ML Identity Access Management for Dynamic Policy Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security systems for companies rely on static security policies that require manual updates and lack a streamlined approach for user information storage, authentication, and access authorization, leading to increased workload for IT professionals and inefficiencies in threat mitigation.

Innovation Solution

A machine learning-based identity access management system using a backpropagation technique within an artificial neural network algorithm to classify transactions as normal or abnormal, allowing or mitigating access based on real-time data updates and dynamic policy adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security policy is used for identity access management, then security operations can be carried out, but additional manual input from security personnel is required and the system cannot adapt dynamically to new threats

Engineering Contradiction:
Improvedynamic adaptation of security policyVSAvoidmanual input requirement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system enables self-service through machine learning models that automatically analyze transaction data, classify transactions as normal or abnormal, and update security policies without requiring manual security personnel intervention. The model continuously learns from new data and autonomously adjusts security parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where transaction outcomes are continuously fed back to the machine learning model, which then updates its classification parameters and security policies. This closed-loop feedback mechanism enables dynamic adaptation as the model learns from actual system performance and emerging threat patterns.

Inventive Principle:
Principle #23Feedback

2Productivity

If separate programs and databases are used for user information storage, authentication, and access authorization, then data security functions can be performed, but the workload for IT professionals increases and processes are not streamlined

Engineering Contradiction:
Improvestreamlined processing efficiencyVSAvoidnumber of separate programs and databases
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate security functions (user information storage, authentication, access authorization, and transaction classification) into a unified machine learning-based identity access management system. This consolidation integrates previously separate programs and databases into a single streamlined architecture that reduces complexity while improving processing efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The machine learning model serves multiple functions simultaneously: it stores user information, authenticates users, authorizes access, and classifies transactions. This multi-functional approach eliminates the need for separate specialized programs for each security operation, thereby reducing overall system complexity and improving productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional security systems are used, then basic authentication and authorization can be performed, but real-time threat mitigation and dynamic policy updates are not achieved

Engineering Contradiction:
Improvereal-time threat mitigation capabilityVSAvoidautomatic policy update capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system transitions from static security policies to dynamic, adaptive security parameters through machine learning. The model continuously adjusts security thresholds and classification criteria based on real-time transaction data analysis, enabling the system to respond dynamically to emerging threats while maintaining reliable authentication and authorization.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240135019A1Machine learning for identity access management
Publication Date: 2024.04.25 SOFTWARFARE LLC
  • US20240135019A1 patent drawing
  • US20240135019A1 patent drawing
  • US20240135019A1 patent drawing

AI summary

A computer readable medium, a system, and a method for providing data security through identity access management using a transaction classifier to classify transactions according to a set of transaction data associated with the transaction and mitigate abnormal transactions. The transaction classifier is trained using a set of training data and updated after each transaction. The identity access management may also include a mitigation policy that is used to determine a mitigation technique for each transaction.