Multidimensional Vectors for Identity Permission Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity and permission management systems in computer systems become cumbersome and inefficient, especially in large or dynamically changing environments, as they fail to dynamically update identity groups and minimize the attack surface by creating least-privilege groups, leading to increased risks from compromised identities with excessive permissions.

Innovation Solution

The development of multidimensional vectors to analyze and visually display identity permissions, using machine learning techniques to group similar identities together, update privileges, and implement a least-privilege policy, thereby streamlining privilege management and enhancing system security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual grouping of identities is implemented, then identity management becomes more organized, but it becomes difficult to implement effectively for large systems with many identities

Engineering Contradiction:
Improveidentity managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system automatically performs identity grouping and permission analysis without requiring manual intervention. The machine learning model autonomously analyzes identity data, determines optimal groupings, and assigns permissions, allowing the system to serve itself in managing identities at scale.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical grouping processes with automated machine learning algorithms. Instead of administrators manually organizing identities, the system uses computational models to automatically analyze identity patterns, create groupings, and manage permissions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If existing permission management techniques are used, then access control is maintained, but they do not dynamically update identity groups as circumstances change

Engineering Contradiction:
Improveaccess controlVSAvoiddynamic updating
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically updates identity groupings and permissions based on changing circumstances. The machine learning model continuously analyzes identity data and automatically adjusts group assignments and permission levels as identities evolve, ensuring both reliable access control and adaptability to new conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where identity usage patterns and access behaviors are continuously monitored and fed back into the machine learning model. This feedback enables the system to learn from actual usage and automatically adjust permission assignments to maintain optimal security and accessibility.

Inventive Principle:
Principle #23Feedback

3Productivity

If identities are granted extensive permissions, then they can function effectively, but the attack surface increases if identities are compromised

Engineering Contradiction:
Improveidentity functionalityVSAvoidattack surface
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies the principle of local quality by granting permissions specifically tailored to each identity's actual needs and usage patterns. Instead of blanket extensive permissions, the machine learning model analyzes individual identity behaviors and assigns only the necessary permissions, maintaining functionality while minimizing the attack surface for each identity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes permission parameters based on identity analysis results. The machine learning model adjusts permission levels, group assignments, and access scopes as parameters, optimizing the balance between identity functionality and security exposure by granting only the minimum necessary permissions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11038927B1Multidimensional vectors for analyzing and visually displaying identity permissions
Publication Date: 2021.06.15 CYBER ARK SOFTWARE LTD
  • US11038927B1 patent drawing
  • US11038927B1 patent drawing
  • US11038927B1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for multidimensional vectors for analyzing and visually displaying identity permissions. Techniques include identifying a plurality of identities, privileges used by the identities, and data associated with the identities, developing privilege vectors based on the identified information, and generating groupings of the identities based on the privilege vectors. Further techniques include generating a group score for an identity grouping, using the group score to determine if the grouping is a least privilege grouping, and updating the privileges of the identities within the grouping.