Nested Access Knowledge Graphs for Cloud IAM Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity and access management (IAM) systems in cloud environments fail to track layered access patterns, leading to incomplete visibility into access ecosystems, inability to detect over-privileges, and challenges in ensuring regulatory compliance.

Innovation Solution

A resource access security system that monitors layered access paths by combining data from various sources, correlating identities with resources, and using access knowledge graphs to visualize and manage access permissions, thereby enabling the detection of over-privileges and compliance with regulatory requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional IAM systems are used to manage access, then basic access control is provided, but layered access patterns cannot be tracked and visibility into access ecosystems remains incomplete

Engineering Contradiction:
Improvevisibility into access ecosystemsVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements nested access knowledge graphs where graphs are embedded within other graphs to represent hierarchical access relationships. Inner graphs represent specific access paths while outer graphs provide broader context, enabling tracking of multi-layered access patterns without requiring a completely separate system for each access level.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent adds a new dimension to access management by creating visual knowledge graphs that map access relationships in a graphical space rather than traditional tabular formats. This dimensional transformation enables comprehensive visibility into layered access paths by representing entities, resources, and access relationships as interconnected nodes and edges in a visual landscape.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive access tracking is implemented to detect over-privileges, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors access patterns and feeds this information back into the access knowledge graphs. By comparing actual access behavior against defined access policies and hierarchical relationships, the system automatically detects anomalies such as over-privileges and generates alerts, creating a closed-loop feedback mechanism that improves security detection without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access knowledge graph serves as an intermediary layer between raw access logs and security analysis. Instead of directly analyzing complex access logs, the system translates them into structured knowledge graphs that represent access relationships, making it easier to detect security issues while reducing the computational complexity of direct log analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If detailed access policy enforcement is implemented to ensure regulatory compliance, then compliance accuracy is improved, but processing time increases

Engineering Contradiction:
Improvecompliance accuracyVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system pre-processes and structures access policies and hierarchical relationships into access knowledge graphs before compliance checking is needed. By organizing access policies, entities, and resources into predefined graphical representations with established relationships, the system eliminates the need for complex real-time policy interpretation during compliance verification, significantly reducing processing time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250193198A1Resource access security
Publication Date: 2025.06.12 CAPITAL ONE SERVICES LLC
  • US20250193198A1 patent drawing
  • US20250193198A1 patent drawing
  • US20250193198A1 patent drawing

AI summary

In some implementations, a resource access security system may obtain a plurality of identifiers of a plurality of entities, one or more indications of a plurality of resources, and one or more indications of one or more access policies that control access to the plurality of resources by the plurality of entities. The resource access security system may determine that the one or more access policies permit access to a resource, of the plurality of resources, by a first entity of the plurality of entities, via at least a second entity of the plurality of entities. The resource access security system may perform, based at least in part on determining that the one or more access policies permit access to the resource by the first entity via at least the second entity, a security action associated with the resource.