Automated Database Provisioning via Identity Governance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing permissions across multiple users and programs accessing databases in cloud systems is time-consuming and prone to insecure modifications due to manual administration in identity governance platforms.

Innovation Solution

An automated method and system for database provisioning that includes receiving a provisioning request, accessing identity data records, generating privilege accounts, defining access credential rules, and automatically managing access credentials within the database using a secured port.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual administration is used to manage permissions in identity governance platforms, then administrators can directly update identity data records and permissions, but the process is time-consuming and prone to insecure modifications

Engineering Contradiction:
ImprovePermission management capabilityVSAvoidSecurity of permission modifications
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables self-service automated provisioning where the database provisioning system automatically creates privilege accounts and manages access credentials based on identity data records, eliminating the need for manual administrator intervention and reducing security risks associated with human error and insecure modifications

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an automated database provisioning system as an intermediary between identity governance platforms and databases. This intermediary automatically updates identity data records and manages permissions by connecting to secured ports, thereby eliminating direct manual access while maintaining security and compliance policies

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated database provisioning is implemented, then the process becomes faster and more secure, but requires integration with identity management mechanisms and secured ports

Engineering Contradiction:
ImproveDatabase provisioning speedVSAvoidSystem integration requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated database provisioning system is designed to work with multiple identity management mechanisms and database types through standardized interfaces. It can access identity data records, connect to various database secured ports, and enforce compliance policies across different systems, reducing integration complexity through universal functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary actions by pre-configuring compliance policies and access credential rules before database provisioning occurs. Identity data records are prepared and validated in advance, and the system establishes secured port connections proactively, streamlining the overall provisioning process while managing complexity through upfront preparation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250077707A1Automated database provisioning and methods thereof
Publication Date: 2025.03.06 CAPITAL ONE SERVICES LLC
  • US20250077707A1 patent drawing
  • US20250077707A1 patent drawing
  • US20250077707A1 patent drawing

AI summary

Systems and methods of the present disclosure enable the automated provisioning of security and compliance policies and onboarding to identity governance solutions. The systems and methods include processors to receive a database provisioning request associated with at least one entity and accessing at least one identity data record via an identity management mechanism associated with the at least one entity. The processors automatically access the database via a secured port; automatically cause to generate in the database, at least one privilege account and at least one access credential rule based on the at least one identity data record. The database is configured to utilize the at least one access credential rule to automatically manage access credentials for accessing the database via the at least one privilege account. The processors automatically disconnect from the secured port of the database.