Rules Engine for Least Privilege Access Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for implementing least privilege policies in cloud environments are cumbersome, requiring manual creation of access rules for new resources and services, which can lead to unintended access permissions.

Innovation Solution

A rules engine-based system that analyzes access requests against predefined rules to determine compliance with a least privilege policy, automatically provisioning or denying access while generating reports for non-compliant requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual creation of IAM policies is performed for each new resource or service, then access control precision is improved, but device complexity and time consumption increase significantly

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system enables self-service policy generation where the templating tool automatically creates IAM policies based on user-input parameters (account, resource, action, effect). The tool serves itself by maintaining a library of policy templates and automatically generating appropriate policies without requiring manual intervention from security personnel for each new resource.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The templating tool provides universal policy creation capabilities that work across multiple cloud resources, services, and actions. A single tool interface handles diverse policy creation needs by selecting from predefined templates and adjusting parameters, making the system versatile for different policy scenarios without requiring separate manual processes for each resource type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If manual creation of IAM policies is performed for each new resource or service, then access control precision is improved, but loss of time increases due to the daunting task for database managers

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy creation time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-defining policy templates with common access patterns and structures. When a new resource or service is added, the templating tool can quickly generate appropriate policies by selecting from these pre-prepared templates and filling in specific parameters, rather than creating policies from scratch each time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated templating tool performs the policy creation task itself without requiring extensive manual intervention. The system self-services by automatically generating policies based on input parameters, eliminating the time-consuming manual process for database managers and security personnel.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If broad access permissions are granted to developers, then ease of operation is improved, but security is worsened due to unintended access to new functionalities

Engineering Contradiction:
Improvedeveloper access convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies local quality by granting access permissions specifically tailored to each developer's needs and the particular resources they require. Rather than applying uniform broad permissions, the templating tool generates localized policies that match specific account-resource-action combinations, ensuring developers have access only where necessary.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access control system is dynamic, automatically adapting policies when new resources or services are added to the cloud environment. The system dynamically generates or updates policies based on current resource inventories and developer roles, ensuring access permissions remain appropriate as the environment evolves without manual intervention.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12289348B2Rules engine for selectively granting access to secured resources
Publication Date: 2025.04.29 CAPITAL ONE SERVICES LLC
  • US12289348B2 patent drawing
  • US12289348B2 patent drawing
  • US12289348B2 patent drawing

AI summary

Systems and methods for providing least privilege access to a resource within a secured server are disclosed. The systems and method can include receiving an access request from a client requesting access to the resource, the access request comprising a role or policy associated with the client and one or more actions associated with the resource. A rules engine can be initialized, the engine defining one or more rules usable by the system to determine whether the access request complies with a least privilege policy. The systems and method can analyze the role or policy and the access request with the rules engine to determine whether the access request complies with the least privilege policy. When the access request complies with the rules, access to the resource can be granted; when the access request does not comply with the rules, access to the resource can be denied.