Dynamic Graph Access Management for Redundant Network Entities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems struggle to efficiently manage entities such as users, devices, and rules due to redundancy and anomalies, leading to inefficiencies and increased maintenance.
Innovation Solution
A graph-based system that dynamically adapts edges between nodes representing entities based on a tolerance parameter, allowing for the automatic merging and removal of redundant entities and anomalies, thereby optimizing network management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated permission management is implemented using traditional methods, then management efficiency is improved, but redundancy and anomalies in entity management increase system complexity
Solution Approach 1:
The patent merges redundant entities by identifying entities with identical or overlapping attribute sets and consolidating them into single representative entities. This reduces the total number of entities in the system while preserving all unique attribute combinations, thereby reducing system complexity while maintaining management efficiency.
Solution Approach 2:
The patent introduces a tolerance parameter that dynamically adjusts the threshold for determining when entities should be merged. By changing this parameter, the system can adaptively control the degree of merging based on acceptable levels of redundancy, optimizing the balance between management efficiency and system complexity.
2Device complexity
If manual management of user identities and access permissions is performed, then system complexity is reduced, but time consumption and maintenance effort increase
Solution Approach 1:
The system implements self-service automation where entities automatically identify and merge with redundant entities based on attribute comparison. The automated permission management system continuously monitors and updates entity relationships without manual intervention, eliminating time-consuming manual management while keeping system complexity manageable through algorithmic efficiency.
Solution Approach 2:
The patent performs preliminary actions by pre-defining attribute sets and containment relationships for entities before actual permission management operations. This pre-processing organizes entities into hierarchical structures and identifies merge candidates in advance, reducing the time required for ongoing permission management while maintaining reasonable system complexity.
3Measurement precision
If strict containment rules are enforced for entity merging, then accuracy of permission management is improved, but the number of redundant entities increases
Solution Approach 1:
The patent uses a tolerance parameter to adjust the strictness of containment rules. By varying this parameter, the system can enforce stricter rules when high accuracy is needed or more lenient rules when reducing entity count is prioritized, dynamically balancing accuracy requirements against the proliferation of redundant entities.
Solution Approach 2:
The system applies partial merging by consolidating entities that meet a threshold level of similarity rather than requiring complete identity. This partial action approach merges entities with sufficiently similar attribute sets, achieving adequate permission management accuracy while avoiding the creation of excessive redundant entities that would result from overly strict merging criteria.
Data Source
AI summary
There is provided a method for automated permission management, comprising: accessing a graph including nodes denoting different groups having different access permissions levels, each group associated with a set of user identities, the graph including edges between nodes that represent at least a partial subset of one another, each edge associated with a score indicating an accuracy of containment between groups connected by the edge, dynamically adapting a tolerance parameter indicating a threshold for amount of accuracy of containment of user identities between different groups, dynamically adapting the graph by creating or removing edges between nodes according to the score of the respective edges relative to the threshold, automatically merging access permission levels of at least two groups connected by an edge for automatically eliminating redundant access permission levels of the groups, and automatically updating access permission levels of the at least two groups according to the dynamically updated graph.


