Policy Analyzer Service for Security Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and maintaining the security of computer systems and networks is complex due to changing user access rights, making it difficult to determine whether security policies grant or deny access to the correct resources as the number and types of users expand.
Innovation Solution
A policy analyzer service that compares security policies using propositional logic to determine their relative permissiveness, equivalence, or incomparability, utilizing a satisfiability engine to translate permission statements into logical constraints and evaluate their satisfiability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number and types of users in a computer system expand, then the system supports more users and resources, but it becomes difficult to determine whether access rights grant or deny access to correct resources
Solution Approach 1:
The patent introduces a policy analyzer service as an intermediary between security policies and users/resources. This service automatically analyzes security policies to determine their relative permissiveness and equivalence, acting as a mediator that resolves the complexity of access right determination in expanded user environments without requiring manual verification of each policy's effects
2Ease of operation
If security policies are manually managed and maintained, then policy changes can be made, but it becomes complex and challenging to determine whether policies correctly grant or deny access as the system expands
Solution Approach 1:
The patent implements feedback mechanisms where the policy analyzer service continuously evaluates security policies and provides information about their relative permissiveness and equivalence. This feedback loop allows system administrators to understand the actual effects of policy changes and maintain correct access control without manually tracking complex policy interactions as the system expands
Solution Approach 2:
The policy analyzer service enables security policies to essentially self-evaluate and self-describe their relationships. By automatically determining equivalence and permissiveness, the system reduces the need for manual policy management and analysis, allowing the security system to maintain itself as it expands
Data Source
AI summary
Requests of a computing system may be monitored. A request associated with the application of a policy may be identified and a policy verification routine may be invoked. The policy verification routine may detect whether the policy of the request is more permissive than a reference policy and perform a mitigation routine in response to determining that the policy of the request is more permissive than the reference policy. Propositional logics may be utilized in the evaluation of policies.


