Automated Policy Generation from Static Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing physical access control systems rely on static permissions, which require manual administrative tasks for updates, leading to inefficiencies and risks of incorrect permission records, and are incompatible with dynamic rule-based policies, making it impractical to transition to a system capable of real-time access processing.

Innovation Solution

A system and method that generates rule-based policies from static permissions using a processor to analyze static permission records, incorporating pattern mining and metrics analysis to create policies that include user, resource, and environment properties, allowing for automated and robust policy generation without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual administrative tasks are used to manage static permissions, then the system maintains simplicity and compatibility with existing architectures, but it consumes time and introduces the risk of incorrect permission records

Engineering Contradiction:
Improveaccuracy of permission recordsVSAvoidtime for administrative tasks
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically generates rule-based policies by analyzing access event data and static permission records without requiring manual administrative intervention. The processor autonomously identifies patterns in access events and translates them into policies, eliminating the need for manual permission management while ensuring accuracy through data-driven analysis

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual administrative operations are replaced with an automated processing system that uses a processor to analyze access events and generate policies. This substitution transforms the mechanical process of manual permission management into an automated computational process, reducing both time consumption and human error

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If rule-based policies are implemented for dynamic processing of access requests, then the system improves adaptability and reduces manual effort, but it requires a complex system architecture incompatible with existing physical access control systems

Engineering Contradiction:
Improvedynamic access control capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system separates policy generation from policy execution. The complex rule-based policy generation process is segmented from the simpler policy enforcement process. Static permissions are analyzed offline to generate policies, which are then stored and executed by the existing access control system without requiring real-time rule engine complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Rule-based policies are generated in advance by analyzing historical access event data and static permission records. This preliminary action creates a policy set that captures dynamic access patterns, which can then be enforced by the existing system without requiring real-time dynamic processing capability

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual creation of rule-based policies from static permissions is performed, then the system maintains control and accuracy, but it becomes costly and impractical for large-scale systems

Engineering Contradiction:
Improvepolicy accuracyVSAvoidpolicy generation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

Manual policy creation is replaced with automated analysis of access event data by a processor. The system systematically examines access patterns and translates them into rule-based policies, maintaining accuracy through data-driven analysis while achieving high efficiency through automation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system self-generates policies by autonomously analyzing access event logs and static permission records. This self-service capability eliminates the need for manual policy creation while ensuring accuracy through systematic pattern recognition and rule generation algorithms

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10430594B2Extraction of policies from static permissions and access events for physical access control
Publication Date: 2019.10.01 HONEYWELL INTERNATIONAL INC
  • US10430594B2 patent drawing
  • US10430594B2 patent drawing
  • US10430594B2 patent drawing

AI summary

A system for generating at least one policy includes a static permission database containing a plurality of static permission records identifying access permissions for at least one credential holder to at least one resource, a policy database, and a processor to analyze the plurality of static permission records to generate the at least one policy, wherein an outcome of execution of the at least one policy corresponds to the plurality of static permission records.