Identity Management System Account Template Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Identity and Access Management (IAM) systems require significant user intervention and time for autoprovisioning, involving system administrators to manually define account defaults, which delays deployment and may increase security risks.

Innovation Solution

An IAM system is augmented to automatically analyze existing account information and generate account templates based on detected attribute patterns, enabling automated provisioning of user accounts without manual predefinition, using script expressions for dynamic value determination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If system administrators manually specify default values for all account attributes in advance, then autoprovisioning can be implemented, but the deployment time is significantly delayed and requires extensive user intervention

Engineering Contradiction:
Improveautoprovisioning capabilityVSAvoiddeployment time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system performs self-service by automatically analyzing existing account information and discovering attribute patterns without requiring system administrators to manually pre-configure all account defaults. The autoprovisioning system provisions itself by learning from existing accounts, eliminating the need for extensive manual setup and reducing deployment time from many days to a minimal configuration phase.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary pattern recognition system that acts as a bridge between existing account information and new account provisioning. This intermediary analyzes existing accounts, discovers patterns in account attributes, and automatically generates appropriate default values for new accounts, thereby eliminating the need for manual pre-configuration while ensuring consistent and secure provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual pre-configuration of account templates is required, then security can be maintained, but the complexity of the provisioning process increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically discovers and learns security-relevant patterns from existing accounts through self-service analysis. By examining existing account attributes and their relationships, the system autonomously configures appropriate defaults for new accounts, maintaining security consistency without requiring administrators to manually understand and configure complex security parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously analyzes existing account information, learns from successful provisioning patterns, and adjusts its pattern recognition algorithms accordingly. This feedback loop ensures that security standards are maintained while the system becomes increasingly accurate in automatically determining appropriate account configurations, reducing the need for manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9979733B2Automatically provisioning new accounts on managed targets by pattern recognition of existing account attributes
Publication Date: 2018.05.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9979733B2 patent drawing
  • US9979733B2 patent drawing
  • US9979733B2 patent drawing

AI summary

An identity management system is augmented to provide for automated provisioning of user accounts in an IAM system. A user account is autoprovisioned based on detected attribute patterns. Responsive to a user request from a requesting user for access to a first target, it is determined that access will require a creation of a new account on the first target. A set of existing account information is retrieved. The retrieved set of existing account information is analyzed to discover attribute patterns in the existing account information. Next, an account template is generated according to the discovered attribute patterns. Using the generated account template, a new account on the first target is created giving the user access to the target.