Access Credential Discovery and Analysis for Third-Party Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in mitigating risks associated with accessing third-party computing systems, including data breaches and unauthorized access, due to difficulties in managing and tracking access permissions across multiple third-party systems.
Innovation Solution
A method involving querying and analyzing access credentials, classifying permissions, inspecting access logs, and generating mappings of potential and actual data transfers to identify unused permissions and facilitate responsive actions, such as rescinding access credentials, to reduce data loss risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access credentials are granted to third-party computing systems to enable computing functionality, then system functionality and versatility are improved, but data security and risk of unauthorized access worsen
Solution Approach 1:
The patent introduces an intermediary system that sits between the entity computing system and third-party systems. This intermediary discovers, analyzes, and monitors access credentials and data transfers, acting as a mediator that enables third-party functionality while maintaining security oversight and controlling risk exposure.
Solution Approach 2:
The system continuously monitors access logs and data transfers, providing feedback about actual usage patterns. This feedback mechanism allows the entity to adjust access credentials and permissions based on real-world behavior, enabling the system to adapt to changing security needs while maintaining both functionality and security.
2Adaptability or versatility
If access credentials are granted to multiple third-party computing systems, then system functionality is improved, but complexity of managing and tracking access permissions worsens
Solution Approach 1:
The patent segments the complex management of multiple third-party access credentials into distinct functional components: credential discovery, permission classification, access log inspection, and data transfer mapping. This segmentation organizes the complexity into manageable analytical steps that automatically process each third-party system's access rights.
Solution Approach 2:
The system performs self-service analysis by automatically discovering credentials, classifying permissions, and monitoring access patterns without requiring manual intervention. The computational processes autonomously manage the complexity of tracking multiple third-party systems, eliminating the need for manual security administration.
3Object-affected harmful factors
If comprehensive access monitoring is implemented to track data transfers, then data security is improved, but computational resources and processing time worsen
Solution Approach 1:
The patent applies partial action by focusing monitoring on specific high-value targets such as classified data objects and critical access credentials rather than attempting to monitor all system activity uniformly. This selective monitoring approach maintains effective security while reducing the computational overhead and processing time required for comprehensive analysis.
Data Source
AI summary
In various aspects, a data transfer discovery and analysis system may query an entity computing system to identify access credentials for third-party computing systems and scan each access credential to determine associated permissions provided by each access credential on the entity computing system. The data transfer discovery and analysis system may further inspect access logs to identify actual data transfers between the entity computing system and third-party computing systems as well as other access activity associated with each of the credentials. The system can generate and store a mapping of all actual data transfers (e.g., based on the access log data) and potential data transfers (e.g., based on particular access permissions) between/among the entity computing system and the third-party computing systems. By analyzing access logs to determine actual data transfers executed under each particular access credential, the data transfer discovery and analysis system can identify unused and/or underutilized access permissions.


