IT Change Reconciliation via Context-Aware Authorization Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex IT systems, unauthorized changes are difficult to identify, leading to prolonged outages and increased costs due to the lack of effective monitoring and reconciliation processes.
Innovation Solution
A system and method that detect changes in configuration parameters, generate change request records, and determine an authorization score based on context information such as the implementer, scope, and time window to classify changes as authorized, unauthorized, or potentially authorized, using AI and change manifests to manage and reverse unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional monitoring methods are used in complex IT systems, then system complexity is managed, but unauthorized changes cannot be effectively identified
Solution Approach 1:
The patent segments the monitoring system into multiple specialized components: a configuration parameter detection module that collects changes from stations, a change request record management module that stores authorization information, and a reconciliation module that compares actual changes with authorized changes. This segmentation allows each component to focus on specific tasks, improving detection accuracy without overwhelming the entire system with complexity.
Solution Approach 2:
The patent introduces change request records as an intermediary data structure that bridges the gap between authorized changes (planned by administrators) and actual changes (performed in the system). These records contain authorization information, implementer details, scope, and time windows, serving as a mediator that enables precise identification of unauthorized changes by comparing actual changes against this intermediate reference layer.
2Measurement precision
If comprehensive monitoring is implemented to identify unauthorized changes, then detection accuracy improves, but processing time increases
Solution Approach 1:
The patent implements preliminary action by requiring change request records to be created and stored before actual changes are performed. These records pre-defining authorization information, approved implementers, scope, and time windows allow the system to quickly validate changes by simple comparison rather than complex analysis, significantly reducing processing time while maintaining high detection accuracy.
Solution Approach 2:
The reconciliation process provides immediate feedback by comparing actual configuration parameter changes against the pre-stored change request records. The system generates clear identification of unauthorized changes, approved changes, and potentially authorized changes, enabling rapid response and reducing the time loss associated with detecting and addressing unauthorized modifications.
3Measurement precision
If manual verification of each change is performed, then authorization accuracy improves, but productivity decreases
Solution Approach 1:
The system implements self-service by automatically performing the verification function that would otherwise require manual administrator intervention. The reconciliation module autonomously compares actual changes with authorized changes using change request records, automatically identifying unauthorized changes without requiring manual review of each change event, thus dramatically improving productivity while maintaining authorization accuracy.
Solution Approach 2:
The patent replaces the mechanical manual verification process with an automated electronic reconciliation system. Instead of administrators manually reviewing and verifying each change request and actual change, the system uses automated comparison algorithms that process configuration parameter changes against stored authorization records, substituting human manual labor with automated computational processes to improve efficiency.
4Loss of information
If change request records are maintained for all changes, then authorization tracking improves, but information management complexity increases
Solution Approach 1:
The patent extracts only the essential authorization-related information from change management processes and stores it in standardized change request records. These records contain specifically extracted fields such as authorization information, implementer details, scope, and time windows, separating critical authorization data from other operational details. This extraction approach improves authorization tracking by focusing on essential information while reducing information management complexity by excluding unnecessary data.
Data Source
AI summary
A method of change reconciliation, including: detecting changes in configuration parameters collected from stations of a system and collecting or generating change request records for the detected changes, identifying unauthorized changes and authorized changes based on given rules, for a potentially authorized change that is not clearly authorized or unauthorized, identifying a context for the change request records, including: a) identifying authorized change implementers; b) identifying a scope of the content that is to be changed; c) identifying a time window when the change is allowed to be performed; identifying a context for the actual change, including: a) identifying a change implementer; b) identifying a scope of the content that was changed; c) identifying a time window when the change was performed; comparing the context of the change request with the context of the actual change; determining an authorization score responsive to said comparing; outputting the change authorization score.


