IAM Attribute Normalization Using Transform Models and Posture Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity and access management systems struggle to efficiently ingest and normalize diverse attribute formats from disparate sources, leading to inconsistencies and challenges in applying policies accurately.
Innovation Solution
A method involving a transform model that correlates source attributes with standard attributes, enabling the mapping and normalization of identity and access management attributes, along with a posture scoring system to flag non-compliant identities for review.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If diverse attribute formats from disparate sources are ingested without normalization, then data variety and source coverage are improved, but data consistency and policy application accuracy deteriorate
Solution Approach 1:
The patent introduces a normalization layer with transform models that act as intermediaries between diverse source systems and the policy engine. This normalization layer standardizes attributes from multiple sources into a common format, enabling both broad source coverage and consistent policy application without requiring changes to source systems or the policy engine itself.
Solution Approach 2:
The transform models dynamically adjust and map source-specific attribute parameters to standardized parameters. By changing the parameter representation through transformation functions, the system maintains adaptability to various source formats while ensuring data consistency for policy evaluation, resolving the contradiction between source diversity and data uniformity.
2Measurement precision
If manual normalization processes are used for attribute mapping, then mapping accuracy is improved, but processing time and operational complexity increase
Solution Approach 1:
The system performs preliminary normalization by pre-defining transform models that map source attributes to standardized attributes before policy evaluation occurs. These transform models are established in advance and automatically applied during attribute ingestion, eliminating the need for manual normalization during runtime and significantly reducing processing time while maintaining accuracy.
Solution Approach 2:
The transform models enable self-service normalization where the system automatically maps and normalizes attributes without requiring manual intervention. The models autonomously handle the transformation process, achieving both high mapping accuracy through pre-configured mappings and rapid processing through automated execution, thereby resolving the time-accuracy tradeoff.
3Measurement precision
If comprehensive attribute collection from multiple sources is implemented, then user identification accuracy is improved, but system complexity and computational resources increase
Solution Approach 1:
The patent segments the attribute collection and processing system into distinct modular components: source systems, normalization layer with transform models, and policy engine. Each component handles specific tasks independently, reducing overall system complexity while enabling comprehensive attribute collection. The segmentation allows the system to process attributes from multiple sources without creating monolithic complexity.
Solution Approach 2:
The normalization layer serves as a universal interface that handles attributes from multiple diverse sources through a single standardized mechanism. This multi-functional normalization layer consolidates what would otherwise require multiple specialized processing paths, reducing system complexity while maintaining the capability to collect and process comprehensive attributes for accurate user identification.
Data Source
AI summary
One variation of the method includes: accessing a set of objects generated by a set of sources connected to a computer network, the set of objects including an object defining: a source field; and a source attribute value corresponding to the source field; defining a transformation between the source field and a standard field based on a transform model; identifying an identity characterized by the source attribute value; storing the source attribute value in an identity container representing the identity, the source attribute value corresponding to the standard field; identifying a policy valid for the identity based on the identity container; calculating a posture score for the identity based on correspondence between the policy and the source attribute value; and, in response to the posture score exceeding a threshold posture score, flagging the identity for review by security personnel associated with the computer network.


