Graph-Based Access Review for Cross-Application SoD Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in efficiently managing user access rights and segregation of duties across multiple mission-critical applications, leading to increased complexity and risk due to the exponential growth of data and complex authorization models, making it difficult to identify and mitigate security risks.
Innovation Solution
A visual model using graph-based analysis is employed to efficiently manage user access rights and segregation of duties across multiple applications, utilizing a graph model that allows for simultaneous cross-application reviews, enabling the identification of how permissions are assigned and providing a clear path for remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional methods are used to manage user access rights across multiple applications, then comprehensive security review can be achieved, but system complexity and processing time increase exponentially
Solution Approach 1:
The patent segments the complex multi-application access review into hierarchical levels: application-specific access reviews, cross-application segregation of duties reviews, and consolidated risk assessment. This segmentation allows each component to be analyzed independently while maintaining overall security comprehensiveness, preventing exponential complexity growth.
Solution Approach 2:
The patent introduces an intermediary access review system that mediates between multiple applications and users. This intermediary consolidates access rights data from various applications, applies segmentation rules, and generates unified security reviews, thereby managing complexity while maintaining comprehensive security oversight.
2Reliability
If traditional methods are used to manage user access rights across multiple applications, then comprehensive security review can be achieved, but processing time increases exponentially
Solution Approach 1:
The patent implements preliminary action by pre-establishing access review policies, segmentation rules, and risk criteria before actual access reviews are performed. Access rights data is continuously monitored and pre-processed, so when security reviews are needed, the system can quickly apply predefined rules without exponential processing delays.
Solution Approach 2:
The patent maintains continuity of useful action through continuous monitoring of access rights changes across applications. Instead of periodic batch processing that causes time delays, the system continuously tracks and updates access information, enabling real-time security reviews without exponential time increases.
3Measurement precision
If detailed tracking of permission assignments is implemented, then security risk identification improves, but data complexity and analysis difficulty increase
Solution Approach 1:
The patent applies dimensionality change by representing complex permission relationships in a graph-based model where users, applications, and permissions become nodes and relationships become edges. This visual representation transforms complex multi-dimensional permission data into an intuitive structure that maintains measurement precision while reducing analysis difficulty.
Solution Approach 2:
The patent changes parameters by transforming detailed permission data into standardized risk categories and severity levels. Instead of analyzing raw permission assignments directly, the system converts them into structured risk parameters that are easier to detect and measure while maintaining accurate tracking of underlying permission relationships.
Data Source
AI summary
Security can be improved in a business application or system, such as a mission-critical application, by automatically analyzing user access (UA) and segregation of duties (SoD). This analysis may be using a graphical representation of a model with nodes for business application concepts and edges for relationships between nodes. A review of the graphical representation is used for UA and SoD.


