Access Credential Discovery and Analysis for Third-Party Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in mitigating risks associated with accessing third-party computing systems, including data breaches and unauthorized access, due to difficulties in managing and tracking access permissions across multiple third-party systems.

Innovation Solution

A method involving querying and analyzing access credentials, classifying permissions, inspecting access logs, and generating mappings of potential and actual data transfers to identify unused permissions and facilitate responsive actions, such as rescinding access credentials, to reduce data loss risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access credentials are granted to third-party computing systems to enable computing functionality, then system functionality and versatility are improved, but data security and risk of unauthorized access worsen

Engineering Contradiction:
Improvecomputing functionalityVSAvoiddata breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system that sits between the entity computing system and third-party systems. This intermediary discovers, analyzes, and monitors access credentials and data transfers, acting as a mediator that enables third-party functionality while maintaining security oversight and controlling risk exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system continuously monitors access logs and data transfers, providing feedback about actual usage patterns. This feedback mechanism allows the entity to adjust access credentials and permissions based on real-world behavior, enabling the system to adapt to changing security needs while maintaining both functionality and security.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If access credentials are granted to multiple third-party computing systems, then system functionality is improved, but complexity of managing and tracking access permissions worsens

Engineering Contradiction:
Improvesystem functionalityVSAvoidaccess permission management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex management of multiple third-party access credentials into distinct functional components: credential discovery, permission classification, access log inspection, and data transfer mapping. This segmentation organizes the complexity into manageable analytical steps that automatically process each third-party system's access rights.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-service analysis by automatically discovering credentials, classifying permissions, and monitoring access patterns without requiring manual intervention. The computational processes autonomously manage the complexity of tracking multiple third-party systems, eliminating the need for manual security administration.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If comprehensive access monitoring is implemented to track data transfers, then data security is improved, but computational resources and processing time worsen

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidprocessing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing monitoring on specific high-value targets such as classified data objects and critical access credentials rather than attempting to monitor all system activity uniformly. This selective monitoring approach maintains effective security while reducing the computational overhead and processing time required for comprehensive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240311497A1Data transfer discovery and analysis systems and related methods
Publication Date: 2024.09.19 ONETRUST LLC
  • US20240311497A1 patent drawing
  • US20240311497A1 patent drawing
  • US20240311497A1 patent drawing

AI summary

In various aspects, a data transfer discovery and analysis system may query an entity computing system to identify access credentials for third-party computing systems and scan each access credential to determine associated permissions provided by each access credential on the entity computing system. The data transfer discovery and analysis system may further inspect access logs to identify actual data transfers between the entity computing system and third-party computing systems as well as other access activity associated with each of the credentials. The system can generate and store a mapping of all actual data transfers (e.g., based on the access log data) and potential data transfers (e.g., based on particular access permissions) between/among the entity computing system and the third-party computing systems. By analyzing access logs to determine actual data transfers executed under each particular access credential, the data transfer discovery and analysis system can identify unused and/or underutilized access permissions.