Integrated Account Risk Analysis for Unused Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing account management systems face challenges in efficiently managing user accounts due to changes in user departments or tasks, leading to security risks and inefficiencies, especially when zero trust firewalls are not accurately managed, allowing attackers to hijack unused accounts.
Innovation Solution
A processor-implemented method and apparatus that perform risk analysis on individual and integrated levels, generating lists and recommendations for account management, including deletion or authority changes based on access history and location, to identify and manage unnecessary accounts or authority, thereby blocking security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If account managers directly manage accounts manually, then account management can be performed with detailed control, but it requires a huge amount of time and resources especially when the number of users and services increase
Solution Approach 1:
The system performs automatic account analysis and risk assessment without requiring manual intervention from account managers. The processor automatically identifies unused accounts, evaluates security risks, and generates management recommendations, enabling the system to manage itself rather than relying on human resources for each account management task.
Solution Approach 2:
The patent replaces the mechanical manual account management process with an automated computational system. Instead of account managers manually reviewing each account, the system uses processors to automatically analyze account data, assess risks, and generate recommendations, substituting human manual labor with automated computational mechanisms.
2Productivity
If account authority is granted broadly to ensure task completion, then users can perform required tasks efficiently, but security risks increase when users change departments or leave the company
Solution Approach 1:
The system performs preliminary risk assessment and account analysis before security issues arise. By continuously monitoring account usage patterns and identifying unused accounts in advance, the system can proactively revoke or adjust authorities before they are misused, preventing security breaches rather than reacting to them after occurrence.
Solution Approach 2:
The system establishes a feedback loop that continuously monitors account usage and automatically updates risk assessments. When account usage patterns change (such as users changing departments or leaving), the system detects these changes, reevaluates the necessary authority levels, and provides updated management recommendations to maintain both productivity and security.
3Reliability
If zero trust firewalls are implemented to secure each section, then security for each firewall section can be improved, but account management becomes more complex and requires accurate performance
Solution Approach 1:
The patent implements a universal account management system that works across multiple firewall sections and services simultaneously. The same processor-based analysis and risk assessment mechanisms are applied uniformly across all account types and service domains, providing a multi-functional solution that handles diverse account management scenarios without requiring separate complex management systems for each firewall section.
4Duration of action of stationary object
If account authority is maintained for extended periods to ensure continuous service access, then service availability is improved, but the risk of account hijacking increases when accounts become unused
Solution Approach 1:
The system implements periodic account analysis and risk reassessment instead of static long-term authority assignment. Accounts are continuously monitored and reevaluated at regular intervals based on usage patterns, allowing the system to maintain authority duration when needed while automatically detecting and flagging unused accounts for authority revocation, creating a rhythmic cycle of grant-monitor-revoke actions.
Data Source
AI summary
A processor-implemented method including generating a risk analysis on respective accounts of one or more accounts, the one or more accounts being linked to each service of one or more services, generating an integrated risk analysis on a first account, among the one or more accounts, by considering both of a first risk analysis result for a first service and a second risk analysis result for a second service, among the one or more services, and presenting an account management recommendation for the first account responsive to a result of the integrated risk analysis.


