Intelligent Agents for Identity Graph Decision Support

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems face challenges in effectively managing access entitlements in distributed networked computing environments, particularly in large organizations, due to complexity and the risk of insider threats, leading to inefficiencies in compliance monitoring and increased security risks.

Innovation Solution

The implementation of a network graph approach combined with intelligent decision support agents and artificial intelligence-based identity governance systems, which utilize machine learning classifiers to analyze access requests and provide recommendation for approval or denial, enhancing the evaluation of access data and improving identity governance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity management systems are used to manage access entitlements in large organizations, then comprehensive access control can be maintained, but the system complexity and computational burden increase significantly

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identity management system into multiple intelligent agents distributed across the network, each responsible for specific decision-making tasks. This divides the complex centralized system into smaller, manageable units that can operate independently, reducing overall system complexity while maintaining comprehensive access control through coordinated agent interactions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces graph-based identity peer grouping as an intermediary layer between individual identities and the access control system. This intermediary structure organizes identities into meaningful groups based on their relationships, simplifying the management of access entitlements by allowing policies to be applied at the group level rather than individually to each identity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional identity management systems are used to monitor compliance across all users, then thorough security monitoring can be achieved, but the time and resources required increase significantly

Engineering Contradiction:
Improvecompliance monitoring reliabilityVSAvoidcompliance monitoring time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements partial monitoring by having intelligent agents focus their compliance monitoring efforts on specific high-risk identities or groups rather than uniformly monitoring all users. The graph-based peer grouping enables the system to identify and prioritize monitoring of critical identities, achieving thorough security monitoring for high-risk areas while reducing overall monitoring time and resources.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The intelligent agents operate autonomously to perform compliance monitoring and access decisions without requiring constant human intervention. The agents self-manage the monitoring process by analyzing access requests, evaluating compliance policies, and making decisions based on the graph-based identity relationships, significantly reducing the time and human resources required for compliance monitoring.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If machine learning classifiers are implemented to evaluate access requests, then decision accuracy improves, but computational burden increases

Engineering Contradiction:
Improveaccess request evaluation accuracyVSAvoidcomputational energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary action by pre-computing graph-based features and identity peer groupings before access requests are evaluated. The system pre-processes the identity data to create structured representations and relationships, so that when access requests arrive, the machine learning classifiers can make accurate decisions using pre-prepared features rather than computing everything from scratch, significantly reducing the computational energy required for each access decision.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If graph-based identity peer grouping is implemented, then data structure efficiency improves, but initial processing complexity increases

Engineering Contradiction:
Improvedata access efficiencyVSAvoidgraph processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical or manual identity management processes with graph-based data structures and automated intelligent agents. The graph structure naturally represents identity relationships and enables efficient querying and traversal, improving data access efficiency. The complexity of graph processing is managed through automated algorithms and intelligent agents that handle the computational tasks, reducing the perceived complexity for users and operators.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11818136B2System and method for intelligent agents for decision support in network identity graph based identity management artificial intelligence systems
Publication Date: 2023.11.14 SAILPOINT TECHNOLOGIES INC
  • US11818136B2 patent drawing
  • US11818136B2 patent drawing
  • US11818136B2 patent drawing

AI summary

Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing identities or entitlements of a distributed networked enterprise computing environment. Specifically, in certain embodiments, an artificial intelligence based identity governance systems may include an intelligent decision support agent to provide an approval or denial recommendation for an access request. To provide an approval or denial recommendation, the intelligent agent may utilize a classifier trained on historical certification data. The intelligent agent may utilize features which represent relevant signals to the approval or denial decision including features that may be associated with a network graph of the identities and entitlements of the enterprise computing environment.