Interposed Access Control System for Computer Audit and Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively audit, monitor, and control access to computers, particularly in protecting against improper access and external tampering while allowing authorized access, and do not adequately manage alternate levels of access or record transactions between users and protected computer systems.

Innovation Solution

A system is interposed between user computers and protected computers to authenticate and authorize access, using software to verify user and superuser identities, record all transactions, and restrict access, with features like SSH connections, audit databases, and proprietary software like SecureAgent to manage and monitor access, ensuring secure and controlled interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a system is interposed between user computers and protected computers to verify and authorize access, then security against improper access and external tampering is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements an access control system that acts as an intermediary component between user computers and protected computers. This intermediary system verifies user identities, authorizes access requests, and monitors transactions without requiring direct integration into the protected computer systems, thereby improving security while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system provides alternate levels of access including superuser access, then adaptability and versatility are improved, but device complexity increases

Engineering Contradiction:
Improveaccess levelsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control system implements dynamic access level management that can adaptively grant different levels of access (standard user, superuser, administrative) based on verified user identities and authorization policies. The system dynamically adjusts the scope and permissions of access without requiring static, hard-coded configurations for each access level, thereby improving versatility while managing complexity through flexible, policy-driven control.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If the system audits and monitors all transactions and data between users and protected computer systems, then measurement precision and detection capability are improved, but loss of information and processing overhead increase

Engineering Contradiction:
Improvetransaction monitoringVSAvoiddata processing overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts and isolates the auditing and monitoring functions into a dedicated component that operates independently from the core access control logic. This extracted monitoring module captures transaction data and user activities without interfering with the primary access authorization process, thereby achieving precise transaction measurement while minimizing information loss and processing overhead by handling monitoring as a separate, non-intrusive function.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2051180B1System to audit, monitor and control access to computers
Publication Date: 2018.01.17 JOHNSON CO
  • EP2051180B1 patent drawingFigure 1

AI summary

An audit, monitor, and access control system for use with at least one user computer and at least one protected computer. The system includes first software to authenticate authorized access by a user computer. A server connection network adapter permits communication with a user computer. Second software is provided to authenticate authorized superuser access by a user computer. A client connection network adapter permits communication with a protected computer. All data transferred and all activity between user computers and protected computers is recorded. Additionally, all data transferred and all activity between the user computers and the protected computers is audited.