Enterprise Access Permission Request Processing System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively manage access permissions in enterprise networks, often granting unnecessary access or failing to provide appropriate permissions, leading to security risks and inefficiencies in data access management.

Innovation Solution

A method and system that process access permission requests by identifying similarities among enterprise users and data elements to provide recommendations on granting access, including approval, disapproval, or conditional approval based on user and data element similarities, additional approver approval, and time-limited permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access permissions are granted broadly to ensure sufficient access for all users, then user productivity and ease of operation improve, but security risks and unnecessary access permissions increase

Engineering Contradiction:
Improveaccess permission managementVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system automatically analyzes access permission requests by comparing user characteristics, data element properties, and historical access patterns to generate approval recommendations without requiring manual security officer intervention for each request. The system serves itself by making intelligent decisions based on learned patterns from enterprise data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously learns from access permission decisions and their outcomes, using the results to refine future recommendations. By analyzing the effectiveness of granted permissions and user behavior patterns, the system adapts its approval criteria to improve security while maintaining operational efficiency.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If access permissions are restricted tightly to ensure security, then security risks decrease, but user productivity and access efficiency worsen

Engineering Contradiction:
Improvesecurity risksVSAvoiddata access efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system autonomously evaluates access requests against enterprise policies and historical patterns, automatically generating approval recommendations that balance security requirements with user productivity needs without manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-establishes access permission guidelines and policies based on enterprise data analysis before requests are made. By having pre-defined approval criteria and user profiles ready, the system can quickly evaluate requests without delaying user productivity.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual review of access permission requests is performed to ensure appropriateness, then permission decision accuracy improves, but processing time and operational complexity increase

Engineering Contradiction:
Improvepermission decision accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically performs the review function that previously required manual security officers by analyzing user characteristics, data properties, and access patterns to generate approval recommendations, eliminating manual processing time while maintaining decision accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical review processes with automated computational analysis, using algorithms to evaluate access requests against enterprise policies and historical data, thereby reducing processing time while maintaining or improving decision accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If comprehensive access permission management is implemented to prevent unnecessary access, then security improves, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveaccess permission securityVSAvoidpermission management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system serves multiple functions within a single platform: analyzing user profiles, evaluating data elements, processing access requests, generating recommendations, and learning from outcomes. This multi-functionality reduces the need for separate complex systems while maintaining comprehensive security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system combines user profile analysis, data element evaluation, access request processing, and security policy enforcement into a unified automated workflow, simplifying the overall system architecture while maintaining comprehensive security management capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11706227B2Systems and methods for processing access permission type-specific access permission requests in an enterprise
Publication Date: 2023.07.18 VARONIS SYSTEMS INC
  • US11706227B2 patent drawing
  • US11706227B2 patent drawing
  • US11706227B2 patent drawing

AI summary

A system including a processor and a non-transitory, tangible computer-readable medium in which computer program instructions are stored, which instructions, when read by a computer, cause the computer to process access permission type-specific access permission requests from enterprise users in an enterprise, the system including access permission type-specific access permission request receiving functionality operable for receiving at least one request for at least one access permission type-specific access permission of at least one user to at least one data element in the enterprise, and access permission type-specific access permission request output providing functionality operable for employing information pertaining to ones of the enterprise users having similarities to the at least one user with respect to at least the access permission type-specific access permission to the data elements in order to provide an output indication of perceived appropriateness of grant of the request.