Identity Manager Privilege Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Business-critical information is at risk due to unused or seldom-used access privileges within information handling systems, often resulting from employees accumulating permissions that are no longer necessary as their roles change, leading to potential security threats and inefficiencies.

Innovation Solution

An identity manager correlates group membership data with access map data to create a user-resource access map, analyzing user activity logs to identify unused privileges and automatically modifying user accounts to remove or adjust these privileges based on usage thresholds, thereby ensuring only active permissions are maintained.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users are granted broad access privileges to ensure they can perform all possible tasks, then adaptability and versatility are improved, but security risks and system complexity increase due to accumulated unused permissions

Engineering Contradiction:
Improveaccess privilege coverageVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of user activity patterns before making privilege modification decisions. By monitoring and analyzing historical access logs and user behavior patterns in advance, the system identifies unused privileges and prepares modification recommendations, preventing security risks before they materialize while maintaining necessary access during the analysis period

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a continuous feedback loop where user access patterns are monitored, analyzed, and used to dynamically adjust privileges. The identity manager receives feedback from access logs and activity monitoring, processes this information to identify unused permissions, and automatically modifies user accounts accordingly, creating a closed-loop system that continuously optimizes security while maintaining adaptability

Inventive Principle:
Principle #23Feedback

2Reliability

If manual review and management of user privileges is performed, then security control is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidtime for privilege management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automated privilege management where the identity manager autonomously monitors user activity, identifies unused privileges, and modifies user accounts without requiring manual intervention. The system serves itself by automatically generating and executing privilege optimization decisions based on analyzed access patterns, eliminating the time-consuming manual review process while maintaining reliable security control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of privilege review with an automated electronic system. The identity manager uses computer-based algorithms to analyze access logs, correlate user behavior patterns, and automatically modify permissions, substituting human manual operations with automated computational processes that are both faster and more reliable

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated systems monitor and analyze user activity logs to identify unused privileges, then productivity is improved by reducing manual intervention, but device complexity and processing requirements increase

Engineering Contradiction:
Improveprivilege management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The identity manager is designed as a universal system that performs multiple functions: it monitors user activity, analyzes access patterns, identifies unused privileges, and automatically modifies user accounts. By consolidating these diverse functions into a single multi-functional platform, the system achieves high productivity in privilege management while avoiding the complexity that would result from multiple separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10230734B2Usage-based modification of user privileges
Publication Date: 2019.03.12 QUEST SOFTWARE INC
  • US10230734B2 patent drawing
  • US10230734B2 patent drawing
  • US10230734B2 patent drawing

AI summary

Systems and techniques to identify and modify unused (or seldom used) access privileges are described. Group membership data may be correlated with access map data to create a user-resource access map identifying privilege levels associated with individual user accounts to access computing resources in a computing system. User activity event logs generated as a result of user accounts accessing the resources may be correlated with the user-resource access map to identify user accounts that do not use (or seldom use) particular privilege levels to access particular resources. The identified user accounts may be modified to remove the unused (or seldom used) privileges levels.