Activity-Based Access Graphs for Dynamic Privilege Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in comprehensively understanding and managing user access rights due to dynamic organizational structures and evolving regulatory landscapes, leading to vulnerabilities in data access control across heterogeneous IT environments.

Innovation Solution

A data management server that provides adaptive security applications, offering continuous access evaluation, risk monitoring, and access analytics through standardized data schemas, dashboards, and graphical representations to streamline access management and governance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional role-based access control methods are used, then implementation is straightforward, but they fall short of adequately addressing nuanced needs of modern enterprises with dynamic organizational structures

Engineering Contradiction:
Improveadaptability to dynamic organizational structuresVSAvoidcomplexity of access management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control by continuously monitoring user activities, contextual factors, and organizational structure changes. The system automatically adjusts access permissions in real-time based on current risk assessments and organizational dynamics, rather than relying on static role-based assignments. This enables the system to adapt to evolving organizational structures while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates continuous feedback loops that monitor user behavior, access patterns, and organizational changes. This feedback is used to dynamically update access policies and risk assessments, allowing the system to learn and adapt to new organizational structures and security threats automatically.

Inventive Principle:
Principle #23Feedback

2Reliability

If granular control over data access is maintained to address nuanced needs, then security is improved, but managing access rights becomes a daunting task

Engineering Contradiction:
Improvesecurity of data access controlVSAvoidease of managing access rights
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service capabilities where access permissions are automatically granted, adjusted, or revoked based on real-time risk assessments and organizational structure changes. The system autonomously manages granular access control without requiring manual intervention for each permission change, thereby maintaining high security while reducing operational burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes access parameters based on contextual factors such as user behavior patterns, device security states, and organizational hierarchy changes. This automatic parameter adjustment enables granular control to be maintained while eliminating the need for manual management of each access right.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access permissions are及时调整 as employees transition between roles to maintain security, then data protection is improved, but keeping track of all changes becomes complex

Engineering Contradiction:
Improvedata protection during role transitionsVSAvoidcomplexity of tracking access changes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system maintains continuous monitoring and automatic adjustment of access permissions during employee role transitions. By continuously tracking organizational structure changes and user activity patterns, the system ensures seamless updates to access rights without interruption to security protection, eliminating the need for manual tracking of transitions.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system proactively anticipates access permission changes by monitoring organizational structure changes and user role transitions before they complete. This preliminary action allows the system to pre-adjust access permissions accordingly, ensuring continuous data protection while automatically managing the complexity of tracking changes.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If comprehensive monitoring of user access rights is implemented across heterogeneous IT environments, then security visibility is improved, but system complexity increases

Engineering Contradiction:
Improvevisibility of access rights informationVSAvoidcomplexity of monitoring system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a universal monitoring framework that can operate across heterogeneous IT environments including cloud services, on-premises systems, and hybrid architectures. The system provides multi-functional capabilities to collect, normalize, and analyze access rights information from diverse sources through a single unified platform, thereby improving visibility without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250307428A1Activity Based Risk Monitoring
Publication Date: 2025.10.02 OLERIA CORP
  • US20250307428A1 patent drawing
  • US20250307428A1 patent drawing
  • US20250307428A1 patent drawing

AI summary

A system establishes connections with a data resource system and connections with a security monitoring system. The system receives metadata related to data access history of the data resources from the data resource system and risk related signals associated with data access activities from the security monitoring system. The system generates an access graph comprising graph objects that are connected by access paths signaling access levels of the data resources controlled by the data resource system. The system aggregates the metadata from the data resource system, the risk related signals from the security monitoring system, and data associated with the access graph to generate normalized risk signals and identifies a cybersecurity risk-related instance associated with an access paths in the access graph. The system generates an alert which allows a user to adjust access privilege of a data resource associated with the cybersecurity risk-related instance.