Identity Graph Peer Grouping for Access Risk Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large organizations, managing user access entitlements in complex, distributed networked computing environments is challenging due to high employee turnover, reorganizations, and varying access risks, leading to inefficient compliance efforts and difficulty in quantifying and mitigating access risks posed by insiders.
Innovation Solution
A network graph approach is used for peer grouping of identities, where identities and their entitlements are represented as nodes and edges in a graph, with similarity weights, allowing for clustering and optimization through pruning and feedback loops to improve identity governance and compliance assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional user access management methods are used in large organizations, then compliance efforts can be applied uniformly across all users, but the complexity of managing user access entitlements increases significantly due to high employee turnover, reorganizations, and varying access risks
Solution Approach 1:
The patent segments the organization's user base into peer groups based on graph-based similarity analysis of access patterns, roles, and attributes. This segmentation transforms the monolithic access management problem into manageable peer group units, reducing overall system complexity while maintaining compliance assurance through group-based policies.
Solution Approach 2:
The patent changes the management parameter from individual user entitlements to peer group entitlements. By defining access policies at the peer group level rather than individually, the system reduces the number of parameters to manage while maintaining appropriate access control through the graph-based peer group definitions.
2Measurement precision
If comprehensive access monitoring is implemented across all users, then access risks can be identified, but the computational burden and time required for compliance assessments increases
Solution Approach 1:
The patent divides the comprehensive access monitoring task into peer group-level assessments. By analyzing access risks at the peer group level rather than individually for each user, the system maintains detection accuracy through graph-based similarity metrics while significantly reducing the time and computational resources required for compliance assessments.
Solution Approach 2:
The patent creates peer group representations that copy and aggregate individual user access patterns into group-level models. These peer group copies enable comprehensive risk assessment at the group level, providing accurate risk detection without the computational burden of analyzing every individual user's access entitlements separately.
3Ease of operation
If individual user access entitlements are managed separately, then precise control over each user's access is maintained, but the difficulty of managing thousands of users across hundreds of applications increases
Solution Approach 1:
The patent merges individual user access entitlements into peer group entitlements based on graph-based similarity analysis. This merging simplifies management operations by reducing thousands of individual entitlements to manageable peer group units while preserving access pattern insights through the graph structure that captures relationships and similarities among users.
Solution Approach 2:
The patent creates peer groups that serve multiple functions simultaneously: they enable simplified access entitlement management, provide insights into access patterns through graph analysis, and facilitate compliance assessments. This multi-functionality reduces operational complexity while maintaining information richness about user access behaviors.
Data Source
AI summary
Systems and methods for graph based artificial intelligence systems for identity management systems are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to peer grouping of identities of distributed networked enterprise computing environment. Specifically, in certain embodiments, data on the identities and the respective entitlements assigned to each identity as utilized in an enterprise computer environment may be obtained by an identity management system. A network identity graph may be constructed using the identity and entitlement data. The identity graph can then be clustered into peer groups of identities. The peer groups of identities may be used by the identity management system and users thereof in risk assessment or other identity management tasks.


