Transitive Identity Tracking with Polygraphs for Cloud Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods for tracking and managing identity transitions within complex compute environments, such as cloud and non-cloud settings, which can lead to security vulnerabilities and compliance issues.

Innovation Solution

A data platform with agents deployed on compute assets to collect and analyze data, creating polygraphs of user and system interactions, enabling real-time anomaly detection and identity tracking across multiple identities and roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity tracking is implemented across multiple identities and roles, then security and compliance are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments identity tracking by creating separate polygraphs for different entities (users, services, machines) and maintaining distinct identity transition logs. Each entity type has its own tracking mechanism, which simplifies the overall system architecture while enabling comprehensive security monitoring across multiple identities and roles.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces polygraphs as intermediary data structures that mediate between identity management systems and security monitoring systems. These polygraphs aggregate and normalize identity transition data, allowing the security system to monitor multiple identities without requiring direct complex interactions with each identity management component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring of identity transitions is implemented, then compliance is improved, but data processing requirements increase

Engineering Contradiction:
ImprovecomplianceVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-defining expected identity transition patterns and creating baseline polygraphs before compliance monitoring begins. This allows real-time monitoring to focus only on deviations from established patterns, reducing the data processing burden while maintaining comprehensive compliance coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and isolates critical compliance-relevant information from the broader identity transition data stream. By filtering and extracting only the essential transition events and polygraph changes that impact compliance, the system reduces data processing requirements while maintaining effective monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12405849B1Transitive identity usage tracking by a data platform
Publication Date: 2025.09.02 FORTINET INC
  • US12405849B1 patent drawing
  • US12405849B1 patent drawing
  • US12405849B1 patent drawing

AI summary

An illustrative method includes tracking, by a data platform configured to monitor a compute environment, a plurality of identity transitions that occur over time with respect to an entity, wherein each of the identity transitions includes a transition by the entity from being associated with one identity to being associated with another identity, the one identity and the another identity having different permission sets with respect to resources within the compute environment; determining, by the data platform while performing the tracking, that an attribute of the plurality of identity transitions satisfies a predetermined criterion; and performing, by the data platform based on the attribute of the plurality of transitions satisfying the predetermined criterion, a remedial action associated with the entity.