Non-Provisioned Application Access Detection via Entity Consolidation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in monitoring and identifying non-provisioned usage of applications within their IT infrastructure, which can compromise security and regulatory compliance.

Innovation Solution

A method that collects data on software applications used by organizational identities, performs entity and application consolidation processes to identify main active directory accounts and generic application identifiers, and determines whether access is provisioned or non-provisioned, preventing access if accounts are deleted or inactive.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations implement comprehensive monitoring of all entity activities to ensure provisioned access, then security and compliance are improved, but system complexity and monitoring overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between Identity Providers and applications. This intermediary consolidates entity information and maintains application definitions, enabling automated detection of non-provisioned access without requiring complex monitoring infrastructure across the entire organization. The intermediary translates and correlates data from multiple sources to identify unauthorized access patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the monitoring system continuously compares actual access patterns against defined application permissions. When non-provisioned access is detected, the system provides feedback by identifying and reporting these anomalies, enabling organizations to take corrective action while maintaining simplified monitoring architecture through automated detection loops.

Inventive Principle:
Principle #23Feedback

2Reliability

If organizations require all employees to use provisioned access methods through Identity Providers, then security and monitoring are improved, but ease of access and user convenience deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-defining application permissions and consolidating entity information before access attempts occur. Application definitions are established in advance that specify which entities are authorized to access which applications. This pre-configuration enables automated enforcement of provisioned access requirements without adding friction to the user experience, as the system proactively identifies and blocks non-provisioned access attempts.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If organizations implement automated detection systems for non-provisioned access, then compliance monitoring is improved, but false positives and detection errors may increase

Engineering Contradiction:
Improvecompliance monitoring efficiencyVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments the detection process into distinct functional components: entity consolidation, application definition management, and access pattern analysis. By dividing the monitoring system into these specialized segments, each component can focus on its specific task with high precision. The entity consolidation segment maintains accurate entity information, the application definition segment manages permission rules, and the analysis segment detects anomalies, reducing false positives through specialized processing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12314384B1Systems and methods for detecting non-provisioned usage of applications in an organization
Publication Date: 2025.05.27 RECOLABS LTD
  • US12314384B1 patent drawing
  • US12314384B1 patent drawing
  • US12314384B1 patent drawing

AI summary

A method for identifying non-provisioned access to software applications, the method comprising collecting from resources used by an organization a data record of software applications used by entities of the organization and a list of accounts registered in the software applications, performing an entity consolidation process to identify a main AD account associated with a specific account, where the main AD account is the account used for provisioned access to the software applications, extracting a list of application definitions that the main AD account of the specific account is assigned to access in a provisioned manner, performing an application consolidation process to identify a generic application identifier associated with a specific application of the software applications, and determining whether the specific account accesses the specific application in a provisioned manner or a non-provisioned manner according to the application definitions of the main AD account associated with the specific account.