Automated Access Control Policy Verification Using Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control management in IT infrastructure is inefficient due to reliance on manual, sporadic, and error-prone methods, leading to inconsistent policy enforcement and vulnerabilities in complex, dynamic environments, particularly in cloud infrastructure where rapid changes and large scales make comprehensive verification impractical.

Innovation Solution

The implementation of a processor-implemented method using machine learning and AI techniques to normalize, visualize, and enforce access control policies across a distributed IT infrastructure, creating an access control graph to identify non-compliant policies and automate continuous verification and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If manual access control verification methods are used, then implementation simplicity is maintained, but verification comprehensiveness and security reliability deteriorate

Engineering Contradiction:
Improveaccess control management complexityVSAvoidaccess control verification reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces manual mechanical verification processes with an automated computer-implemented system that uses machine learning models to continuously analyze access control policies, entity relationships, and infrastructure configurations, thereby maintaining simplicity while dramatically improving verification reliability and comprehensiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service automation where the access control management system automatically performs continuous verification, policy analysis, and anomaly detection without requiring manual intervention, allowing the system to monitor and enforce its own security policies across the entire infrastructure

Inventive Principle:
Principle #25Self-service

2Use of energy by moving object

If sporadic manual reviews are conducted, then resource consumption is reduced, but security coverage and policy enforcement consistency worsen

Engineering Contradiction:
Improvecomputational resource consumptionVSAvoidsecurity policy enforcement reliability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent implements continuous automated verification that operates continuously across the entire IT infrastructure, constantly monitoring access control policies, entity relationships, and configuration changes to ensure consistent enforcement without gaps, thereby maintaining security reliability while using computational resources efficiently through automated processes

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If comprehensive automated verification is implemented, then security reliability and policy enforcement consistency improve, but system complexity and computational resource requirements worsen

Engineering Contradiction:
Improveaccess control verification reliabilityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex verification task into distinct functional components including machine learning model training, entity relationship analysis, policy configuration validation, and anomaly detection modules, allowing each component to specialize in specific aspects of access control verification while working together to provide comprehensive security coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary access control graph that represents entity relationships and access patterns in a structured format, serving as a mediator between raw infrastructure data and verification logic, thereby simplifying the complexity of analyzing complex access control policies and entity relationships

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If manual access control analysis is performed, then ease of operation is maintained, but verification speed and responsiveness to infrastructure changes worsen

Engineering Contradiction:
Improveaccess control management easeVSAvoidverification speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent replaces manual analysis operations with automated machine learning-based verification processes that continuously monitor and analyze access control policies, entity relationships, and infrastructure configurations at high speed, maintaining ease of operation through automated processes while dramatically improving verification speed and responsiveness to changes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11178182B2Automated access control management for computing systems
Publication Date: 2021.11.16 SAILPOINT TECHNOLOGIES INC
  • US11178182B2 patent drawing
  • US11178182B2 patent drawing
  • US11178182B2 patent drawing

AI summary

Normalized access control policies associated with entities in an information technology (IT) infrastructure comprising a plurality of subsystems may be obtained based on a stored access control policy representation governing access to resources in the IT infrastructure. Based on the normalized access control policies, entity clusters associated with the entities may be determined. Further, derived access control policies corresponding to the at least one entity cluster may be determined. A set of non-compliant access control policies may be determined where the set of non-compliant access control policies may comprise: a subset of the normalized access control policies that are non-compliant with stated access control policies applicable to the entity clusters, and/or a subset of the derived access control policies that are non-compliant with the stated access control policies. Machine learning and/or Artificial Intelligence techniques may be used to determine, maintain, and audit policies for the IT infrastructure.