Automated Access Re-certification System for Role-Based Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current corporate systems lack a systematic and automated methodology for approving and re-certifying user access rights to applications, leading to inefficient access management, security vulnerabilities, and labor-intensive processes, especially in global business environments where user roles and access levels often change without timely updates.

Innovation Solution

An integrated system for approving and re-certifying user access rights based on configurable timeframes and functional roles, utilizing a computer-controlled re-certification process that involves designated reviewers, automated notifications, and a management summary to monitor progress, ensuring secure and efficient access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual processes are used to approve and re-certify user access rights, then flexibility in handling individual cases is maintained, but the process becomes labor-intensive and inefficient

Engineering Contradiction:
Improveaccess rights management efficiencyVSAvoidoperational complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system segments the access rights management process into distinct automated components: initial approval workflow, periodic re-certification reminders, automated notifications to reviewers, and systematic tracking. This segmentation enables high-volume automated processing while maintaining operational simplicity through standardized procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service mechanisms where reviewers automatically receive reminders and notifications about pending re-certification tasks, and the system autonomously tracks and manages the entire re-certification workflow without requiring manual intervention to initiate or monitor processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If systematic automated re-certification is implemented, then security is improved and labor-intensive processes are reduced, but system complexity increases

Engineering Contradiction:
Improveaccess rights securityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring re-certification timeframes and automatically generating reminders before deadlines occur. This preliminary automation ensures security compliance without requiring complex real-time decision-making structures, thereby improving reliability while managing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where automated notifications are sent to reviewers about pending re-certification tasks, and the system tracks and records all re-certification actions. This feedback loop ensures security compliance through systematic monitoring while maintaining manageable complexity through standardized feedback channels.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple approvers are initiated for re-certification, then security oversight is enhanced, but the process time increases

Engineering Contradiction:
Improveaccess rights verificationVSAvoidre-certification duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic re-certification actions at predetermined time intervals for different users and access levels. This periodic approach allows multiple approvers to review systematically at scheduled times rather than requiring sequential approval from all approvers simultaneously, thereby enhancing verification reliability while controlling process time through structured periodic cycles.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8181016B1Applications access re-certification system
Publication Date: 2012.05.15 JPMORGAN CHASE BANK NA
  • US8181016B1 patent drawing
  • US8181016B1 patent drawing
  • US8181016B1 patent drawing

AI summary

An applications access re-certification system is disclosed. The system is used for approving and re-certifying a user's access rights to applications stored or existing in an institution's computer system based on reviewing in a configurable timeframe the user's functional roles by designated reviewers. The system is used to ensure security of the applications by means of a reviewing process. The system is used to automate the re-certification process by means of a computer-controlled re-certification system which automatically operates in a defined methodology under control of re-certification administrators. The system could perform a management summary of access rights to the applications, and a automated scorecard to monitor the re-certification progress. The system could carry out a control process to ensure the changes to existing permissions are effectively managed at source destinations. The system has a capability of initiating multiple approvers for re-certifying a user's access rights.