Automated Resource Access Certification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing and certifying access to resources within their systems, particularly in ensuring compliance with policies and regulations, as employees' access levels change due to status updates, transfers, or terminations, which can lead to security risks if not properly monitored and controlled.

Innovation Solution

A system and method for resource management and certification that includes a resource inventory, human resources data feed, termination and transfer service, ownership service, policy service, certification service, and reporting service, which monitor and adjust access rights based on employment status changes and compliance with organizational policies and regulations, ensuring timely and compliant access management across various resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access management is used, then flexibility in granting access is maintained, but security risks increase due to improper monitoring and control of access levels

Engineering Contradiction:
ImprovesecurityVSAvoidaccess management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically granting access to resources when an employee is hired or transferred, and automatically revoking access when an employee is terminated. This eliminates the need for manual access management while maintaining security, as the system proactively manages access based on employment status changes before security risks can arise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring employment status changes and automatically adjusting access levels accordingly. This closed-loop feedback ensures that access rights are always aligned with current employment status, maintaining security without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If access management is manually monitored, then compliance can be checked, but time consumption increases due to continuous monitoring requirements

Engineering Contradiction:
ImprovecomplianceVSAvoidmonitoring time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically monitoring employment status changes and compliance with access policies without requiring manual intervention. The system autonomously detects status changes, evaluates compliance requirements, and adjusts access accordingly, eliminating time-consuming manual monitoring while maintaining compliance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous automated monitoring of employment status and access compliance, ensuring that compliance checks occur continuously without interruption or manual intervention. This eliminates gaps in monitoring while reducing the time burden on human operators.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automated access management is implemented, then efficiency improves through automatic updates, but system complexity increases due to multiple services and integration requirements

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidsystem structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves universality by creating a multi-functional access management platform that handles hiring, transfers, terminations, compliance monitoring, and access granting/revoking through a single integrated system. This consolidates multiple functions into one system, improving efficiency without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system applies segmentation by dividing access management into distinct functional modules (employment status monitoring, compliance evaluation, access granting, access revoking) that can operate independently but integrate seamlessly. This modular segmentation improves efficiency by allowing parallel processing while managing complexity through clear functional boundaries.

Inventive Principle:
Principle #1Segmentation

4Reliability

If access levels are not automatically updated, then system simplicity is maintained, but security risks arise from employees retaining access after termination or transfer

Engineering Contradiction:
ImprovesecurityVSAvoidaccess update automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs preliminary actions by automatically detecting employment status changes and revoking access before security incidents can occur. When an employee is terminated or transferred, the system proactively removes access rights immediately, preventing potential security breaches while maintaining appropriate automation levels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops that continuously monitor employment status and automatically adjust access levels in response to status changes. This ensures that access rights are always aligned with current employment status, maintaining security through appropriate automation without excessive system complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9465951B1Systems and methods for resource management and certification
Publication Date: 2016.10.11 JPMORGAN CHASE BANK NA
  • US9465951B1 patent drawing
  • US9465951B1 patent drawing
  • US9465951B1 patent drawing

AI summary

Systems for managing access to a plurality of resources for an organization are disclosed, and may include a plurality of resources associated with an organization and having an access restriction; an interface for onboarding each resource to a resource inventory; a human resources data feed that identifies a status for a plurality of individuals within the organization; a termination and transfer service that changes an individual's access to a resource based on a change in the individual's status; an ownership service that assigns at least one of the individuals to be a default owner for each resource; an evergreen service that modifies the default owner for a resource based on a change in the owner's status; a policy service that monitors ownership for compliance with at least one policy; a certification service that certifies each individual's access to the plurality of resources; and a reporting service.