Trust-Based Dynamic Access Control for Granular Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networks face challenges in managing user access to network resources due to increased risk from broad access via VPNs, complex network management, and lack of client control over authorization processes, especially in distributed environments, leading to poor user experience and inefficient policy updates.

Innovation Solution

A dynamic access control system (DACS) that enables clients to define custom access policies based on trust information from multiple sources, including directly connected and out-of-band trust providers, and utilizes a trust broker and policy engine to manage fine-grained network access and routing, allowing clients to integrate their security data into the authentication and authorization process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If broad network access via VPN is provided to support distributed operations, then network connectivity and user access capability are improved, but security risk and system vulnerability increase

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network into multiple network segments and divides access control into granular policies. Instead of providing broad VPN access to the entire network, users are assigned access to specific network segments based on their roles and trust levels. This segmentation allows distributed operations while limiting the attack surface and security risk exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different access control policies to different network segments and resources. Each resource or network segment has customized access requirements and trust criteria. This allows the system to provide appropriate access levels locally rather than uniform broad access, maintaining security while enabling necessary connectivity.

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional VPN-based access control is used, then network connectivity is maintained, but policy update efficiency and client control capability deteriorate

Engineering Contradiction:
Improvenetwork connectivityVSAvoidpolicy update efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access control policies that can be updated in real-time without requiring VPN reconfiguration or network changes. The policy engine allows administrators to modify access policies dynamically, and changes are immediately enforced. This maintains reliable network connectivity while dramatically improving policy update efficiency compared to static VPN-based systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a policy engine as an intermediary between the network infrastructure and access control requirements. This intermediary layer handles policy evaluation and enforcement independently of the underlying network connectivity mechanism. Administrators can update policies through this intermediary without affecting network stability, enabling efficient policy management while maintaining reliable connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If centralized authorization control is implemented, then security management is simplified, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improveauthorization managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal trust evaluation framework that works across multiple network segments, resources, and authentication methods. The same policy engine and trust evaluation mechanisms are used throughout the system regardless of the specific resource or access method. This provides simplified centralized authorization management while avoiding the complexity of implementing separate control systems for different scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables self-service authentication and authorization where clients can independently evaluate trust criteria and obtain access tokens without complex centralized intervention. The policy engine provides self-service capabilities for policy evaluation, and clients can autonomously determine their access rights based on published policies. This simplifies authorization management while reducing the operational complexity of centralized control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12425409B2Trust-based dynamic access control system
Publication Date: 2025.09.23 AMAZON TECH INC
  • US12425409B2 patent drawing
  • US12425409B2 patent drawing
  • US12425409B2 patent drawing

AI summary

Systems and methods are provided for creating and running an instance of a dynamic access control system (DACS). Trust providers may be defined in a trust broker of the DACS such that trust information associated with the trust providers can be used to create a custom data structure. Resources and resource groups may be defined in the DACS. Policies may be configured or coded in the DACS to map the custom data structure to recourses or resources groups. Additionally, policies may be configured or coded in the DACS to route the data structure and request to network segments or shared with other parties.