Vertically Integrated Access Control for Flagged Capability Combinations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current resource access managers struggle to determine entity capabilities enabled by user entitlements and identify flagged combinations, which can lead to separation of duties conflicts and unauthorized actions.

Innovation Solution

A vertically integrated access control system that links entity capabilities with computing resources and access control rules in a database, enabling the identification and remediation of flagged combinations by managing user entitlements and forming tailored access units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current resource access managers are used to manage user entitlements, then basic access control is provided, but the system cannot determine entity capabilities enabled by user entitlements or identify flagged combinations, leading to separation of duties conflicts and unauthorized actions

Engineering Contradiction:
Improveinformation securityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments access control into distinct layers: user entitlements, access control rules, entity capabilities, and flagged combinations. Each layer is independently managed and evaluated, allowing the system to track specific capability combinations without overwhelming complexity. The segregation of duties framework divides responsibilities among different user roles, preventing any single user from having conflicting capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system that sits between users and computing resources. This intermediary evaluates user entitlements against access control rules, determines resulting entity capabilities, and identifies flagged combinations before allowing access. This mediator layer provides the additional security functionality without requiring complete redesign of existing resource access managers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system continuously monitors and evaluates user entitlements to prevent flagged combinations, then information security is enhanced, but the computational overhead and system complexity increase

Engineering Contradiction:
Improveaccess control securityVSAvoidcomputational resources consumed
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary evaluation of user entitlements and access control rules before granting access. By pre-determining entity capabilities and checking for flagged combinations in advance, the system avoids continuous real-time monitoring during operations. This upfront assessment reduces computational overhead during actual access operations while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a virtual model or copy of the access control evaluation process that can be pre-computed and stored. Instead of continuously monitoring and re-evaluating all entitlements, the system uses pre-computed capability assessments and flagged combination checks, reducing the computational burden during runtime while maintaining security enforcement.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10824754B2Vertically integrated access control system for identifying and remediating flagged combinations of capabilities resulting from user entitlements to computing resources
Publication Date: 2020.11.03 BANK OF AMERICA CORP
  • US10824754B2 patent drawing
  • US10824754B2 patent drawing
  • US10824754B2 patent drawing

AI summary

A vertically integrated access control system may store in a database data records corresponding to the interfaces, access control rules, and computing resources of an information system, as well as data records for entity capabilities. Data records for related interfaces, access control rules, computing resources, and entity capabilities may be linked. Using the database, the system may determine the entity capabilities that can be performed based on an existing user entitlement. If the entity capabilities include a flagged combination of entity capabilities, the system may perform an information security action to remediate the flagged combination. The system may use the database to form vertically integrated access units. The vertically integrated access units may be used to form user entitlements. The system may continuously monitor whether any proposed configurations would create a flagged combination of entity capabilities, and if so take an action to prevent such flagged combination.