Role History Analysis for Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for performing security assessments in computing environments lack the ability to effectively detect inconsistencies in role data, leading to potential unauthorized access and inadequate security measures.

Innovation Solution

An access-control computing system that receives an access request data structure from a client computing system, identifies the roles held by a target entity, compares these roles with role history data from a secure identity repository, and generates a dynamic access-control data structure to assess security risks and facilitate further security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If automated role data comparison is implemented, then security assessment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an access-control computing system as an intermediary between client computing systems and secure identity repositories. This mediator automatically compares role data from multiple sources, detects inconsistencies, and generates security assessments, thereby improving measurement precision while managing system complexity through centralized automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual security assessment processes with automated computing systems that perform role data comparison and inconsistency detection. This substitution of mechanical/manual operations with automated computational processes improves assessment accuracy while the systematic automation actually reduces operational complexity despite increasing technical system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive role history data is collected from multiple sources, then detection precision is improved, but information processing complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidinformation processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access-control computing system is designed to perform multiple functions: collecting role data from various contributor computing systems, storing it in a secure identity repository, comparing it with access requests, detecting inconsistencies, and generating security assessments. This multi-functional approach improves detection precision by comprehensively analyzing role history data while managing processing complexity through a unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If real-time access control assessment is performed, then security response speed is improved, but computational load increases

Engineering Contradiction:
Improvesecurity response speedVSAvoidcomputational load
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by pre-collecting and storing role history data in secure identity repositories before access requests are made. When access requests arrive, the system performs rapid comparisons against pre-stored data, enabling real-time security assessments with reduced computational load during critical decision-making moments.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250119433A1Third-party access-control support using role history analysis
Publication Date: 2025.04.10 EQUIFAX INC
  • US20250119433A1 patent drawing
  • US20250119433A1 patent drawing
  • US20250119433A1 patent drawing

AI summary

Various aspects of the present disclosure involve computing environments that provide third-party access-control support. For instance, an access-control computing system can access a secure identity repository having role history data from various contributor computing systems. The access-control computing system can compare an identified set of roles with a set of roles described by role history data for a target entity. The access-control computing system can determine, from the comparison, whether the target entity poses a security risk based on inconsistencies between the sets of roles, durations associated with the roles, or both. The access-control computing system can provide a client computing system with a dynamic access-control data structure that is generated based on the comparison. The dynamic access-control data structure allows the client computing system to output the security assessment to an end user or to otherwise facilitate further security measures with respect to the target entity.