Automated Privileged Access Mapping Across Diverse IT Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient and automated method to discover and analyze privileged access across multiple computing platforms, particularly in organizations with diverse IT environments, leading to potential security risks and compliance challenges.

Innovation Solution

A system and method for automated privileged access analysis (APAA) that retrieves, parses, and maps account data from various computing platforms, applies predefined and customizable rules to determine privilege levels, and generates reports, using job scheduling and machine learning to optimize the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated privileged access discovery is implemented across multiple computing platforms, then security monitoring capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal privileged access discovery system that can connect to and analyze multiple different computing platforms (Windows, Linux, Unix, macOS, cloud environments) through a single unified interface. The system uses standardized data collection methods and common analysis algorithms that work across all platforms, eliminating the need for separate monitoring systems for each platform type while maintaining comprehensive security monitoring capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer consisting of agents installed on target systems and a central server that mediates between diverse computing platforms and the analysis engine. These agents collect privileged access data from their respective platforms and transmit it to the central server, which then performs unified analysis. This intermediary architecture simplifies the overall system by handling platform-specific complexities at the agent level while presenting a standardized interface at the server level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If comprehensive account data is collected and analyzed across multiple platforms, then privileged access visibility is improved, but data processing time increases

Engineering Contradiction:
Improveprivileged access visibilityVSAvoiddata processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent segments the privileged access discovery process into distinct modular components: data collection phase, data processing phase, and reporting phase. The system collects account data from multiple platforms in parallel, processes different types of data (account information, entitlements, permissions) through specialized analysis routines, and generates targeted reports. This segmentation allows the system to handle large volumes of cross-platform data efficiently by processing different data types concurrently rather than sequentially.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-defining analysis rules, entitlement mappings, and privilege criteria before the actual discovery process begins. The system pre-configures platform-specific data formats and normalization rules, so when data is collected from multiple platforms, it can be quickly processed and mapped to standardized privilege categories without requiring complex real-time analysis decisions.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated job scheduling is implemented for discovery processes, then operational efficiency is improved, but automation complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidautomation complexity
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements automated job scheduling that performs privileged access discovery at periodic intervals (daily, weekly, or monthly) rather than requiring continuous manual execution. The system automatically triggers discovery jobs based on scheduled timelines, ensuring regular updates of privileged access information across all connected platforms without requiring manual intervention. This periodic automation maintains operational efficiency while using simple, well-understood scheduling mechanisms.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12386991B2Systems and methods for automated discovery and analysis of privileged access across multiple computing platforms
Publication Date: 2025.08.12 ERNST & YOUNG U S LLP
  • US12386991B2 patent drawing
  • US12386991B2 patent drawing
  • US12386991B2 patent drawing

AI summary

In some embodiments, a method includes retrieving data associated with each account from a set of accounts from one or more computing platforms and parsing the data to determine a set of characteristics associated with each account from the set of accounts. The method includes mapping, based on an entitlement value of each account, a first subset of accounts from the set of accounts to a first privilege value, and mapping, based on an entitlement value of each account, a second subset of accounts from the set of accounts to a second privilege value. The method includes generating a report indicating the first subset of accounts having the first privilege value and the second subset of accounts having the second privilege value. In some implementations, the method includes scheduling a set of jobs to execute the jobs automatically in response to at least one trigger event.