Emergency Identity Access Shutdown and Restore Tool

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity and access management solutions lack efficient methods for emergency shutdown and restoration of access entitlements during and after security breaches, leading to downtime and increased operational costs due to manual processes and reliance on individual vendors for predefined systems.

Innovation Solution

An emergency identity access shutdown and restore tool within an IAM system that dynamically defines identity populations based on attributes, allowing for rapid and automated shutdown and restoration of access entitlements across the enterprise computing environment using source-specific connectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual shutdown procedures are used to power down directory servers and systems during security breaches, then complete system shutdown is achieved, but shutdown time and operational downtime are significantly increased

Engineering Contradiction:
Improvesecurity breach response effectivenessVSAvoidshutdown and restore time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-defines shutdown and restore procedures, systems, and application programs before security breaches occur. These pre-configured mechanisms enable rapid execution during actual breaches, eliminating the need for manual setup and reducing both shutdown and restore times significantly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (pre-defined shutdown/restore systems) that acts as a mediator between the security breach detection and the actual system shutdown/restore operations. This intermediary layer automates the process and coordinates actions across multiple applications and technologies uniformly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If pre-defined shutdown systems are configured for individual applications and systems, then automated shutdown capability is provided, but configuration time and vendor coordination requirements are increased

Engineering Contradiction:
Improveshutdown and restore automationVSAvoidsystem configuration complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent creates a universal pre-defined shutdown and restore mechanism that can be applied across multiple different applications, systems, and technologies. This universal approach eliminates the need to configure separate vendor-specific solutions for each system, reducing overall configuration complexity while maintaining broad automation capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple individual shutdown and restore configurations into a single unified pre-defined system. By combining these functions into one coordinated mechanism, the system reduces the complexity of managing multiple separate configurations while maintaining comprehensive automation across all connected applications and systems.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If complete system shutdown is performed to perform security breach analysis, then security analysis capability is improved, but operational productivity and resource utilization are reduced

Engineering Contradiction:
Improvesecurity breach analysis capabilityVSAvoidenterprise operational productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables selective shutdown of specific applications, systems, or components rather than requiring complete system shutdown. This segmentation allows security breach analysis to be performed on targeted areas while other parts of the enterprise system continue to operate normally, maintaining productivity in unaffected areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial shutdown actions only where necessary for security breach analysis rather than shutting down the entire system. This partial action approach provides sufficient security analysis capability while minimizing the impact on overall enterprise operational productivity and resource utilization.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11979417B2Systems and methods for emergency shutdown and restore of access entitlements responsive to security breach
Publication Date: 2024.05.07 SAILPOINT TECHNOLOGIES INC
  • US11979417B2 patent drawing
  • US11979417B2 patent drawing
  • US11979417B2 patent drawing

AI summary

Responsive to a user instruction or a security breach occurring in an enterprise computing environment, an emergency shutdown and restore module is adapted to obtain and evaluate an identity population definition to determine a population of identities (e.g., a forensic team) associated with accounts distributed across applications in the enterprise computing environment. The emergency shutdown and restore module is further adapted to determine source systems of such accounts and communicate with those source systems via source-specific connectors. The emergency shutdown and restore module can respectively request the source systems to shut down access to the applications by the accounts associated with the population of identities, or to exclude the accounts associated with the population of identities in shutting down access to the applications. After performing a security breach analysis, the emergency shutdown and restore module can request the source systems to restore access respectively.