Interim Security Policy Segmentation in AI-Driven Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computerized security platforms face challenges in managing and distinguishing between long-term security rules and temporary exceptions, leading to bloated security systems with potential security loopholes.
Innovation Solution
Implementing an interim security policy within a computerized security platform that uses generative artificial intelligence to automatically generate temporary security policies based on historical patterns or user behavior, allowing for non-permanent changes without editing permanent rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If long-term security rules and temporary exceptions are commingled within the security platform, then the security platform can maintain a unified rule structure, but the security platform becomes bloated with intractable and stale rules that create security loopholes
Solution Approach 1:
The patent segments security rules into two distinct categories: permanent security rules stored in a first data structure and interim security policies stored in a second data structure. This segmentation allows the system to maintain a unified security platform while preventing the commingling of permanent and temporary rules, thereby avoiding bloat and security loopholes.
Solution Approach 2:
The patent extracts interim security policies from the permanent security rules by storing them in a separate second data structure. This extraction enables the system to remove or alter temporary exceptions without affecting the core permanent security rules, maintaining security posture while managing rule complexity.
2Ease of operation
If administrators opt not to remove rule exceptions due to inadequate or inability to access impact information, then the security platform maintains operational continuity, but the security platform accumulates stale rules that create security loopholes
Solution Approach 1:
The patent implements a impact analysis mechanism that provides feedback to administrators about the effects of removing or altering security rules. The system identifies dependent interim policies and notifies administrators, enabling informed decision-making about rule management while maintaining operational continuity.
Solution Approach 2:
The patent enables the security platform to automatically identify and report the impact of potential rule changes. The system self-analyzes dependencies between permanent rules and interim policies, providing administrators with the information needed to make informed decisions without manual impact assessment.
3Reliability
If interim security policies are stored separately from security rules, then the security platform becomes more secure and easier to maintain, but the security platform requires additional storage structures
Solution Approach 1:
The patent segments the data storage into two distinct structures: a first data structure for permanent security rules and a second data structure for interim security policies. This segmentation improves security and maintainability by preventing rule commingling while organizing complexity through clear separation of concerns.
Solution Approach 2:
The patent creates a universal security platform architecture that can handle both permanent rules and interim policies through standardized data structures. The separate second data structure for interim policies enables multiple functions including temporary exceptions, testing environments, and time-limited access controls within a unified system.
Data Source
AI summary
An apparatus, having a server and processor, is configured to receive a first set of security rules applicable to a set of users or a set of files for a first period of time. The first set of security rules are executable in an order of priority. The processor receives an interim security policy that is different from the first set of security rules. The interim security policy is applicable to a subset of the set of users for a second period of time that is less than the first period, or a subset of the set of files for a second period of time that is less than the first period. The processor determines, in the first set of security rules, an insertion point among the order of priority. The processor executes, at the insertion point and in the first set of security rules, the interim security policy.


