Activity-Based Access Graphs for Dynamic Privilege Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises face challenges in comprehensively understanding and managing user access rights due to dynamic organizational structures and evolving regulatory landscapes, leading to vulnerabilities in data access control across heterogeneous IT environments.
Innovation Solution
A data management server that provides adaptive security applications, offering continuous access evaluation, risk monitoring, and access analytics through standardized data schemas, dashboards, and graphical representations to streamline access management and governance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional role-based access control methods are used, then implementation is straightforward, but they fall short of adequately addressing nuanced needs of modern enterprises with dynamic organizational structures
Solution Approach 1:
The patent implements dynamic access control by continuously monitoring user activities, contextual factors, and organizational structure changes. The system automatically adjusts access permissions in real-time based on current risk assessments and organizational dynamics, rather than relying on static role-based assignments. This enables the system to adapt to evolving organizational structures while maintaining security.
Solution Approach 2:
The system incorporates continuous feedback loops that monitor user behavior, access patterns, and organizational changes. This feedback is used to dynamically update access policies and risk assessments, allowing the system to learn and adapt to new organizational structures and security threats automatically.
2Reliability
If granular control over data access is maintained to address nuanced needs, then security is improved, but managing access rights becomes a daunting task
Solution Approach 1:
The system implements self-service capabilities where access permissions are automatically granted, adjusted, or revoked based on real-time risk assessments and organizational structure changes. The system autonomously manages granular access control without requiring manual intervention for each permission change, thereby maintaining high security while reducing operational burden.
Solution Approach 2:
The system dynamically changes access parameters based on contextual factors such as user behavior patterns, device security states, and organizational hierarchy changes. This automatic parameter adjustment enables granular control to be maintained while eliminating the need for manual management of each access right.
3Reliability
If access permissions are及时调整 as employees transition between roles to maintain security, then data protection is improved, but keeping track of all changes becomes complex
Solution Approach 1:
The system maintains continuous monitoring and automatic adjustment of access permissions during employee role transitions. By continuously tracking organizational structure changes and user activity patterns, the system ensures seamless updates to access rights without interruption to security protection, eliminating the need for manual tracking of transitions.
Solution Approach 2:
The system proactively anticipates access permission changes by monitoring organizational structure changes and user role transitions before they complete. This preliminary action allows the system to pre-adjust access permissions accordingly, ensuring continuous data protection while automatically managing the complexity of tracking changes.
4Loss of information
If comprehensive monitoring of user access rights is implemented across heterogeneous IT environments, then security visibility is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal monitoring framework that can operate across heterogeneous IT environments including cloud services, on-premises systems, and hybrid architectures. The system provides multi-functional capabilities to collect, normalize, and analyze access rights information from diverse sources through a single unified platform, thereby improving visibility without proportionally increasing complexity.
Data Source
AI summary
A system establishes connections with a data resource system and connections with a security monitoring system. The system receives metadata related to data access history of the data resources from the data resource system and risk related signals associated with data access activities from the security monitoring system. The system generates an access graph comprising graph objects that are connected by access paths signaling access levels of the data resources controlled by the data resource system. The system aggregates the metadata from the data resource system, the risk related signals from the security monitoring system, and data associated with the access graph to generate normalized risk signals and identifies a cybersecurity risk-related instance associated with an access paths in the access graph. The system generates an alert which allows a user to adjust access privilege of a data resource associated with the cybersecurity risk-related instance.


