Trust Measure-Based Self-Service Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access management in corporate information systems is rigid and lacks self-service capabilities, requiring employees to manually request access to resources, which is inefficient and time-consuming.

Innovation Solution

Implementing a method that determines a user's trust measure based on logged communication events across multiple platforms and applies a self-service access policy to automatically grant or deny access to content, ensuring secure and efficient access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual access request process is used, then security control is maintained, but access efficiency deteriorates

Engineering Contradiction:
Improveaccess efficiencyVSAvoidtime for access request
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables users to autonomously request and obtain access to resources through self-service portals without manual intervention from IT staff. Users can initiate access requests, upload credentials, and receive automated decisions based on pre-configured policies, eliminating the need to email or call support centers and significantly reducing access time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access policies, trust thresholds, and approval workflows are pre-configured before users need access. The system maintains pre-approved credential lists and policy rules that enable rapid automated decision-making when access requests are submitted, avoiding the need for real-time manual security reviews.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated access decision is implemented, then access efficiency is improved, but security control may deteriorate

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system continuously monitors user behavior, access patterns, and credential validity, feeding this information back into trust measure calculations. This dynamic feedback loop allows the automated system to adapt to changing security conditions and user reliability, maintaining security control while enabling automation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts trust thresholds and access permissions based on changing parameters such as user behavior history, current security context, and resource sensitivity. This allows the automated system to maintain appropriate security control by adjusting parameters in real-time rather than using fixed rigid rules.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If trust measure analysis is performed, then access security is enhanced, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a universal trust measure framework that can evaluate multiple user attributes (communication behavior, access patterns, credential history) through a single integrated analysis mechanism. This multi-functional approach enhances security without proportionally increasing complexity, as the same infrastructure handles diverse trust assessment requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10140466B1Systems and methods of secure self-service access to content
Publication Date: 2018.11.27 QUEST SOFTWARE INC
  • US10140466B1 patent drawing
  • US10140466B1 patent drawing
  • US10140466B1 patent drawing

AI summary

In one embodiment, a method is performed by a computer system. The method includes receiving a request from a user to access particular content. The method further includes determining a trust measure of the user, wherein the trust measure is based, at least in part, on an analysis of logged user-initiated communication events of the user on a plurality of communications platforms. In addition, the method includes accessing a self-service access policy applicable to the particular content. Further, the method includes ascertaining, from the self-service access policy, a trust threshold applicable to the particular content. Moreover, the method includes, responsive to a determination that the trust measure fails to satisfy the trust threshold, automatically denying access by the user to the particular content.