Risk-Based Access Control Policy Revision

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing access control systems in information technology face challenges in dynamically revising access control policies due to frequent changes in organizational structures, regulatory modifications, and manual intervention, leading to costly and potentially ineffective revisions, as well as risks of data security and compliance exposures.

Innovation Solution

A method is introduced that evaluates trigger policies based on risk and countermeasure parameters to determine when a revision of the access control system is necessary, automating the process to ensure accurate and reproducible revisions, thereby reducing unnecessary changes and preventing delays in necessary updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access control policies are revised frequently to adapt to organizational changes and regulatory modifications, then adaptability is improved, but system stability deteriorates due to costly and potentially ineffective revisions

Engineering Contradiction:
Improveadaptability of access control policiesVSAvoidstability of access control system
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements dynamic access control policy revision by continuously monitoring risk parameters and automatically triggering revisions only when necessary. The system transitions from static periodic reviews to dynamic risk-based revisions, where the revision frequency adapts to actual risk levels rather than following a fixed schedule, thus improving adaptability while maintaining stability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter that triggers policy revision from time-based (periodic schedules) to risk-based (risk parameter thresholds). By monitoring risk parameters such as security incidents, compliance violations, and organizational changes, the system revises policies based on actual risk levels rather than arbitrary time intervals, resolving the contradiction between adaptability and stability.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If manual intervention is used to evaluate and revise access control policies, then flexibility is improved, but productivity deteriorates due to high costs and potential delays

Engineering Contradiction:
Improveflexibility in policy revisionVSAvoidproductivity of policy revision process
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements self-service automation where the access control system automatically monitors risk parameters, evaluates policy adequacy, and triggers revisions without manual intervention. The system serves itself by autonomously identifying when policy changes are needed based on risk thresholds, eliminating the need for continuous manual evaluation while maintaining flexibility through automated decision-making.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback loop where the system continuously monitors risk parameters, compares them against thresholds, and automatically triggers policy revisions when thresholds are exceeded. This closed-loop feedback mechanism replaces manual evaluation with automated monitoring and decision-making, improving productivity while maintaining the flexibility to respond to actual risk conditions.

Inventive Principle:
Principle #23Feedback

3Speed

If access control policies are revised without proper risk assessment, then speed of implementation is improved, but reliability deteriorates due to ineffective revisions and security exposures

Engineering Contradiction:
Improvespeed of policy revisionVSAvoidreliability of access control system
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent performs preliminary risk assessment by continuously monitoring risk parameters before triggering any policy revision. The system evaluates risk levels, identifies specific vulnerabilities, and determines necessary policy changes in advance, ensuring that revisions are both timely and targeted. This preliminary evaluation prevents hasty, ineffective revisions while maintaining fast response to actual security risks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12107900B2Revision of access control system triggered by policies based on risks and/or countermeasures thereof
Publication Date: 2024.10.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12107900B2 patent drawing
  • US12107900B2 patent drawing
  • US12107900B2 patent drawing

AI summary

A solution is proposed for facilitating a maintenance of an access control system. A corresponding method comprises evaluating one or more trigger policies according to one or more policy parameters; the policy parameters of the trigger policies in part relate to risks of the access control system and/or to countermeasures for mitigating the risks. A revision of the access control system, comprising a corresponding mining activity, is triggered according to a result of the evaluation of the trigger policies. A computer program and a computer program product for performing the method are also proposed. Moreover, a system for implementing the method is proposed.