Server Access Window Optimization via Historical Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in optimizing access control for server privilege, balancing data protection and business continuity, while minimizing unauthorized exposure and ensuring compliance within active directory environments.

Innovation Solution

A system that electronically receives server access requests, determines a time period based on past access actions, initiates an access window, and automatically terminates it, allowing for snapshot generation and future completion of actions if needed, to manage access effectively and efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If privileged access management adds protection to privileged groups with monitoring and fine-grained controls, then security and compliance are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically determines time periods based on historical access data and authentication levels without requiring manual configuration. The access window management is automated, with the system self-adjusting time stamps and duration based on past patterns, reducing operational overhead while maintaining security controls

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-calculates time periods by analyzing historical access requests and actions before granting new access windows. By determining appropriate time stamps and durations in advance based on past behavior patterns, the system reduces real-time decision complexity while maintaining security

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access control restrictions are implemented to prevent unauthorized exposure, then security is improved, but business continuity and user productivity may be compromised

Engineering Contradiction:
Improveunauthorized exposure preventionVSAvoidbusiness continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access window duration is dynamically adjusted based on authentication levels and historical access patterns. High-authentication users receive longer access windows that accommodate complex tasks, while maintaining strict time limits for lower-authentication users, thus balancing security with productivity needs

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the time period parameter based on authentication level and historical data. By adjusting the duration and time stamps of access windows according to user credentials and past behavior, the system allows sufficient time for legitimate business operations while preventing unauthorized prolonged access

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual access approval processes are used to ensure compliance, then security control is improved, but processing time and operational efficiency decrease

Engineering Contradiction:
Improvecompliance controlVSAvoidaccess request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses feedback from historical access requests and executed actions to automatically determine time periods for new access windows. By analyzing past compliance data and access patterns, the system makes automated compliance decisions without manual intervention, reducing processing time while maintaining auditability

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system automatically evaluates compliance requirements and determines appropriate time stamps and durations based on historical data and authentication levels, without requiring manual approval for each request. This self-service approach maintains compliance control while eliminating manual processing delays

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11025641B2System for optimizing access control for server privilege
Publication Date: 2021.06.01 BANK OF AMERICA CORP
  • US11025641B2 patent drawing
  • US11025641B2 patent drawing
  • US11025641B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for optimizing access control for server privilege. The present invention is configured to electronically receive, from a first computing device associated with a user, a server access request to access one or more servers; determine a first time period associated with the server access request based on an amount of time required to execute a first action on the one or more servers, wherein the first time period is defined by a first time stamp and a second time stamp; initiate an access window at the first time stamp from which the first computing device is capable of executing the first action on the one or more servers; and automatically terminate the access window at the second time stamp.