Role Mining via Network Graph Peer Grouping for Identity Governance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in effectively managing user access entitlements in complex, distributed networked computing environments, leading to increased security risks and compliance issues due to the evolution of roles and identities over time, which existing identity management systems struggle to accurately assess and manage.
Innovation Solution
The implementation of a network graph approach for role mining in identity management systems, utilizing peer grouping of identities and entitlements to identify and model current access entitlement patterns, allowing for accurate bottom-up role mining and identification of new roles, deprecated entitlements, and outlier entitlements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional identity management systems are used to manage user access entitlements in large organizations, then compliance monitoring and controls can be applied, but the systems cannot accurately assess and manage evolving roles and identities, leading to wasted resources and inability to focus on actual security risks
Solution Approach 1:
The patent segments the complex identity management problem into distinct components: identities, roles, and entitlements. It introduces role mining technology that separately identifies and analyzes each component, then reconstructs their relationships. This segmentation allows the system to handle large numbers of identities and entitlements without becoming unmanageable, as each segment can be processed independently using specialized algorithms.
Solution Approach 2:
The patent introduces role mining as an intermediary process between traditional identity management systems and compliance monitoring. This intermediary layer analyzes identity data, discovers roles and entitlements, and provides structured information to downstream systems. The role mining component acts as a mediator that transforms unstructured access data into meaningful role-based patterns, enabling accurate assessment without directly modifying the underlying complex systems.
2Object-affected harmful factors
If comprehensive compliance monitoring is applied to all users and applications, then security coverage is maximized, but time and resources are wasted on areas of greatest access risk rather than being focused there
Solution Approach 1:
The patent applies local quality by enabling differentiated compliance monitoring based on identified risk levels. Instead of uniform monitoring across all users and applications, the system uses role mining to identify high-risk roles and entitlements, then concentrates monitoring resources on those specific areas. This allows the organization to maintain strong security coverage while reducing time and resources spent on low-risk areas.
Solution Approach 2:
The patent implements feedback mechanisms where role mining continuously analyzes access patterns and identifies emerging security risks. This feedback loop enables the system to dynamically adjust compliance monitoring focus based on actual risk levels rather than static policies. The system learns from observed access behaviors and redirects monitoring resources to areas where they are most needed, reducing overall time investment while maintaining or improving security coverage.
3Measurement precision
If role mining is performed on the entire identity graph, then complete role discovery is achieved, but computational burden increases and performance decreases
Solution Approach 1:
The patent segments the identity graph into manageable components for role mining operations. It divides the graph into subgraphs based on identities, roles, and entitlements, allowing parallel processing of different segments. This segmentation enables complete role discovery across the entire organization while maintaining computational efficiency, as each segment can be processed independently and results aggregated.
Solution Approach 2:
The patent implements partial role mining by allowing users to specify scopes for role discovery operations. Instead of always performing exhaustive mining on the entire identity graph, the system can perform partial mining on specific subsets of identities or entitlements when full discovery is not required. This approach maintains productivity for routine operations while preserving the capability for complete discovery when needed, balancing completeness with computational efficiency.
Data Source
AI summary
Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing identities or entitlements of a distributed networked enterprise computing environment. Specifically, in certain embodiments, an artificial intelligence based identity management systems may utilize the peer grouping of an identity graph (or peer grouping of portions or subgraphs thereof) to identify roles from peer groups or the like.


