Identity Access Management Risk Analysis System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale IT systems face challenges in assessing and managing security vulnerabilities, particularly due to complex access right management and high employee turnover, leading to potential abuse and misuse of access rights, which are difficult and costly to detect and remediate.

Innovation Solution

A system and method that enables decision-makers to model, analyze, and assess identity and access management (IAM) processes, including provisioning and de-provisioning, to identify risks, explore automation options, and quantify the impact of different decision scenarios, using a risk analyzer and model engine to simulate outcomes and provide actionable insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used for managing access rights, then flexibility and adaptability are maintained, but security risks increase and detection time is delayed

Engineering Contradiction:
Improvesecurity risk managementVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical processes for managing access rights with an automated computational system that uses algorithms to provision, review, and de-provision access rights. This substitution enables continuous monitoring and immediate detection of security violations, eliminating the time delay inherent in manual processes while maintaining security management flexibility through configurable policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If automated systems are implemented for access management, then detection speed improves, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the access management system into distinct functional modules: a provisioning module for granting access rights, a review module for monitoring and detecting violations, and a de-provisioning module for revoking access. This segmentation allows each module to be optimized independently for speed while the overall system complexity is managed through clear modular boundaries and defined interfaces between components.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive monitoring of access rights is implemented, then security assessment accuracy improves, but resource consumption increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements partial monitoring by focusing computational resources on detecting specific types of security violations and high-risk access patterns rather than uniformly monitoring all access events. The review module prioritizes analysis of access rights that pose greater security risks, thereby achieving high security assessment accuracy while consuming computational resources more efficiently by avoiding exhaustive monitoring of low-risk operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8397302B2System and method for analyzing a process
Publication Date: 2013.03.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8397302B2 patent drawing
  • US8397302B2 patent drawing
  • US8397302B2 patent drawing

AI summary

A system for analyzing a process, comprising a model engine to generate a model of the environment using multiple components defining adjustable elements of the model and including components representing a process for provisioning and de-provisioning of access credentials for an individual in the environment and a risk analyzer to calculate multiple randomized instances of an outcome for the environment using multiple values for parameters of the elements of the model selected from within respective predefined ranges for the parameters, and to use a results plan to provide data for identifying the security risk using the multiple instances.