Smart Object Access Management via Contextual Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access management techniques face challenges in balancing security and usability, particularly with password-based, biometric, and token-based systems, which often result in weak security due to user convenience settings, cognitive burdens, and privacy concerns, as well as issues with deauthentication.

Innovation Solution

The implementation of an 'active environment' utilizing dynamically reconfigurable sets of smart objects, where user access is managed through a learning agent that determines the likelihood of user interaction with specific smart objects, requesting and utilizing cryptographic material to verify user involvement, thereby controlling access to applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used to control access, then ease of operation is improved, but security deteriorates because users choose weak passwords

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces mechanical/password-based authentication with environmental context sensing and machine learning inference. Instead of requiring users to manually provide passwords, the system automatically determines authentication status by analyzing contextual factors such as device location, time, user behavior patterns, and environmental conditions, thereby eliminating the need for weak passwords while maintaining ease of use

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service authentication by automatically making decisions about access control based on learned user behavior patterns and contextual analysis. The machine learning model continuously adapts to user habits and automatically authenticates or de-authenticates without requiring user intervention, replacing the manual password entry process

Inventive Principle:
Principle #25Self-service

2Reliability

If biometric authentication is used to improve security, then device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes physical biometric sensors and cryptographic hardware with software-based machine learning inference. Instead of requiring fingerprints, facial recognition, or secure enclaves, the system uses contextual analysis of device sensors, network communications, and user behavior patterns to determine authentication status, eliminating the need for expensive hardware while maintaining security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates a virtual copy of the authentication process by inferring user identity and intent from contextual data rather than requiring direct physical verification. The machine learning model analyzes patterns in device usage, location, time, and environmental factors to create a computational representation of the user's authentication state, replacing physical biometric verification

Inventive Principle:
Principle #26Copying

3Reliability

If physical tokens are required for access to eliminate weak authentication, then ease of operation deteriorates due to the burden of carrying tokens

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication requirement from physical tokens and relocates it to environmental context analysis. Instead of requiring users to carry and present physical keys or tokens, the system extracts authentication information from the contextual environment surrounding the device, such as location data, time of day, network connections, and user behavior patterns, thereby eliminating the burden of carrying physical tokens

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces environmental context as an intermediary between the user and the authentication mechanism. Rather than direct physical token presentation, the context analysis acts as a mediator that translates environmental factors into authentication decisions, allowing secure access without requiring users to physically carry or present tokens

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If automatic relocking after timeout is implemented to improve security, then ease of operation worsens due to extended timeout periods reducing convenience

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic timeout management where the locking behavior adapts in real-time based on contextual analysis. Instead of a fixed timeout period, the system continuously monitors environmental factors, user activity patterns, and device state to dynamically adjust when relocking occurs, allowing extended periods when context indicates safety and immediate relocking when risk is detected, thereby optimizing both security and convenience

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback-based timeout control where contextual analysis continuously informs authentication decisions. The machine learning model analyzes user behavior patterns and environmental context to provide feedback on when relocking is appropriate, replacing static timeout settings with an adaptive system that learns from user habits and contextual changes to balance security and usability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9817957B1Access management based on active environment comprising dynamically reconfigurable sets of smart objects
Publication Date: 2017.11.14 EMC IP HLDG CO LLC
  • US9817957B1 patent drawing
  • US9817957B1 patent drawing
  • US9817957B1 patent drawing

AI summary

A processing device comprises a processor coupled to a memory and is configured to predict or otherwise determine that a user will utilize a target application on a user device in involvement with a particular set of smart objects, to request cryptographic material for activating the smart objects of the set, to receive the cryptographic material responsive to the request, and to utilize the cryptographic material to activate the smart objects. Each of the activated smart objects provides a verifier with a proof of involvement with the user device. The verifier controls user access to the target application based at least in part on the proofs provided by the activated smart objects. The determining, requesting, receiving and utilizing operations in some embodiments are performed by a learning agent running on the processing device. The learning agent illustratively includes functionality for learning target application access behavior of the user over time.