Access Rights Conflict Detection via Risk Management Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in efficiently managing and reviewing access rights across complex computing systems, leading to resource strain and potential security vulnerabilities due to the need for frequent updates and periodic access reviews.

Innovation Solution

A centralized identity and access management (IAM) system with a rule configuration interface for risk management, allowing administrators to configure risk management rules, monitor access rights, and perform reviews, thereby identifying and addressing conflicts and violations efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access reviews are performed periodically on large volumes of access rights, then security is improved, but resource strain increases

Engineering Contradiction:
ImprovesecurityVSAvoidresource strain
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis of access rights data to identify potential conflicts and violations before comprehensive reviews are executed. Risk management rules are pre-configured to define conflicting access rights, allowing the system to proactively detect issues rather than reacting during full-scale reviews, thereby reducing resource strain during review execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically monitors and analyzes access rights provisioned at the computing system against configured risk management rules. The automated monitoring continuously identifies when users are provisioned with both base access rights and conflicting access rights without requiring manual intervention or resource-intensive periodic reviews, enabling the system to self-manage security compliance.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive access reviews are conducted, then detection precision is improved, but time consumption increases

Engineering Contradiction:
Improvedetection precisionVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts and focuses on specific high-risk access right combinations by configuring risk management rules that define base access rights and their corresponding conflicting access rights. Instead of reviewing all access rights comprehensively, the system targets only those combinations that match predefined conflict patterns, maintaining detection precision while significantly reducing review time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the monitoring parameters from comprehensive access right analysis to targeted conflict detection based on pre-configured risk management rules. By parameterizing the review process around specific conflict patterns rather than universal scrutiny, the system achieves efficient detection of critical security issues without the time overhead of exhaustive reviews.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If manual monitoring of access rights is performed, then detection capability is improved, but operational complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidoperational complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The system introduces an intermediary automated monitoring layer between access rights provisioning and security verification. The risk management rules act as intermediaries that automatically compare provisioned access rights against configured conflict patterns, eliminating the need for manual monitoring while maintaining detection capability. This intermediary automation reduces operational complexity by handling the detection process systematically.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops where access rights provisioning is automatically monitored and compared against risk management rules. When conflicts are detected, the system provides immediate feedback about violations, enabling rapid response without manual intervention. This automated feedback mechanism maintains high detection capability while simplifying operations through systematic, rule-based monitoring.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10341385B2Facilitating separation-of-duties when provisioning access rights in a computing system
Publication Date: 2019.07.02 BANK OF AMERICA CORP
  • US10341385B2 patent drawing
  • US10341385B2 patent drawing
  • US10341385B2 patent drawing

AI summary

Systems and methods for managing risk management rules are provided. A risk management rule may be configured at a rule configuration interface are described. The rule configuration interface may include a list of access rights available for selection. Based on input received, one of the access rights may be identified as a base access right and one of the access rights may be identified as a conflicting access right for the risk management rule. The access rights provisioned at the computing system may be monitored to determine whether a user is provisioned with both the base access right and the conflicting access right. If so, a violation review may be created and presented at a violation review interface at which a decision for the violation review is receivable. An exception to the risk management rule may also be configured at an exception configuration interface.