protection.

Inventive Principle:
Principle #23Feedback

4Ease of manufacture

If role-based access control is implemented, then access rights can be standardized according to organizational roles, but the system lacks adaptability to dynamic organizational changes and diverse access control models

Engineering Contradiction:
Improveaccess rights standardizationVSAvoidadaptability to organizational changes
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts access control configurations to reflect real-time organizational changes while maintaining role-based standardization. As organizational structures, roles, and relationships change, the system automatically updates access rights to match current realities, ensuring both standardization and adaptability in diverse and evolving organizational environments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9727744B2Automatic folder access management
Publication Date: 2017.08.08 VARONIS
  • US9727744B2 patent drawing
  • US9727744B2 patent drawing
  • US9727744B2 patent drawing

AI summary

Methods and systems are provided for decentralizing user data access rights control activities in networked organizations having diverse access control models and file server protocols. A folder management application enables end users of the file system to make requests for access to storage elements, either individually, or by becoming members of a user group having group access privileges. Responsibility for dealing with such requests is distributed to respective group owners and data owners, who may delegate responsibility to authorizers. The application may also consider automatically generated proposals for changes to access privileges. An automatic system continually monitors and analyzes access behavior by users who have been pre-classified into groups having common data access privileges. As the organizational structure changes, these groups are adaptively changed both in composition and in data access rights.