Permission Assignment Advisor for Dynamic Role Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data access control systems face challenges in accurately assigning user roles and permissions, often resulting in either excessive or insufficient access rights, and fail to detect anomalies in user behavior effectively.

Innovation Solution

A method and system that identifies user actions, compiles historical data, and analyzes trends or anomalies to recommend appropriate role reassignments or permission changes, utilizing a networked computer environment with processors, memories, and program instructions to generate recommendations for administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional data access control systems are used to manage user roles and permissions, then administrators can control access to files and data, but the systems fail to accurately assign appropriate roles and permissions, resulting in either excessive or insufficient access rights

Engineering Contradiction:
Improveaccuracy of role and permission assignmentVSAvoidappropriateness of access rights
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system continuously monitors user actions and feeds this information back to automatically adjust roles and permissions. By collecting data on what users actually do and comparing it to their assigned roles, the system provides feedback loops that enable dynamic refinement of access rights, ensuring they remain appropriate and accurate over time

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables automatic self-adjustment of roles and permissions based on monitored user behavior patterns. Rather than requiring manual administrator intervention for every change, the system autonomously analyzes user actions and automatically assigns or modifies roles and permissions to match actual usage patterns, improving both accuracy and appropriateness

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional data access control systems are used, then basic access regulation is maintained, but the systems fail to detect anomalies in user behavior effectively

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidanomaly detection effectiveness
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system establishes continuous feedback loops that monitor user actions against established baselines and role expectations. When deviations are detected, the system generates alerts and can automatically respond to anomalies, transforming static access control into a dynamic security monitoring system that actively detects and responds to suspicious behavior

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-establishes baselines of normal user behavior and defines anomaly detection criteria before suspicious activities occur. By setting up these detection mechanisms in advance and continuously comparing actual behavior against predetermined security policies, the system can proactively identify and respond to anomalies rather than reacting after incidents occur

Inventive Principle:
Principle #10Preliminary action

3Productivity

If manual role assignment is used in data access control, then administrators have control over permissions, but the process is time-consuming and results in inaccurate role assignments

Engineering Contradiction:
Improverole assignment efficiencyVSAvoidaccuracy of role assignment
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system automatically assigns roles and permissions by monitoring user actions and autonomously determining appropriate access rights based on observed behavior patterns. This eliminates manual administrator intervention for routine assignments, dramatically improving efficiency while maintaining or enhancing accuracy through data-driven decision-making

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts role parameters and permissions based on changing user behavior patterns and organizational needs. By continuously monitoring and adapting role definitions to reflect actual usage, the system maintains high accuracy in role assignments while eliminating the time-consuming manual review and adjustment processes

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12177223B1Permission assignment advisor
Publication Date: 2024.12.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12177223B1 patent drawing
  • US12177223B1 patent drawing
  • US12177223B1 patent drawing

AI summary

A method, computer program product, and computer system are provided for recommending user role assignments. An action executed by a user from among a plurality of users on a network is identified. Data corresponding to the identified action is compiled and consolidated in a database of historical actions associated with the plurality of users. A trend or an anomaly is identified within the compiled and consolidated data based on a role and permissions associated with the user. A recommendation is generated for reassignment of new permissions or a new role associated with the user based on the identified trend or anomaly.