Identity Graph Predictive Modeling for Entitlement Diffusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in managing user access entitlements in complex, distributed networked computing environments, leading to inefficiencies in compliance efforts and increased security risks due to unpredictable role evolution and entitlement diffusion, which existing identity management systems struggle to predict and control.

Innovation Solution

The implementation of a network graph approach for identity management systems that utilizes predictive modeling based on identity graphs to forecast future access events, identify pathways for entitlement spread, and predict role growth, allowing for proactive management of access risks and compliance through peer grouping and role mining.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional identity management systems are used to manage user access entitlements in large organizations, then compliance monitoring and controls can be applied, but the systems cannot predict future access events or role evolution, leading to wasted resources and inability to focus on actual security risks

Engineering Contradiction:
Improveprediction accuracy of access eventsVSAvoidcomplexity of identity management system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by using predictive modeling to forecast future access events, role evolution, and entitlement diffusion before they actually occur. The system analyzes historical access patterns and identity relationships to proactively identify potential security risks, allowing organizations to prepare appropriate controls and compliance measures in advance rather than reacting after incidents occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary predictive modeling layer between traditional identity management systems and security compliance processes. This intermediary component uses machine learning algorithms to analyze identity graphs and predict future access patterns, serving as a mediator that translates raw access data into actionable security insights without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If compliance monitoring is applied across all users and applications in large organizations, then comprehensive security coverage is achieved, but time, labor, and resources are wasted on low-risk areas

Engineering Contradiction:
Improvecompliance coverageVSAvoidefficiency of compliance efforts
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by enabling differentiated compliance monitoring based on predicted risk levels for different users, applications, and access patterns. Instead of uniform monitoring across all entities, the system identifies high-risk areas through predictive modeling and concentrates compliance resources where they are most needed, while reducing monitoring intensity in low-risk areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of compliance resource allocation from static uniform distribution to dynamic risk-based distribution. By using predictive models to continuously assess risk parameters, the system adjusts compliance monitoring intensity and resource allocation in real-time, optimizing both coverage and efficiency.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If manual processes are used to manage user access entitlements involving thousands of users and hundreds of applications, then detailed control is possible, but the process becomes difficult and complex

Engineering Contradiction:
Improveease of entitlement managementVSAvoidcomplexity of access management system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling automated entitlement management through predictive modeling. The system automatically identifies appropriate access entitlements based on user roles, historical patterns, and predicted future needs, reducing the need for manual intervention in entitlement decisions while maintaining appropriate levels of control and oversight.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses strong oxidants metaphorically by applying advanced machine learning algorithms and predictive analytics that rapidly process and analyze large volumes of identity and access data. This accelerated analysis capability enables the system to handle complex entitlement management scenarios quickly, making the process more manageable despite the scale involved.

Inventive Principle:
Principle #38Strong oxidants (Accelerated oxidation)

4Object-affected harmful factors

If organizations implement proactive access risk management to minimize insider threats, then security risk is reduced, but operational costs and resource requirements increase

Engineering Contradiction:
Improveinsider threat riskVSAvoidoperational cost
Core Design Contradiction:
Object-affected harmful factorsVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by proactively identifying potential insider threats through predictive modeling before malicious activities occur. The system analyzes behavioral patterns, access anomalies, and role evolution trends to flag high-risk users and access patterns, enabling early intervention and prevention of security incidents.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary predictive analytics layer that sits between operational identity management systems and security risk mitigation processes. This intermediary uses machine learning to process access data and generate risk predictions, enabling targeted security interventions without requiring comprehensive monitoring of all organizational activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11811833B2System and method for predictive modeling for entitlement diffusion and role evolution in identity management artificial intelligence systems using network identity graphs
Publication Date: 2023.11.07 SAILPOINT TECHNOLOGIES INC
  • US11811833B2 patent drawing
  • US11811833B2 patent drawing
  • US11811833B2 patent drawing

AI summary

Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing identities, roles, entitlements or other identity management artifacts of a distributed networked enterprise computing environment. Specifically, embodiments of an artificial intelligence based identity management systems may perform predictive modeling for entitlement diffusion or role evolution or other aspects of identity management artifact using network identity graphs.