Secure Container Access Control via Behavioral Enforcement Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data access control methods fail to prevent unauthorized access and illegitimate actions by authorized users, lacking comprehensive protection throughout the data access process.

Innovation Solution

A secure container based on an image file is instantiated at an endpoint device, where access is authenticated and controlled through an enforcement engine that monitors user behavior, decrypting data only as needed and preventing access violations by monitoring access patterns and geographical locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional access control methods are used, then ease of operation is maintained, but security against unauthorized access and illegitimate actions deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into multiple encrypted portions and stores them in separate secure containers. Each container requires authentication and behavioral verification to access specific data portions, distributing security control across multiple independent units rather than relying on a single complex access control system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an enforcement engine as an intermediary between users and data. This engine monitors user behavior, verifies credentials, and controls data access dynamically, replacing conventional direct access control with a mediating layer that enhances security without requiring users to manage complex security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted and stored in secure containers, then security protection is improved, but ease of accessing legitimate data deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiddata access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control where the enforcement engine continuously monitors user behavior and adjusts data access permissions in real-time. Legitimate users experience smooth access through automated behavioral verification, while the system adapts to suspicious activities by restricting access, maintaining convenience for authorized operations while enhancing security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The enforcement engine performs self-service by automatically verifying user credentials and monitoring behavior without requiring manual security interventions. The system autonomously determines whether to grant or deny access based on predefined policies and observed user actions, eliminating the need for users to navigate complex security approval processes.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive monitoring of user behavior is implemented, then detection of illegitimate actions is improved, but loss of time for processing access requests deteriorates

Engineering Contradiction:
Improvebehavior monitoring accuracyVSAvoidaccess request processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing baseline user behavior profiles and access policies before actual data access occurs. The enforcement engine pre-configures monitoring parameters and verification thresholds, enabling rapid real-time evaluation of user actions without requiring complex analysis during each access request, thus maintaining both monitoring precision and fast processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11880482B2Secure smart containers for controlling access to data
Publication Date: 2024.01.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11880482B2 patent drawing
  • US11880482B2 patent drawing
  • US11880482B2 patent drawing

AI summary

A computer system controls access to data. A secure container that is based on an image file is instantiated at an endpoint device of a user, wherein the secure container includes encrypted data corresponding to the user. An access request to the secure container is authenticated by verifying credentials of the user. In response to verifying the credentials of the user, access to the data is granted. Access to the data is controlled by decrypting and enabling access to a portion of the data, wherein additional portions of the data are decrypted and made accessible based on user behavior.