Identity Time Machine for Access History Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy identity and access management solutions are ill-equipped to handle the challenges of secure authentication and authorization in cloud-based services, particularly with the increasing number of identities, volume of activities, and remote working, leading to difficulties in managing identity, entitlements, and access history.
Innovation Solution
The disclosed technology introduces an identity time machine that captures and stores identity management events with as-of time stamps, enabling the examination of the state of identity management objects at any arbitrary prior time, thus providing a comprehensive view of user access and compliance with stringent regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If security information and event management (SIEM) technology is used to collect and analyze security events, then the ability to examine access history is improved, but device complexity and resource consumption increase significantly
Solution Approach 1:
The patent extracts the history examination functionality from complex SIEM systems and implements it natively within the identity management system itself. The history examination component is integrated into the core identity management architecture, allowing access history to be examined without requiring separate, complex SIEM infrastructure.
Solution Approach 2:
The identity management system is designed to perform multiple functions including authentication, authorization, and history examination within a single unified platform. This multi-functionality eliminates the need for separate specialized systems and reduces overall system complexity while maintaining comprehensive security event analysis capabilities.
2Reliability
If audit logs are used to track compliance information, then regulatory compliance capability is improved, but time and resources required to retrieve and analyze compliance data increase enormously
Solution Approach 1:
The system pre-processes and structures compliance data during normal operations, organizing audit information in advance according to regulatory requirements. This preliminary organization enables rapid retrieval and analysis of compliance data when audits are needed, eliminating the need to sift through unstructured logs during compliance reviews.
Solution Approach 2:
The patent introduces an intermediary component that sits between the identity management operations and the audit compliance requirements. This intermediary continuously monitors and captures relevant compliance information in a structured format, making it easily accessible for regulatory audits without requiring direct analysis of raw operational logs.
3Reliability
If traditional access management systems are used to support single sign-on, then authentication capability is improved, but the ability to examine and manage access history deteriorates
Solution Approach 1:
The patent merges the authentication functionality with the history examination capability into a single integrated system. The identity management system simultaneously handles single sign-on authentication and maintains comprehensive access history, allowing both functions to work together rather than as separate competing systems.
Solution Approach 2:
The history examination capability is nested within the authentication system architecture. The access history examination component is embedded in the identity management platform, allowing it to leverage the same data structures and access paths that the authentication system already uses, thereby enhancing history visibility without compromising authentication reliability.
Data Source
AI summary
The disclosed technology teaches a computer-implemented method of enabling identity governance administration to examine the state of identity management objects at an arbitrary prior time. The method includes maintaining a data store of identity management objects used for identity governance administration, including specification of user roles from which permissions or authorizations derive and recording in the data store copies of identity management objects with an as-of time stamp at each creation, change and deletion of each identity management object. Also included is retaining time-stamped versions of the objects for a queryable time window. The method also includes receiving a query with an as-of time criteria for at least some of the identity management objects and returning responsive objects from which the permissions or authorizations were derived at the as-of-time. Responding to the query with the responsive objects that correspond to the as-of time criteria in the query is also disclosed.


