Identity Graph Peer Grouping for Access Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large organizations, managing user access entitlements in complex, distributed networked computing environments is challenging due to high employee turnover, reorganizations, and varying access risks, leading to inefficient compliance efforts and difficulty in quantifying and mitigating access risks posed by insiders.

Innovation Solution

A network graph approach is used for peer grouping of identities, where identities and their entitlements are represented as nodes and edges in a graph, with similarity weights, allowing for clustering and optimization through pruning and feedback loops to improve identity governance and compliance assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user access management methods are used in large organizations, then compliance efforts can be applied uniformly across all users, but the complexity of managing user access entitlements increases significantly due to high employee turnover, reorganizations, and varying access risks

Engineering Contradiction:
Improvecompliance assuranceVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the organization's user base into peer groups based on graph-based similarity analysis of access patterns, roles, and attributes. This segmentation transforms the monolithic access management problem into manageable peer group units, reducing overall system complexity while maintaining compliance assurance through group-based policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the management parameter from individual user entitlements to peer group entitlements. By defining access policies at the peer group level rather than individually, the system reduces the number of parameters to manage while maintaining appropriate access control through the graph-based peer group definitions.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive access monitoring is implemented across all users, then access risks can be identified, but the computational burden and time required for compliance assessments increases

Engineering Contradiction:
Improveaccess risk detection accuracyVSAvoidcompliance assessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent divides the comprehensive access monitoring task into peer group-level assessments. By analyzing access risks at the peer group level rather than individually for each user, the system maintains detection accuracy through graph-based similarity metrics while significantly reducing the time and computational resources required for compliance assessments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates peer group representations that copy and aggregate individual user access patterns into group-level models. These peer group copies enable comprehensive risk assessment at the group level, providing accurate risk detection without the computational burden of analyzing every individual user's access entitlements separately.

Inventive Principle:
Principle #26Copying

3Ease of operation

If individual user access entitlements are managed separately, then precise control over each user's access is maintained, but the difficulty of managing thousands of users across hundreds of applications increases

Engineering Contradiction:
Improveaccess entitlement management easeVSAvoidaccess pattern insights
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent merges individual user access entitlements into peer group entitlements based on graph-based similarity analysis. This merging simplifies management operations by reducing thousands of individual entitlements to manageable peer group units while preserving access pattern insights through the graph structure that captures relationships and similarities among users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates peer groups that serve multiple functions simultaneously: they enable simplified access entitlement management, provide insights into access patterns through graph analysis, and facilitate compliance assessments. This multi-functionality reduces operational complexity while maintaining information richness about user access behaviors.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11695828B2System and method for peer group detection, visualization and analysis in identity management artificial intelligence systems using cluster based analysis of network identity graphs
Publication Date: 2023.07.04 SAILPOINT TECHNOLOGIES INC
  • US11695828B2 patent drawing
  • US11695828B2 patent drawing
  • US11695828B2 patent drawing

AI summary

Systems and methods for graph based artificial intelligence systems for identity management systems are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to peer grouping of identities of distributed networked enterprise computing environment. Specifically, in certain embodiments, data on the identities and the respective entitlements assigned to each identity as utilized in an enterprise computer environment may be obtained by an identity management system. A network identity graph may be constructed using the identity and entitlement data. The identity graph can then be clustered into peer groups of identities. The peer groups of identities may be used by the identity management system and users thereof in risk assessment or other identity management tasks.