Frequent Pattern Tree for Entitlement Rule Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise organizations face challenges in identifying and managing complex entitlement rules for access to computing resources in real-time, due to the vast number of network devices and users with multiple combinations of entitlements, which can lead to security risks and inefficiencies in managing access controls.
Innovation Solution
A system utilizing a frequent pattern tree (FP-tree) is deployed to analyze entitlement data, generate patterns, and trigger actions based on the frequency of occurrence and correlation of entitlements, allowing for real-time identification and modification of access rules, thereby optimizing network resources and ensuring accurate access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional methods are used to manage access controls in enterprise networks, then manual management of entitlements can be performed, but the process is time-consuming and cannot be performed efficiently in real-time
Solution Approach 1:
The patent replaces manual mechanical processes of entitlement management with an automated computing system that uses FP-tree data structures and pattern matching algorithms to automatically identify entitlement rules, extract patterns from entitlement data, and trigger actions based on detected patterns, thereby eliminating time-consuming manual operations
Solution Approach 2:
The system enables self-service by automatically monitoring entitlement data changes, updating FP-trees, detecting patterns, and triggering actions without requiring manual intervention, allowing the enterprise network to autonomously manage and update its entitlement rules in real-time
2Reliability
If comprehensive access control monitoring is implemented across vast enterprise networks, then security coverage is improved, but the complexity of managing and analyzing entitlement data increases significantly
Solution Approach 1:
The patent segments the complex entitlement data management problem into distinct components: FP-tree construction from entitlement data, pattern detection within the tree structure, and action triggering based on detected patterns. This segmentation simplifies the overall complexity by breaking down the monolithic management task into manageable, modular operations
Solution Approach 2:
The FP-tree data structure serves as an intermediary between the raw entitlement data and the pattern detection process. It transforms complex entitlement relationships into a structured format that facilitates efficient pattern matching and rule extraction, thereby reducing the complexity of analyzing vast entitlement datasets
3Measurement precision
If real-time entitlement rule identification is implemented, then access control accuracy is improved, but the computational resources required for analyzing entitlement data increase
Solution Approach 1:
The patent performs preliminary action by constructing the FP-tree data structure from entitlement data in advance, organizing the data into a pattern-friendly format before actual pattern detection is needed. This preprocessing step enables faster and more accurate real-time pattern identification without requiring intensive computational resources during the actual rule identification process
Data Source
AI summary
Aspects of the disclosure relate to identifying entitlement rules based on a frequent pattern tree. A computing platform may retrieve entitlement data associated with a relational database, where the entitlement data is indicative of user entitlements to computing resources in an enterprise network. Then, the computing platform may generate, for the entitlement data, a frequent pattern tree. Then, the computing platform may compare a pair of branches and may detect a pattern associated with a pair of entitlements. Then, the computing platform may determine, based on the frequent pattern tree, a frequency of occurrence of the pattern. Then, the computing platform may identify, based on the frequency of occurrence, a rule associated with the pattern. Subsequently, the computing platform may trigger, via the computing device and based on the rule, an action related to one or more of the entitlements of the pair of entitlements.


