Automated Access Control System Using Confidence Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access management systems in enterprises are complex and time-consuming, often resulting in over-granting of access privileges, which increases security concerns and inefficient use of resources due to unnecessary access permissions.
Innovation Solution
A system that automatically determines and grants access entitlements to target systems and applications based on profile data from HR or user management systems, using rules and confidence values to assess the need for access, and periodically reviews usage to revoke unnecessary entitlements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual access management processes are used with multiple approval layers and administrators, then access control security is maintained, but the time and complexity required to obtain access increases significantly
Solution Approach 1:
The system enables self-service access management where the access management system automatically determines appropriate access entitlements for requestors based on their profile data and the requested target system, eliminating the need for manual approval processes and reducing the time to obtain access while maintaining security through automated policy enforcement
Solution Approach 2:
The system performs preliminary actions by pre-configuring access policies, entitlement definitions, and profile data mappings in advance, allowing the automated access management system to quickly determine and grant appropriate access rights without requiring real-time human intervention or complex approval workflows
2Ease of operation
If access is granted broadly to multiple employees without precise determination, then ease of access administration is improved, but security concerns increase and resources are inefficiently used
Solution Approach 1:
The system replaces manual administrative processes with an automated access management system that uses profile data, entitlement definitions, and policy rules to automatically determine appropriate access entitlements, maintaining security through precise automated determination while improving ease of administration through automation
Solution Approach 2:
The system implements feedback mechanisms where access entitlements are continuously evaluated based on profile data changes, target system requirements, and usage patterns, allowing the system to automatically adjust and revoke access when no longer needed, thereby maintaining security while simplifying administration
3Ease of operation
If comprehensive access entitlements are granted to all employees, then ease of access is improved, but processing power, network resources, and storage requirements increase inefficiently
Solution Approach 1:
The system applies local quality by granting access entitlements specifically tailored to each requestor's profile data and the particular target system requirements, rather than providing universal access, thereby enabling employees to access needed systems efficiently while minimizing unnecessary processing power, network resources, and storage consumption
Data Source
AI summary
A method for controlling access to one or more of a plurality of target systems includes receiving profile data that defines one or more features associated with a plurality of individuals with one or more entitlements of those individuals. Each entitlement is indicative of target system access. The method further includes generating a model that includes one or more sets of rules where each set of rules is associated with an entitlement of the profile data. Each entitlement is indicative of target system/application access. Each rule within a set relates a combination of one or more features of the profile data with a confidence value. Profile data that defines one or more features associated with a target individual is received from a first user management system. A listing that includes one or more entitlements associated with the target individual, and confidence values associated with the one or more entitlements is generated based on the profile data and the rules. Each confidence value is indicative of whether the target individual should be granted a corresponding entitlement. For each entitlement having a corresponding confidence value higher than a predetermined threshold, an instruction is communicated to a target system associated with the entitlement to allow the target individual access to the target system.


