Policy Analyzer Service for Security Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and maintaining the security of computer systems and networks is complex due to changing user access rights, making it difficult to determine whether security policies grant or deny access to the correct resources as the number and types of users expand.

Innovation Solution

A policy analyzer service that compares security policies using propositional logic to determine their relative permissiveness, equivalence, or incomparability, utilizing a satisfiability engine to translate permission statements into logical constraints and evaluate their satisfiability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number and types of users in a computer system expand, then the system supports more users and resources, but it becomes difficult to determine whether access rights grant or deny access to correct resources

Engineering Contradiction:
Improvenumber and types of users supportedVSAvoiddifficulty to determine correct access rights
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a policy analyzer service as an intermediary between security policies and users/resources. This service automatically analyzes security policies to determine their relative permissiveness and equivalence, acting as a mediator that resolves the complexity of access right determination in expanded user environments without requiring manual verification of each policy's effects

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security policies are manually managed and maintained, then policy changes can be made, but it becomes complex and challenging to determine whether policies correctly grant or deny access as the system expands

Engineering Contradiction:
Improveability to change security policiesVSAvoidcomplexity of managing and maintaining security
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the policy analyzer service continuously evaluates security policies and provides information about their relative permissiveness and equivalence. This feedback loop allows system administrators to understand the actual effects of policy changes and maintain correct access control without manually tracking complex policy interactions as the system expands

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The policy analyzer service enables security policies to essentially self-evaluate and self-describe their relationships. By automatically determining equivalence and permissiveness, the system reduces the need for manual policy management and analysis, allowing the security system to maintain itself as it expands

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10630695B2Security policy monitoring service
Publication Date: 2020.04.21 AMAZON TECH INC
  • US10630695B2 patent drawing
  • US10630695B2 patent drawing
  • US10630695B2 patent drawing

AI summary

Requests of a computing system may be monitored. A request associated with the application of a policy may be identified and a policy verification routine may be invoked. The policy verification routine may detect whether the policy of the request is more permissive than a reference policy and perform a mitigation routine in response to determining that the policy of the request is more permissive than the reference policy. Propositional logics may be utilized in the evaluation of policies.