Automated Time-Based Access Enforcement for Computing Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems lack an automated method to synchronize and enforce time-based user access levels across different computing systems and infrastructures, leading to security breaches, data loss, and compliance issues due to inadequate management of access rules based on employee status, roles, and tasks.
Innovation Solution
A cloud or on-premises computing system that utilizes a review management system to synchronize and enforce time-based user access levels by using unique identifiers, position IDs, and employment status IDs to determine and adjust access permissions based on predefined rules, ensuring that access is revoked or provided according to the current employment status and last login timestamp.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual access management is used to delegate access to computing services, then ease of operation is improved, but reliability deteriorates due to compliance and security issues
Solution Approach 1:
The system implements automated self-service access management where the computing system automatically reviews, synchronizes, and enforces time-based access levels across multiple infrastructures without requiring manual intervention. The system autonomously identifies users, evaluates their employment status and position, and adjusts access permissions according to predefined rules, eliminating the need for continuous manual access management while ensuring compliance and security requirements are met
Solution Approach 2:
The system incorporates continuous feedback mechanisms by periodically reviewing user access levels, comparing current employment status against predefined access rules, and automatically adjusting permissions. The system monitors user activity, tracks employment status changes, and provides real-time feedback to maintain appropriate access levels, ensuring that access management remains reliable and compliant without manual intervention
2Reliability
If automated time-based access enforcement is implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The system implements a universal automated access enforcement mechanism that operates across multiple computing infrastructures, cloud and on-premises systems, and various applications simultaneously. The single automated enforcement system performs multiple functions including user identification, employment status verification, access rule evaluation, and permission adjustment across diverse systems, reducing the need for separate access management solutions for each infrastructure while maintaining high reliability
Solution Approach 2:
The system manages complexity by dynamically changing access level parameters based on user attributes such as employment status, position, and time-based rules. Rather than implementing complex structural changes across systems, the system modifies access permission parameters automatically according to predefined rules, allowing reliable access management through parameter adjustment rather than system restructuring
3Object-affected harmful factors
If periodic review of user access levels is conducted, then security is improved, but loss of time increases due to synchronization requirements
Solution Approach 1:
The system implements periodic automated review of user access levels at scheduled intervals across all computing infrastructures. Rather than continuous real-time monitoring that would consume excessive time, the system performs synchronized access level reviews at defined periodic intervals, automatically evaluating user employment status and adjusting permissions accordingly. This periodic action maintains security by regularly enforcing access rules while minimizing time loss through efficient batch processing and synchronization mechanisms
Data Source
AI summary
A system is provided for enforcing time-based user access levels in a computing infrastructure of an organization. The system includes a processor and a computer readable medium operably coupled thereto, to perform operations which include executing a synchronization of the time-based user access levels, obtaining a first login identifier (ID) of a plurality of login IDs for a group of employees of the organization, identifying a position ID and an employment status ID for the first login ID, determining a current time and a last login timestamp for the first login ID, determining a time-based access rule for the group of employees, determining whether a time period from the last login timestamp to the current time violates the time-based access rule, and setting, for the synchronization of the first login ID, at least a first access level of the first login ID to computing resources.


