Assigning privileges in an access control system

Inventors

Sanders, Matthew WestinYue, Chuan

Assignees

Colorado School of Mines

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11470122-B2

Patent

Publication Date

2022-10-11

Expiration Date


Abstract

An access control system may include a log data parser that receives log data observations in a cloud system and extract user-permission data from the log data observations. The system may also include a clustering unit that uses the user-permission data to generate one or more clusters, each cluster associated with one or more users. Alternatively, and/or additionally, the system may include a feature extractor and a classifier. The feature extractor may extract one or more features from the user-permission data. The classifier may generate predictions of permissions for the one or more users based on the extracted one or more features. The system may also include a policy generator that uses the output of the clustering unit and/or the classifier to generate an access control policy. The policy may be executed in the cloud system to control user's access to one or more services of the system.

Core Innovation

An access control system receives log data observations recorded in a cloud system and extracts user-permission data from the log data observations, where the observations include one or more user actions performed by one or more users in the cloud system. The system extracts one or more features from the user-permission data and generates predictions of permissions for the one or more users based on the extracted features, where each prediction includes one or more permissions associated with each user.

Using the predictions of permissions, the system generates one or more clusters and associates each cluster with the one or more users. The system then generates an access control policy by assigning permissions to each cluster, thereby deriving a policy from observed log data and permission predictions rather than using only static permission information.

In a related approach, the system generates access control policies based on at least one of the predictions of permissions, receives a request from a user device associated with a user, and executes the access control policy to determine whether to grant the request based on a permission of the user associated with the user device. The approach can further include classifier training and evaluation workflows that compare first permissions with first predictions across operation periods and compute precision, recall, and an F measure.

Claims Coverage

The independent claims cover four core aspects: extracting user-permission data from cloud log observations, deriving permissions via feature extraction and classifier-generated permission predictions, clustering users based on the predictions to generate cluster-based policy assignments, and executing the resulting policy to determine whether to grant requests for cloud services. The independent claims also cover variants where the policy is generated based on at least one set of permission predictions and includes classifier training and evaluation across operation periods.

Cloud log parsing for user-permission data extraction

The log data parser is configured to receive log data observations in a cloud system and extract user-permission data from the log data observations, wherein the log data observations include one or more user actions performed by one or more users in the cloud system.

Feature extraction from user-permission data

The feature extractor is configured to extract one or more features from the user-permission data.

Classifier-generated permission predictions from features

The classifier is configured to generate predictions of permissions for the one or more users based on the extracted one or more features, wherein each prediction includes one or more permissions associated with each of the one or more users.

Cluster generation from permission predictions

The clustering unit is configured to cause the processor to use the predictions of permissions to generate one or more clusters.

Cluster-based access control policy by assigning permissions

The policy generator is configured to cause the processor to generate an access control policy by associating each cluster to the one or more users and assigning permissions to each cluster.

Request-time policy execution for grant determination

Executing the access control policy to determine whether to grant the request based on a permission of the user associated with the user device.

Access control policy generation based on predicted permissions

Generating an access control policy based on at least one of the predictions of permissions for the one or more users.

Training the classifier using training log data

A training network that receives training log data from users' cloud system actions, extracts training user-permission data and training features from it, and uses the extracted features to train a classifier.

Two operation-period permission prediction comparison

Determining user permissions and permission predictions for a first operation period, comparing them, and then determining updated permission predictions for a second operation period based on the comparison.

Precision/recall evaluation and F measure

Comparing first predictions with first permissions from the first operation period by determining precision and recall and computing an F measure from precision and recall.

Across the independent claims, the inventive core centers on deriving user-permission information from cloud log observations, transforming it into features, using a classifier to generate permission predictions, and then producing an access control policy, including cluster-based assignment, that is executed to determine whether to grant service requests. Additional independent-claim coverage supports policy generation from predicted permissions and classifier training and evaluation using permission/prediction comparisons and metrics.

Stated Advantages

Generates an access control policy by associating clusters to users and assigning permissions to each cluster.

Executes the access control policy to determine whether to grant a request based on a permission of the user.

Provides evaluation of prediction quality using precision and recall and computing an F measure.

Documented Applications

Controlling access in a cloud system by receiving log data observations and using an access control policy to grant or deny access requests received from a user device.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.