Identity Policy Generation via Usage Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face security risks due to managed identity policies often including unnecessary permissions, violating the principle of least privilege, as they may not accurately match the specific requirements of identities, leading to inefficiencies and increased effort in custom policy creation.

Innovation Solution

An identity management service employs data-based managed policy generation techniques, including identity filtering, grouping, candidate policy generation, and selection, to create policies that reduce unnecessary permissions by filtering out identities with excessive permissions, grouping similar identities, and applying policy generation rules to maximize coverage while limiting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If customers use managed policies provided by the identity management service, then policy creation time and effort are reduced, but the policies may include unnecessary permissions that violate the principle of least privilege and create security risks

Engineering Contradiction:
Improvepolicy creation timeVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary analysis of identity usage patterns, services accessed, and resources utilized before generating policies. This advance preparation allows the system to create policies that are pre-optimized for each identity's actual needs, eliminating unnecessary permissions from the start rather than requiring manual refinement afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The policy generation system automatically analyzes identity-specific data, services accessed, and resources utilized to generate customized policies without requiring customer intervention. The system serves itself by using its own collected data about identity behavior to create appropriate policies, eliminating the need for customers to manually review and adjust permissions.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If customers create custom policies to achieve precise control over access permissions, then security and precision are improved, but time and effort required for policy creation increase

Engineering Contradiction:
Improvepermission control precisionVSAvoidpolicy creation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically generates precise policies by analyzing each identity's actual usage patterns, services accessed, and resources utilized. This self-service approach eliminates the need for customers to manually create and adjust custom policies, achieving both precision and time efficiency simultaneously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors and analyzes identity behavior, services accessed, and resources utilized, using this feedback to generate and refine policies. This closed-loop approach ensures policies remain precisely aligned with actual identity needs while automating the entire process.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If managed policies include a large quantity of permissions to ensure coverage, then adaptability is improved, but the principle of least privilege is violated and security risks increase

Engineering Contradiction:
Improvepolicy coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system generates customized policies for each identity based on their specific usage patterns, services accessed, and resources utilized. Instead of applying a uniform policy with excessive permissions, each identity receives a policy tailored to their local requirements, providing appropriate coverage without unnecessary permissions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary analysis of each identity's actual needs before generating policies, ensuring that only necessary permissions are included. This advance preparation prevents the inclusion of unnecessary permissions while maintaining adequate coverage for each identity's specific requirements.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If the identity management service generates customized policies for each identity based on usage data, then precision and security are improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improvepolicy accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements a universal policy generation framework that handles multiple identities simultaneously using the same core processes. The system collects usage data, analyzes patterns, and generates policies for numerous identities through a single multi-functional system, avoiding the need for separate complex systems for each identity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically generates precise policies by analyzing each identity's actual usage patterns, services accessed, and resources utilized. This self-service approach eliminates the need for manual policy creation and review processes, reducing operational complexity while maintaining high precision through automated analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12107892B1Data-based generation of managed policies
Publication Date: 2024.10.01 AMAZON TECH INC
  • US12107892B1 patent drawing
  • US12107892B1 patent drawing
  • US12107892B1 patent drawing

AI summary

An identity set may be selected from an identity pool of an identity management service. The identity set may be selected based on a threshold quantity of unnecessary permissions relative to one or more existing managed policies provided by the identity management service. The identity set may be grouped into a plurality of identity subsets. The grouping may be performed based at least in part on services accessed by the identity set. A plurality of candidate policies may be generated, such as by generating, for each identity subset of the plurality of identity subsets, based at least in part on a plurality of policy generation rules, a respective candidate policy. At least one candidate policy of the plurality of candidate policies may be selected as a new managed policy that is provided by the identity management service to users.