Dynamic Entitlement Manager for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for monitoring and controlling access to resources within organizations are resource-intensive and inefficient, particularly in large organizations with numerous employees and complex entitlement combinations, leading to potential security risks and compliance issues due to legacy entitlements and poor management of access rights.

Innovation Solution

A computer program product that periodically examines members within an organization to identify uncommon or normal entitlements by determining community-based thresholds, allowing for automated identification and management of access rights, thereby enhancing the efficiency and accuracy of entitlement management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional manual techniques are used to monitor and control entitlements, then access control can be maintained, but significant organizational resources are consumed and management becomes impossible at scale

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables entitlement management to become self-regulating by automatically analyzing entitlement distributions, identifying anomalies, and notifying appropriate parties. The system monitors itself and the entitlement landscape without requiring continuous manual intervention, allowing the organization to maintain reliable access control while consuming minimal human resources.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual review process with an automated computer-based system that uses algorithms to analyze entitlement data, identify uncommon entitlements, and generate notifications. This substitution transforms entitlement management from a labor-intensive manual process to an automated electronic system that can scale to any organization size.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive entitlement monitoring is implemented across the entire organization, then security risks can be detected, but the complexity of managing millions of entitlement combinations becomes overwhelming

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the organization into communities based on job functions and roles, then analyzes entitlement distributions within each community separately. This segmentation breaks down the overwhelming complexity of monitoring millions of entitlement combinations across the entire organization into manageable community-level analyses, while still providing comprehensive security monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the monitoring approach by focusing on statistical parameters (common vs. uncommon entitlements) rather than attempting to manage each individual entitlement combination. By identifying entitlements that deviate from community norms, the system provides comprehensive security monitoring without being overwhelmed by the sheer number of entitlements.

Inventive Principle:
Principle #35Parameter changes

3Stability of the object's composition

If legacy entitlements are retained for transitioning employees, then operational continuity is maintained, but security risks and compliance issues increase

Engineering Contradiction:
Improveoperational stabilityVSAvoidsecurity risks
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The system provides continuous feedback by monitoring entitlement distributions and identifying uncommon entitlements that may represent security risks. When legacy entitlements are detected, the system notifies entitlement administrators and community members, enabling them to review and remove unnecessary entitlements while maintaining operational stability through controlled transitions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes preliminary anti-action by proactively identifying and flagging uncommon entitlements before they can cause security issues. By notifying stakeholders of potential security risks in advance, the system enables preventive removal of legacy entitlements while maintaining operational continuity through planned transitions.

Inventive Principle:
Principle #9Preliminary anti-action

4Measurement precision

If entitlement administrators manually review each member's entitlements, then accurate access control can be ensured, but the time and resources required become prohibitive

Engineering Contradiction:
Improveentitlement accuracyVSAvoidmanagement time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of requiring administrators to review every entitlement for every member, the system applies partial action by automatically identifying only the uncommon entitlements that require attention. This approach maintains high measurement precision by focusing administrative effort on the specific entitlements that deviate from norms, while dramatically reducing the time required compared to comprehensive manual reviews.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8763069B2Dynamic entitlement manager
Publication Date: 2014.06.24 BANK OF AMERICA CORP
  • US8763069B2 patent drawing
  • US8763069B2 patent drawing
  • US8763069B2 patent drawing

AI summary

Embodiments of the invention relate to systems, methods, and computer program products for monitoring and/or controlling access to entitlements. For example, in one embodiment a computer program product is configured to periodically examine the members of a particular community in an organization and automatically identify members in the community that have access to software applications, datasets, or other organizational resources that are uncommon in the community, which may indicate that the member should not have access to the such resources. The computer program product of embodiments of the invention is also configured to automatically and periodically determine the resources that members of the same community should all probably have access to. As such, embodiments of the present invention allow an organization to more efficiently monitor and control access to its resources and other entitlements.