User Access Risk Scoring for Distributed Data Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively assess and manage the risk associated with user access to sensitive data resources in complex, distributed environments, particularly in virtualization-based cloud environments, where vulnerabilities are often overlooked, leading to potential data theft or misuse.

Innovation Solution

An Information Handling System (IHS) that calculates a risk score for user access based on resource risk weights and access permissions, enabling responsive actions such as additional authentication, monitoring, or permission changes in response to security events, and providing real-time risk assessment and automated response mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (virus scanning, password requirements) are deployed, then basic security coverage is improved, but comprehensive security against distributed environment vulnerabilities is not achieved

Engineering Contradiction:
Improvesecurity coverageVSAvoidenvironment coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal risk assessment mechanism that functions across diverse distributed environments including cloud infrastructure, virtualization platforms, and hybrid architectures. The system evaluates multiple risk factors (user permissions, resource sensitivity, access patterns) simultaneously to provide comprehensive security coverage that adapts to various deployment scenarios without requiring environment-specific configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If detailed security monitoring is implemented across all users and resources, then security assessment accuracy is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring system into modular components: risk factor identification modules, weight assignment modules, and score calculation modules. Each component handles specific aspects of risk assessment independently, allowing the system to maintain high measurement precision through detailed monitoring while reducing overall system complexity through modular architecture and independent processing units

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts risk assessment parameters including factor weights and thresholds based on organizational policies, resource sensitivity levels, and observed access patterns. This parameter flexibility allows the system to maintain accurate risk measurement without requiring complex hard-coded rules, as parameters can be modified through configuration rather than system redesign

Inventive Principle:
Principle #35Parameter changes

3Productivity

If real-time risk assessment and responsive actions are implemented, then incident response efficiency is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveincident response efficiencyVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary risk factor identification and weight assignment during system initialization and policy configuration phases. Risk assessment models and decision rules are pre-computed and cached, allowing the system to perform rapid real-time evaluations by simply applying pre-established criteria to current access requests, thereby maintaining high incident response efficiency with minimal processing delay

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12470589B2Systems and methods for risk assessment of user accesses to data resources
Publication Date: 2025.11.11 DELL PROD LP
  • US12470589B2 patent drawing
  • US12470589B2 patent drawing
  • US12470589B2 patent drawing

AI summary

Systems and methods for risk assessment of user accesses to data resources are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor; and a memory coupled to the processor, where the memory includes program instructions store thereon that, upon execution by the processor, cause the IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources; and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user, a risk score for the user that represents a level of security impact of the user on the plurality of resources.