Identity Trust Score System for IAM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity and access management systems are vulnerable to hacker threats, lacking effective mechanisms to assess and enhance user trust scores, which is crucial for enterprise security and risk management.

Innovation Solution

The Identity Trust Score System (ITSS) integrates with on-premise and cloud-based IAM solutions to generate an Identity Trust Score (ITS) by extracting metadata and behavioral information, using machine learning models to weigh and aggregate data, thereby providing a confidence metric for users, groups, and applications, and enabling targeted security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IAM systems are used to manage user identities, then basic access control is provided, but the systems lack effective mechanisms to assess and enhance user trust scores, making them vulnerable to hacker threats

Engineering Contradiction:
Improveuser trust assessmentVSAvoidIAM system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested architecture where the trust score computation engine is integrated within the IAM system, which itself is part of the broader enterprise identity management infrastructure. The trust score model nests multiple evaluation criteria (behavioral analysis, device information, location data) within a unified scoring framework, allowing complex assessments to be contained within a manageable system structure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The trust score computation engine acts as an intermediary layer between the IAM system and security decision-making processes. It receives raw data from multiple sources (user behavior, device information, access patterns), processes this information through machine learning models, and outputs standardized trust scores that the IAM system can use for enhanced access control decisions without directly managing the complexity of individual data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive metadata and behavioral information are collected to compute trust scores, then security assessment accuracy is improved, but data processing complexity and computational resources increase

Engineering Contradiction:
Improvetrust score accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the trust score computation into distinct modular components: behavioral analysis module, device information processing module, location data analysis module, and machine learning model evaluation module. Each module processes specific types of data independently and contributes to the overall trust score, allowing the system to handle comprehensive data collection without overwhelming processing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts evaluation parameters and weighting factors based on the specific context and data quality. The machine learning models adapt to changing patterns in user behavior and threat landscapes, modifying the importance of different data sources as needed. This allows high measurement precision without requiring all data sources to be processed at maximum detail levels simultaneously.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If machine learning models are used to weigh and aggregate identity data, then automated trust assessment is achieved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvetrust score computation automationVSAvoidsystem architecture complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The machine learning models are designed to automatically train and refine themselves using historical identity data and observed user behaviors. The system performs self-validation and continuous improvement without requiring manual intervention for model tuning or parameter adjustment. This automation extends to the entire trust score computation pipeline, from data collection to final score generation, reducing the operational complexity despite the advanced algorithms employed.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12184676B2Identity trust score for identity and access management system
Publication Date: 2024.12.31 GRAJEK GARRET
  • US12184676B2 patent drawing
  • US12184676B2 patent drawing
  • US12184676B2 patent drawing

AI summary

An identity trust score system is described. In one aspect, a computer-implemented method includes accessing, at a server, identity metadata from a remote Identity and Access Management (IAM) system, the identity metadata indicating identity events associated with one or more users of a user group of the IAM system, computing an identity trust score for the one or more users of the user group based on the identity metadata, and configuring the remote IAM system based on the identity trust score.