ML Policy Conflict Resolution for Multi-Admin Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current internet access systems lack visibility and oversight, making them susceptible to security threats and inappropriate content access, particularly for minors, who may not have the ability to make informed decisions about their online activities.

Innovation Solution

A policy-controlled access system that includes a client device with a local application and a mid-link server monitoring network traffic. This system determines categories for data requests, identifies policies based on those categories, generates machine-learning based URL scores from user activities, and applies a policy engine preference to grant access to data based on these scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple administrators set policies for data access, then comprehensive security coverage is improved, but policy conflicts arise that complicate access control

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy conflict complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a machine learning-based policy engine preference system as an intermediary between multiple administrators' policies. This system automatically resolves conflicts by generating preferences based on priority levels assigned to different policies, eliminating the need for manual conflict resolution while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of policy resolution from manual administrative intervention to automated machine learning-based preference generation. By introducing priority level parameters and using ML to generate preferences, the system transforms complex policy conflicts into manageable preference-based decisions.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If machine learning based URL scoring is implemented, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-calculating machine learning-based URL scores and policy engine preferences before actual data access requests occur. This allows the system to have access control decisions ready in advance, improving precision while managing complexity through pre-computation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The machine learning model serves itself by automatically generating URL scores and policy preferences without requiring constant external intervention. The system self-adjusts and self-optimizes based on the data it processes, reducing the operational complexity despite the increased system sophistication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250119457A1Machine learning based policy conflict resolution for multi-administrator data access
Publication Date: 2025.04.10 NETSKOPE INC
  • US20250119457A1 patent drawing
  • US20250119457A1 patent drawing
  • US20250119457A1 patent drawing

AI summary

A policy-controlled access system comprising a client device running a local application, A mid-link server monitors network traffic from the client device. The network traffic includes third-party content accessed by a user on the client device. A request for data from the end-user is received using the local application, a category associated with the request for the data is determined, and multiple administrator accounts of the end-user is identified based on the category. The multiple administrator accounts are associated with multiple policies to access the data. A correspondence is identified between multiple policies of the multiple administrator accounts. A set of policy conflicts are identified among the policies based on the correspondence and a notification is generated to administrator having the policy conflicts. The policy conflicts are resolved based on suggestions from machine learning (ML) models or the administrators. The request is authorized to access the data.