Granular Access Risk Management Engine for Enterprise Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in efficiently managing access risks across multiple disparate business applications in a distributed enterprise computing environment, as they often require manual, inefficient, and custom-tailored solutions that are limited to single-system analyses, failing to adequately detect Segregation of Duties (SoD) risks and malicious behavior.
Innovation Solution
A database-driven analytics engine that abstracts business functions into a uniform data model, enabling granular access management across different systems, merging security principles, permissions, and user profiles to conduct system-agnostic risk analyses at multiple levels, and generating reports for access risk management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If custom solutions are created on a per-system basis to identify SoD risks, then detection accuracy for that specific system is improved, but device complexity and implementation difficulty increase significantly
Solution Approach 1:
The patent creates a universal access risk management service that can analyze multiple disparate business applications (SAP, Oracle, Microsoft Dynamics, Salesforce, Workday) through a single platform. The service uses a standardized data model and common analysis engine that adapts to different systems, eliminating the need for separate custom solutions for each application while maintaining detection accuracy across all systems.
Solution Approach 2:
The patent introduces an intermediary layer (the access risk management service) that sits between the disparate business applications and the analysis engine. This intermediary handles system-specific data extraction and transformation, converting various system formats into a standardized internal representation that the analysis engine can process uniformly, thereby simplifying the overall architecture.
2Adaptability or versatility
If manual processes are used to link risks across different business applications, then flexibility in handling system-specific variations is improved, but productivity and efficiency deteriorate
Solution Approach 1:
The patent replaces manual mechanical processes (manual risk linking, manual data collection) with an automated computer-implemented service. The service automatically extracts data from multiple systems, standardizes it, performs analysis, and links risks across systems programmatically, dramatically improving productivity while maintaining adaptability through configurable system connectors.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring system connectors and data extraction mechanisms for various business applications. These connectors are prepared in advance to automatically retrieve and standardize data when needed, eliminating the need for manual data collection and preparation while maintaining flexibility in handling different system formats.
3Ease of operation
If entitlement management is used to estimate SoD risks during user provisioning, then ease of operation is improved, but measurement precision deteriorates
Solution Approach 1:
The patent implements feedback mechanisms where the access risk management service continuously monitors user permissions and access patterns across systems. When risks are detected or when provisioning decisions are made, the system provides feedback to validate whether the decisions align with actual risk exposures, enabling continuous improvement of both operational ease and detection precision.
Data Source
AI summary
A database-driven analytics engine can break permission data from different enterprise-class systems down to the smallest components and roll them back up one level at a time, to permission groups, to business functions, then to risks (rules). This processing produces a list of complete permissions on a per user basis and allows the engine to conduct access risk analyses across the different enterprise-class systems. Responsive to a multi-system analysis request, the engine can query a database for the list of complete permissions on a per user basis and analyze in view of user permissions granted to each user and business functions assigned to the respective user in a system-agnostic manner and determine user access risks based on rules governing those business functions. Insights from this multi-system analysis can be used for generating a report on system-wide access risks. The report can be presented through a user interface.


