Centralized Database Access Management System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing database access management systems are decentralized, leading to inconsistencies and errors when managing access lists across multiple monitoring systems, particularly when granting temporary access, as changes need to be made individually to each system, increasing the risk of oversight and compromising security.
Innovation Solution
A centralized database access management system that allows for unified management of access lists across a business or line of business, automatically granting and revoking access based on predefined time periods, reducing the need for manual intervention and minimizing errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a decentralized database monitoring system is used, then each system can independently manage its own access control, but managing access lists across multiple systems becomes difficult and error-prone
Solution Approach 1:
The patent combines multiple decentralized database monitoring systems into a single centralized system that maintains a unified access list. This single system manages access control for multiple databases, eliminating the need to maintain separate access lists in each decentralized system and ensuring consistency across all databases.
Solution Approach 2:
The centralized database monitoring system performs multiple functions: it monitors access to multiple different databases, manages a universal access list that applies across all systems, and provides centralized control for granting and revoking access. This multi-functional approach replaces multiple specialized decentralized systems.
2Ease of operation
If manual updates are made to each access list individually, then access control can be customized per system, but errors and oversights increase when granting temporary access
Solution Approach 1:
The system provides self-service functionality by automatically revoking temporary access when the specified time period expires. The centralized system monitors the access list and automatically removes users who have exceeded their temporary access authorization, eliminating the need for manual intervention to revoke access and preventing oversight errors.
Solution Approach 2:
The system implements feedback mechanisms by tracking temporary access grants and automatically triggering revocation actions when expiration conditions are met. This closed-loop control ensures that temporary access is properly managed without requiring continuous manual monitoring or intervention.
3Productivity
If multiple changes are made to access lists for temporary access, then access can be granted and revoked, but the process is time-consuming and prone to errors
Solution Approach 1:
When granting temporary access, the system preemptively schedules the revocation action for when the access period expires. This preliminary setup of the revocation timeline allows the system to automatically execute the access revocation without requiring additional manual intervention, thereby improving efficiency and reducing the time needed for complete access management.
4Adaptability or versatility
If decentralized systems are used, then each system operates independently, but scalability is limited when adding new databases or systems
Solution Approach 1:
The centralized database monitoring system is designed to monitor and manage access to multiple different databases through a single universal interface and unified access list. This architectural approach allows easy addition of new databases without requiring separate monitoring systems, thereby improving scalability while maintaining manageable system complexity.
Data Source
AI summary
Embodiments of the invention provide for a centralized system for database access management. In specific embodiments, the centralized system provides for granting users temporal access to databases for a prescribed period of time, such that upon expiration of the time period the user is automatically blocked (i.e., added back to the blacklist) from accessing the database. Moreover, as a result of centralized management, reporting and auditing of actions related to database access management are greatly improved in that all actions are recorded and a historical database of such actions is available to system users. In addition, the centralized system provides for automatic notification to predetermined stakeholders based on occurrence of predetermined system actions, such as blocking a user from database access, unblocking a user from database access (i.e., granting access) or the like.


