Identity Risk Profile Generation for Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management solutions in computing environments, particularly in cloud computing, struggle to dynamically adapt to changing environments, leading to protection gaps or over-restrictions, which hinders the functionality of these environments.

Innovation Solution

A system and method that detect identities and their permissions in a computing environment, generate an identity risk profile based on activity logs and IAM services, and use this profile to determine cybersecurity risk scores, thereby managing access and initiating mitigation actions as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If predefined access policies are used to manage user accounts, then access control is established, but the system cannot adapt to dynamic changes in the computing environment

Engineering Contradiction:
Improveadaptability to environment changesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access management by continuously monitoring activity logs and automatically updating risk profiles for identities. The system transitions from static predefined policies to dynamic, real-time risk-based access control that adapts to changing environmental conditions and user behaviors without requiring manual policy updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where activity logs are continuously parsed to detect events, risk profiles are generated and updated based on detected patterns, and access decisions are made based on current risk assessments. This closed-loop feedback mechanism enables the system to learn from actual usage patterns and automatically adjust access controls.

Inventive Principle:
Principle #23Feedback

2Productivity

If manual policy updates are required to maintain access control, then security can be enforced, but operational efficiency decreases due to manual intervention needs

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity enforcement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs self-service by automatically generating and updating risk profiles based on activity log analysis. The access management system autonomously monitors user behaviors, detects anomalies, and adjusts access controls without requiring manual intervention from administrators, thereby maintaining both efficiency and security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by continuously monitoring activity logs and pre-updating risk profiles before access requests occur. This proactive approach allows the system to be ready with current risk assessments, eliminating the need for manual policy updates at the time of access requests.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If static access policies are applied to dynamic cloud environments, then implementation is simple, but protection gaps or over-restrictions occur

Engineering Contradiction:
Improveaccess control accuracyVSAvoidease of implementation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical approach of static policy-based access control with an automated risk-assessment system. Instead of relying on predefined rules, the system uses algorithmic analysis of activity logs to dynamically determine risk levels and make access decisions, improving accuracy while maintaining ease of operation through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250173444A1Techniques for providing identity cybersecurity risk assessment in digital environments
Publication Date: 2025.05.29 AVALOR TECH LTD
  • US20250173444A1 patent drawing
  • US20250173444A1 patent drawing
  • US20250173444A1 patent drawing

AI summary

A system and method for generating a cybersecurity risk profile based on an identity in a computing environment is disclosed. The method includes: detecting a plurality of identities in a computing environment, each identity including a permission to initiate an action in the computing environment; querying an identity and access management service to detect a permission associated with a first identity of the plurality of identities; accessing an activity log of the computing environment; parsing the activity log to detect an event based on the first identity; and generating an identity risk profile based on: the detected event, and the detected permission.