A SYSTEM BASED ON AUTOMATIC UNIQUENESS OF CONSECUTIVE IDENTIFICATION FILES.

TR202615531A2Pending Publication Date: 2026-09-21TURKCELL TEKNOLOJI ARASTIRMA & GELISTIRME AS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202615531
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-09-10
Publication Date
2026-09-21

Smart Images

  • Figure 00000013_0000
    Figure 00000013_0000
Patent Text Reader

Abstract

This invention relates to a system (1) which includes a system for technically analyzing successive approval nodes with the same ID in dynamically generated approval chains relating to access requests and a normalization mechanism developed for automatically uniqueing them under certain conditions.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF AUTOMATIC VERSION OF CONSECUTIVE IDENTIFICATION CARD A SYSTEM BASED ON UNIFICATION Technical Area This invention is part of dynamically generated approval chains related to access requests. technical analysis of consecutive verification nodes with the same identity and specific a normalization developed for automatic deduplication under certain conditions A system that includes a mechanism is related to another system. Previous Technique In current identity and access management systems, approval chains are typically Automatic 15 based on organizational hierarchy and application ownership information. is being created. However, identity data comes from different source systems. Because of this, the same user can repeat in the chain with different identity domains, and this This situation creates unnecessary processing steps. This situation is in the workflow engine. Unnecessary state transitions, increased number of operations, proliferation of log records, and system issues. This leads to technical problems such as the unnecessary consumption of resources. 20 In the current state of the art, dynamic approval systems modify approval processes. It should include automated implementation based on organizational changes; approval easier structuring of processes and adaptation to changing conditions Creating accounts and environments on cloud platforms, which enables this to be highlighted 25 provisioning-focused functions such as methods that automate processes Various solutions are encountered that ensure its availability. 2 However, in the current state of the technology, users from different data sources the transformation of their identities into a single canonical identity, unified Compliance assessment is carried out to ensure scope of authorization matches and risk levels are the same. 5. The merging of two consecutive canonical identities when the following conditions are met, before the created confirmation chain is run for consecutive identical identities normalization, in addition to process automation, also includes dynamic approval assignments. No solution has been found that enables this to be done via data. United States Law No. US2005223413, which is included in the known state of the art. Methods for cross-domain security information transformation in patent documents, The invention in question provides systems and computer program products. Application examples included in the invention are in a security service, in a system. 15 from the existence of a system with an identity in at least one security domain. Obtaining security information in the local form of the first security area; security converting the information into a canonical format for security purposes; in canonical form security information transferred from a first security zone to a second security zone in advance Transformation using a defined mapping; transformed canonical the security information in the format is translated into the local format of the second security field and 20 security information returns to the system presence in the local form of the second security area It includes the steps of turning it. Some of the invention canonical transformed security information in regulations / applications Converting the format from the first security area to the local format of the second security area is a procedural software. This is done through the function. In some applications, the second local 25 The format is expressed in XML, the canonical format is expressed in XML, and transformed security information from canonical form to the second security area conversion to local form, from canonical form to local form of the second security area Depending on a predefined mapping expressed in the XSL is being carried out. 30 3 Brief Description of the Invention The aim of this invention is to consolidate user identities from different data sources into a single system. conversion to canonical identity, combined conformity assessment 5 This is done by matching the scope of authority, ensuring the same risk level, and verifying the agency status. provided that the conditions such as the absence of a violation of the separation of duties are met. the merging of two consecutive canonical identities over time, the resulting chain of approval normalization of the process before being run with consecutive identical identities In addition to automation, approval assignments can also be made via dynamic data. 10 a system that provides automatic uniqueness of consecutive identical approval IDs. The system performs this. Detailed Description of the Invention 15 The "Sequential Identical Confirmation" process was carried out to achieve the purpose of this invention. "A System Based on Automatic Uniqueness of Identities" is shown in the figure. and in this form; Figure 1: The subject of the invention is the automatic uniqueness of consecutive identical approval identifiers. It is a schematic view of a system based on [specific principles]. The parts shown in the figure are individually numbered, and the corresponding numbers correspond to these numbers. given below. 25 1. System 2. Database 3. Electronic devices 4. Application 30 4 5. Analytics server In dynamically generated approval chains for access requests, the same sequence occurs consecutively. Technical analysis of identity verification nodes and certain conditions 5 a normalization developed for automatic deduplication under the mechanism involving the automatic issuance of consecutive identical approval identifiers, which is the subject of the invention. a system based on singularization (1); - at least one that connects to the communication infrastructure available at a company, within the company The identities of the persons and managers found, and the 10 related persons and managers configured to store company-related service ownership information at least one database (2) - the user interacts with other people via at least one wired or wireless network. at least one electronic device configured to enable communication (2), 15 - electronic device (2) in which the user's database (2) is located enabling the company to connect with its communication infrastructure, via the interface on it. to enable the user to create an access request to the database (2) at least one application (4) and configured - connecting with the database (2), application (4), on which at least one data 20 collection layer, identity resolution module, confirmation chain generation engine, conformity assessment module, execution engine interface, audit matching data To run the repository and normalization engine, the user must use the application (4) to access the information about the access request it created, according to that access request information By connecting with the database (2) in the company’s communication infrastructure, 25 relevant organizational data, identities of individuals and / or managers within the company to ensure that information is retrieved from the database (2), retrieved from the database (2) Canonical data is created using personal information of individuals and managers within the company. by enabling the generation of personal identity and running the confirmation chain creation engine. 30 necessary approval nodes associated with requests transmitted from the application (4) to ensure its creation, related to the analysis of the relevant consecutive nodes to ensure the suitability of merging consecutive nodes, appropriate The consecutive nodes found are normalized by running the normalization engine to create a singular node. to ensure that the newly created chain is brought into the audit mapping data store configured to ensure that it is stored and transferred to the execution engine. It includes at least one analytics server (5). The database in the system that is the subject of the invention (1) is (2) the corporate directory in the firm personal and manager identification information obtained from services, human Personnel identification information obtained from service sources is listed on page 10. It is configured for storage. In the system that is the subject of the invention, the electronic device (3) included in (1) the user with other people mobile phones, tablets, computers, configured to enable communication, It is a smart device in the form of a 15 In the system subject to the invention, (1) analysis server (5) access transmitted from the application (4) In line with the request information, the person identity information obtained from the database (2) is unique. to ensure the transformation of identities into a single canonical identity, In the conversion, the person directory ID, employee number and service user 20 to enable the merging of keys It is being structured. The analysis server (5) generates the canonical identifier associated with each confirmation node. During this process, the transaction ID (Transaction_id) of the relevant approval nodes is canonical 25. user ID (canonical_user_id), service type, approval role (approval_role), authority_scope, timestamp, to ensure it includes fields in the form of source_system It is being structured. 6 The analysis server (5) sequentially receives the access request from the application (4) Even if two nodes share the same canonical ID, only scope of authority matching increases the risk. having the same level, absence of a proxy situation, violation of separation of duties. When the conditions such as the absence of these two consecutive items are met, It is configured to enable node merging. Analysis server 5 (5) Identity of consecutive nodes in accordance with the access request transmitted from the application (4), to enable comparison with role and authority scope parameters It is being structured. Analysis server (5) matches 10 access requests transmitted from application (4) running the node merging suitability assessment, appropriate to enable the nodes found to be combined under a single node It is being structured. The analysis server (5) will respond to the access request transmitted from the application (4) in accordance with the appropriate 15 After the nodes found are combined under a single node, the reference metadata such as links, audit logs and transaction status are being re-evaluated. It is structured to enable its creation. Analysis server (5) 20 in accordance with the access request transmitted from application (4) to ensure that the merged nodes cannot be deleted from the database (2), original node IDs in a traceability table in the database (2) to ensure it is stored and associated with the normalized node, transferring the normalized approval chains to the execution engine It is structured to provide. 25 7 Industrial application of the invention In the system that is the subject of the invention, (1) the person in the firm's electronic device (2) application (4) is being run. Thanks to the application (4), the person requests access to the database (2) 5 It enables the creation of an access request. The access request information created by the individual is analyzed. The access request created by the person is transmitted to the server (5). The data is transmitted to the data collection layer (5) on the server. This layer is the relevant organizational layer. It receives data from different source services. Identity resolution on the analysis server (5) The module uses this data to generate a canonical user ID. Analysis 10 The approval chain creation engine on the server (5) requires approval for the request. It creates the nodes. Then, the suitability assessment (5) on the analysis server. The module determines the suitability of joining by analyzing consecutive nodes. Suitable Nodes found are singled by the normalization engine (5) on the analysis server. It is converted into a new state. The newly created chain is stored in the control mapping data store and 15 It is transferred to the execution engine (5) on the analysis server. The invention system (1) allows the collection of user identities from different data sources. conversion to a single canonical identity, unified conformity 20 By conducting an assessment, the scope of authority is matched, and the risk level is the same. the absence of a proxy situation, and the absence of a violation of the separation of duties. When the conditions are met, the combination of two consecutive canonical identities is created. normalize the confirmation chain before running it for consecutive identical identities. In addition to process automation, approval assignments are also made using dynamic data. 25 This is ensured through [the system / method]. The system in question (1) is within the scope of the Personal Data Protection Law (KVKK). It operates. 30 8 The invention is based on the automatic uniqueness of successive identical approval identifiers. It is possible to develop a wide variety of applications of the system (1), and the invention is here It cannot be limited to the examples given; it is essentially as stated in the claims.

Claims

9 REQUESTS 1. Sequential in dynamically generated approval chains for access requests. technical analysis of verification nodes belonging to the same identity and specific a normalization developed for automatic deduplication under certain conditions 5 including the mechanism; - at least one that connects to the communication infrastructure available at a company, within the company the personal information of the individuals and managers involved, and the relevant individuals and managers. configured to store company-related service ownership information 10 containing at least one database (2) - the user interacts with other people via at least one wired or wireless network. at least one electronic device configured to enable communication (2), - electronic device (2) in which the user's database (2) is located enabling the company to connect with its communication infrastructure, via the interface on it 15 to enable the user to create an access request to the database (2) at least one application (4) and configured - connecting with the database (2), application (4) and having at least one data collection layer, identity resolution module, confirmation chain generation engine, conformity assessment module, execution engine interface, audit matching data 20 To run the repository and normalization engine, the user must use the application (4) to access the information about the access request it created, according to that access request information By connecting with the database (2) in the company’s communication infrastructure, the company relevant organizational data, identities of individuals and / or managers within the company to ensure that information is retrieved from the database (2), 25 retrieved from the database (2) Canonical data is created using personal information of individuals and managers within the company. by enabling the generation of personal identity and running the confirmation chain creation engine. necessary approval nodes associated with requests transmitted from the application (4) to ensure its creation, related to the analysis of the relevant consecutive nodes To ensure the suitability of merging consecutive nodes, appropriate 30 The consecutive nodes found are normalized by running the normalization engine to create a singular node. to ensure that the newly created chain is brought into the audit mapping data store the most configured to ensure its storage and transfer to the execution engine consecutive identical confirmation characterized by at least one analysis server (5) a system based on automatic unduplication of identities (1). 5 2. Personal and managerial information obtained from the company's corporate directory services. identification information, personnel IDs obtained from human resources services characterized by the database (2) which is structured to store its information. Automatic uniqueness of consecutive identical approval IDs as in Request 1 is required. a system based on (1).

3. Mobile devices configured to allow the user to communicate with other people. electronic device (3) which is a smart device such as phone, tablet, computer 15 consecutive identical confirmation IDs as characterized in Claim 1 or 2 a system based on automatic deduplication (1).

4. Based on the access request information transmitted from the application (4), from the database (2) to ensure that the personal identification information it obtains is converted into a single canonical identity, In the conversion of identities into a single canonical identity, the personal directory identity, personnel 20 the process of merging number and service user keys Characterized by the analysis server (5) configured to enable its integration. The same consecutive approval as in any of the above requests a system based on automatic unduplication of identities (1).

5. During the generation of the canonical identifier associated with each confirmation node, the confirmation in question... Transaction ID of nodes, canonical user ID (canonical_user_id), service_type, approval_role, authorization scope (authority_scope), timestamp, source system The analysis is structured to include fields in the form of (source_system) 30 11 as in any of the above requests characterized by its server (5) a system based on automatic uniqueness of consecutive identical approval IDs (1).

6. In accordance with the access request transmitted from the application (4), two consecutive nodes are the same. Even if it carries the canonical identity, a mere scope of authority match means the risk level is the same as 5. the absence of a proxy situation, and the absence of a violation of the separation of duties. When the conditions in this form are met, the two consecutive nodes in question Characterized by the analysis server (5) configured to enable its integration. The same consecutive approval as in any of the above requests a system based on automatic unduplication of identities (1). 10 7. In accordance with the access request transmitted from the application (4), the identity of the consecutive nodes, to enable comparison with role and authority scope parameters from the above requests characterized by the configured analysis server (5) Automatic uniqueness of consecutive identical confirmation IDs, as in any of them, 15 a system based on (1).

8. Regarding the matching nodes in accordance with the access request transmitted from the application (4). the execution of the integration suitability assessment, if found suitable 20 configured to allow nodes to be combined under a single node any of the above requests characterized by the analysis server (5) one based on the automatic uniqueness of consecutive identical approval IDs, like in one system (1).

9. Nodes found suitable in accordance with the access request transmitted from the application (4) 25 After being combined under a single node, the reference links are controlled. reconstruction of metadata in the form of records and transaction status characterized by the analysis server (5) configured to provide consecutive identical approval IDs as in any of the above requests a system based on automatic deduplication (1). 30 12 10. Nodes combined in accordance with the access request transmitted from the application (4) to ensure that the original node IDs cannot be deleted from the database (2). to be stored in a traceability table in the database (2) and normalized to ensure association with the node, normalized confirmation chains 5 analysis configured to ensure it is passed to the execution engine on it as in any of the above requests characterized by its server (5) a system based on automatic uniqueness of consecutive identical approval IDs (1).