Granular Access Risk Management Engine for Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently managing access risks across multiple disparate business applications in a distributed enterprise computing environment, as they often require manual, inefficient, and custom-tailored solutions that are limited to single-system analyses, failing to adequately detect Segregation of Duties (SoD) risks and malicious behavior.

Innovation Solution

A database-driven analytics engine that abstracts business functions into a uniform data model, enabling granular access management across different systems, merging security principles, permissions, and user profiles to conduct system-agnostic risk analyses at multiple levels, and generating reports for access risk management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If custom solutions are created on a per-system basis to identify SoD risks, then detection accuracy for that specific system is improved, but device complexity and implementation difficulty increase significantly

Engineering Contradiction:
ImproveSoD risk detection accuracyVSAvoidsolution complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal access risk management service that can analyze multiple disparate business applications (SAP, Oracle, Microsoft Dynamics, Salesforce, Workday) through a single platform. The service uses a standardized data model and common analysis engine that adapts to different systems, eliminating the need for separate custom solutions for each application while maintaining detection accuracy across all systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer (the access risk management service) that sits between the disparate business applications and the analysis engine. This intermediary handles system-specific data extraction and transformation, converting various system formats into a standardized internal representation that the analysis engine can process uniformly, thereby simplifying the overall architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual processes are used to link risks across different business applications, then flexibility in handling system-specific variations is improved, but productivity and efficiency deteriorate

Engineering Contradiction:
Improvesystem compatibilityVSAvoidrisk analysis efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical processes (manual risk linking, manual data collection) with an automated computer-implemented service. The service automatically extracts data from multiple systems, standardizes it, performs analysis, and links risks across systems programmatically, dramatically improving productivity while maintaining adaptability through configurable system connectors.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs preliminary actions by pre-configuring system connectors and data extraction mechanisms for various business applications. These connectors are prepared in advance to automatically retrieve and standardize data when needed, eliminating the need for manual data collection and preparation while maintaining flexibility in handling different system formats.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If entitlement management is used to estimate SoD risks during user provisioning, then ease of operation is improved, but measurement precision deteriorates

Engineering Contradiction:
Improveuser provisioning simplicityVSAvoidaccess risk detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the access risk management service continuously monitors user permissions and access patterns across systems. When risks are detected or when provisioning decisions are made, the system provides feedback to validate whether the decisions align with actual risk exposures, enabling continuous improvement of both operational ease and detection precision.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240193519A1Systems and methods for system-wide granular access risk management
Publication Date: 2024.06.13 SAILPOINT TECHNOLOGIES INC
  • US20240193519A1 patent drawing
  • US20240193519A1 patent drawing
  • US20240193519A1 patent drawing

AI summary

A database-driven analytics engine can break permission data from different enterprise-class systems down to the smallest components and roll them back up one level at a time, to permission groups, to business functions, then to risks (rules). This processing produces a list of complete permissions on a per user basis and allows the engine to conduct access risk analyses across the different enterprise-class systems. Responsive to a multi-system analysis request, the engine can query a database for the list of complete permissions on a per user basis and analyze in view of user permissions granted to each user and business functions assigned to the respective user in a system-agnostic manner and determine user access risks based on rules governing those business functions. Insights from this multi-system analysis can be used for generating a report on system-wide access risks. The report can be presented through a user interface.