Zero Trust Access Control via Binary and Discreet Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems and methods for authentication and access control are not comprehensive and are case-specific, failing to address all potential threats effectively.

Innovation Solution

A zero-trust access control method that determines the operational state of computer systems, converts this data into attributes, and applies them to a binary decision model for preventive measures and a secondary discreet model for detective measures, ultimately comparing scores to an access threshold for approval or denial.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current cryptography and access control systems are used, then security measures are implemented, but they are not comprehensive and fail to address all potential threats

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidthreat coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a multi-layered access control system that combines binary decision models for preventive measures with discreet score-based models for detective measures. This universal system handles multiple threat types (malicious insiders, external attackers, compromised credentials) through a single comprehensive framework that evaluates various attributes including user behavior, device state, and environmental context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access control system is divided into distinct segments: a binary decision model that outputs access approval/denial decisions, and a secondary discreet model that outputs risk scores. Each segment handles specific aspects of security evaluation, with the binary model addressing preventive control and the discreet model addressing detective analysis, together providing comprehensive threat coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a comprehensive access control system is implemented, then all potential threats are addressed, but system complexity increases

Engineering Contradiction:
Improvesecurity comprehensivenessVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides complex security evaluation into manageable segments: attribute extraction from operational data, binary decision-making for access control, and discreet score-based risk assessment. Each segment performs a specific function, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including attribute extraction mechanisms that translate operational data into standardized attributes, and decision models that mediate between raw data and access control decisions. These intermediaries simplify the system architecture by providing structured interfaces between different security evaluation layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time algorithms are used for score-based and attribute-based access control, then security reliability is enhanced, but computational resources increase

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The computational workload is segmented into attribute extraction (processing operational data into standardized attributes), binary decision-making (computationally efficient access approval/denial decisions), and discreet score-based assessment (detailed risk scoring). This segmentation allows real-time processing with optimized resource allocation at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary attribute extraction and binary decision-making before conducting detailed discreet score-based assessment. This preliminary action filters out obvious cases early, reducing the computational resources needed for comprehensive analysis while maintaining high security reliability through multi-layered evaluation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250156570A1Zero trust access algorithms
Publication Date: 2025.05.15 MERABET ABDEL AZIZ
  • US20250156570A1 patent drawing
  • US20250156570A1 patent drawing
  • US20250156570A1 patent drawing

AI summary

A method includes converting the data into attributes. The method includes applying the attributes to a binary decision model. The binary decision module is configured to output a first access approval or a first access denial based on one more preventive measures decision algorithms. The method includes, in response to the binary decision model outputting a first approval, applying the data to a secondary discreet model. The secondary discreet model is configured to output a score based on one or more detective measures algorithms. The method includes comparing the score to an access threshold. The method includes outputting a second access approval or a second access denial based on comparing the score to the access threshold.