Emergency Identity Access Shutdown and Restore Tool
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity and access management solutions lack efficient methods for emergency shutdown and restoration of access entitlements during and after security breaches, leading to downtime and increased operational costs due to manual processes and reliance on individual vendors for predefined systems.
Innovation Solution
An emergency identity access shutdown and restore tool within an IAM system that dynamically defines identity populations based on attributes, allowing for rapid and automated shutdown and restoration of access entitlements across the enterprise computing environment using source-specific connectors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual shutdown procedures are used to power down directory servers and systems during security breaches, then complete system shutdown is achieved, but shutdown time and operational downtime are significantly increased
Solution Approach 1:
The system pre-defines shutdown and restore procedures, systems, and application programs before security breaches occur. These pre-configured mechanisms enable rapid execution during actual breaches, eliminating the need for manual setup and reducing both shutdown and restore times significantly.
Solution Approach 2:
The patent introduces an intermediary mechanism (pre-defined shutdown/restore systems) that acts as a mediator between the security breach detection and the actual system shutdown/restore operations. This intermediary layer automates the process and coordinates actions across multiple applications and technologies uniformly.
2Extent of automation
If pre-defined shutdown systems are configured for individual applications and systems, then automated shutdown capability is provided, but configuration time and vendor coordination requirements are increased
Solution Approach 1:
The patent creates a universal pre-defined shutdown and restore mechanism that can be applied across multiple different applications, systems, and technologies. This universal approach eliminates the need to configure separate vendor-specific solutions for each system, reducing overall configuration complexity while maintaining broad automation capability.
Solution Approach 2:
The patent merges multiple individual shutdown and restore configurations into a single unified pre-defined system. By combining these functions into one coordinated mechanism, the system reduces the complexity of managing multiple separate configurations while maintaining comprehensive automation across all connected applications and systems.
3Reliability
If complete system shutdown is performed to perform security breach analysis, then security analysis capability is improved, but operational productivity and resource utilization are reduced
Solution Approach 1:
The patent enables selective shutdown of specific applications, systems, or components rather than requiring complete system shutdown. This segmentation allows security breach analysis to be performed on targeted areas while other parts of the enterprise system continue to operate normally, maintaining productivity in unaffected areas.
Solution Approach 2:
The system performs partial shutdown actions only where necessary for security breach analysis rather than shutting down the entire system. This partial action approach provides sufficient security analysis capability while minimizing the impact on overall enterprise operational productivity and resource utilization.
Data Source
AI summary
Responsive to a user instruction or a security breach occurring in an enterprise computing environment, an emergency shutdown and restore module is adapted to obtain and evaluate an identity population definition to determine a population of identities (e.g., a forensic team) associated with accounts distributed across applications in the enterprise computing environment. The emergency shutdown and restore module is further adapted to determine source systems of such accounts and communicate with those source systems via source-specific connectors. The emergency shutdown and restore module can respectively request the source systems to shut down access to the applications by the accounts associated with the population of identities, or to exclude the accounts associated with the population of identities in shutting down access to the applications. After performing a security breach analysis, the emergency shutdown and restore module can request the source systems to restore access respectively.


