Vertically Integrated Access Control for Flagged Capability Combinations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current resource access managers struggle to determine entity capabilities enabled by user entitlements and identify flagged combinations, which can lead to separation of duties conflicts and unauthorized actions.
Innovation Solution
A vertically integrated access control system that links entity capabilities with computing resources and access control rules in a database, enabling the identification and remediation of flagged combinations by managing user entitlements and forming tailored access units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current resource access managers are used to manage user entitlements, then basic access control is provided, but the system cannot determine entity capabilities enabled by user entitlements or identify flagged combinations, leading to separation of duties conflicts and unauthorized actions
Solution Approach 1:
The system segments access control into distinct layers: user entitlements, access control rules, entity capabilities, and flagged combinations. Each layer is independently managed and evaluated, allowing the system to track specific capability combinations without overwhelming complexity. The segregation of duties framework divides responsibilities among different user roles, preventing any single user from having conflicting capabilities.
Solution Approach 2:
The patent introduces an intermediary access control system that sits between users and computing resources. This intermediary evaluates user entitlements against access control rules, determines resulting entity capabilities, and identifies flagged combinations before allowing access. This mediator layer provides the additional security functionality without requiring complete redesign of existing resource access managers.
2Reliability
If the system continuously monitors and evaluates user entitlements to prevent flagged combinations, then information security is enhanced, but the computational overhead and system complexity increase
Solution Approach 1:
The system performs preliminary evaluation of user entitlements and access control rules before granting access. By pre-determining entity capabilities and checking for flagged combinations in advance, the system avoids continuous real-time monitoring during operations. This upfront assessment reduces computational overhead during actual access operations while maintaining security.
Solution Approach 2:
The patent creates a virtual model or copy of the access control evaluation process that can be pre-computed and stored. Instead of continuously monitoring and re-evaluating all entitlements, the system uses pre-computed capability assessments and flagged combination checks, reducing the computational burden during runtime while maintaining security enforcement.
Data Source
AI summary
A vertically integrated access control system may store in a database data records corresponding to the interfaces, access control rules, and computing resources of an information system, as well as data records for entity capabilities. Data records for related interfaces, access control rules, computing resources, and entity capabilities may be linked. Using the database, the system may determine the entity capabilities that can be performed based on an existing user entitlement. If the entity capabilities include a flagged combination of entity capabilities, the system may perform an information security action to remediate the flagged combination. The system may use the database to form vertically integrated access units. The vertically integrated access units may be used to form user entitlements. The system may continuously monitor whether any proposed configurations would create a flagged combination of entity capabilities, and if so take an action to prevent such flagged combination.


