Account Lifecycle Management via Automated Discovery and Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing user account access privileges in large corporate environments is burdensome and time-consuming, leading to potential security threats and inefficiencies, particularly due to the need for regular audits as per regulations like Sarbanes Oxley/SSAE 16, which are difficult and time-consuming to implement.

Innovation Solution

An account lifecycle management system comprising a discovery engine to identify accounts, a policy engine to assess privileged access, a data modeling engine to associate this access with organizational information, and a remediation engine to take necessary actions, along with an optional mitigation engine to address identified issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual management of user account access is used, then system administrators can control access privileges, but the process becomes burdensome and time-consuming

Engineering Contradiction:
Improveaccount management efficiencyVSAvoidtime to update or modify user access
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables self-service account lifecycle management through automated discovery, identification, and remediation of accounts. The discovery engine automatically finds accounts, the policy engine assesses their security posture, and the remediation engine applies fixes without requiring manual administrator intervention for each account, thus dramatically improving efficiency and reducing time loss.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by continuously discovering and identifying accounts before security issues arise. The policy engine proactively assesses privileged access data and associates it with organizational information in advance, so that when security threats or compliance requirements emerge, remediation can occur rapidly without time-consuming manual analysis.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual account audits are conducted to meet regulatory requirements, then compliance with regulations like SOX/SSAE 16 can be achieved, but the audit process becomes difficult and time-consuming

Engineering Contradiction:
Improvecompliance with regulatory requirementsVSAvoidtime to conduct regular audits
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements continuous account discovery, identification, and assessment rather than periodic manual audits. The discovery engine continuously operates to find accounts, the policy engine continuously evaluates their security posture, and compliance status is maintained continuously, ensuring regulatory requirements are met at all times without requiring time-consuming periodic audit campaigns.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system provides continuous feedback on account security posture and compliance status. The policy engine assesses privileged access data and provides feedback to the remediation engine, which automatically corrects non-compliant accounts. This closed-loop feedback mechanism ensures ongoing compliance with regulations like SOX/SSAE 16 without requiring manual audit intervention.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If delays occur in updating user access, then administrative flexibility is maintained, but the corporation becomes exposed to internal security threats

Engineering Contradiction:
Improveadministrative flexibilityVSAvoidinternal security threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system replaces the mechanical manual process of account management with an automated computational system. The discovery engine automatically discovers accounts, the policy engine automatically assesses their security posture, and the remediation engine automatically applies security fixes. This substitution eliminates delays inherent in manual processes while maintaining administrative flexibility through configurable policies, thereby preventing exposure to internal security threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11206268B2Account lifecycle management
Publication Date: 2021.12.21 JPMORGAN CHASE BANK NA
  • US11206268B2 patent drawing
  • US11206268B2 patent drawing
  • US11206268B2 patent drawing

AI summary

An account lifecycle management system is provided. The system includes a discovery engine configured to discover and identify an account. The system further includes a policy engine configured to identify privileged access data granted to the account identified by the discovery engine. The system further includes a data modeling engine configured to associate the identified privileged access data with organizational information. The system further includes a remediation engine configured to remediate the account based on the associated privileged access data.