Role-Based Attribute Access Control for Automated Risk Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems for computer network-based and web-based services face challenges in providing secure and efficient access management, particularly in large networks, as they often require costly and error-prone manual administration of access control lists, and may not effectively balance user permissions and security levels.
Innovation Solution
A system that combines authentication context, confidence estimation, identity assurance, risk assessment, attributes, and roles within a role-based attribute-based access control (RABAC) model to provide enhanced access control security, using a server application, authentication service, risk service, and authorization service to evaluate and manage access requests from user devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual administration of access control lists is used, then access control can be implemented, but administrative costs increase and errors occur
Solution Approach 1:
The system enables automated self-service access control where the system automatically evaluates access requests against policies and makes authorization decisions without requiring manual administrator intervention for each request, thereby reducing administrative complexity while maintaining reliability
Solution Approach 2:
The patent replaces manual mechanical administration of access control lists with an automated electronic system that uses processors to evaluate access requests against stored policies, eliminating human error and reducing administrative burden
2Reliability
If centralized access policy administration is implemented, then security control is improved, but administration becomes costly and error-prone
Solution Approach 1:
The system implements automated self-service where access policies are automatically evaluated and enforced without requiring manual configuration for each access request, reducing administrative effort while maintaining centralized security control
Solution Approach 2:
The patent creates a universal access control system that handles multiple types of access requests and policies through a single automated evaluation mechanism, making the system both secure and easy to operate
3Adaptability or versatility
If role-based access control is used, then security management aligns with organizational structure, but system complexity increases
Solution Approach 1:
The patent introduces a new dimension of attribute-based evaluation that works alongside traditional role-based access control, allowing the system to handle complex organizational structures by evaluating multiple attributes simultaneously rather than relying solely on hierarchical roles
Data Source
AI summary
Systems and methods are disclosed for receiving an access request from a user device, the access request including an identity claim for a user; evaluating a risk of access based on matching an attribute of the user device with attributes stored in a user information database; authenticating the access request based on the identity claim and the risk evaluation to determine an authentication confidence level; generating a token based on the confidence level and the attribute matched; producing an authorization response based on inputs from the token, a risk based access control, a role based access control, and an attribute based access control, in which the authorization response determines whether to allow access to a system, deny access to the system, or request additional input from the user device.


