Separation-of-Duties Verifier for IAM Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity access management (IAM) systems face challenges in efficiently managing access rights to computing resources, particularly in large enterprises, as they often require manual processes that can lead to mistakes and inconsistencies, and business personnel lack the technical expertise to request changes or conduct access reviews effectively.
Innovation Solution
Implementing an IAM data model that separates logical and physical aspects of access management, allowing business personnel to submit requests and reviews in business terms while technology personnel manage the technical implementation, with a system that includes a separation-of-duties verifier to check for incompatible access rights and automate the provisioning and reconciliation of access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If manual processes are used for managing access rights, then flexibility in handling complex enterprise scenarios is improved, but mistakes and inconsistencies increase leading to reduced reliability
Solution Approach 1:
The system enables self-service access request submission through a portal where business personnel can independently request access rights without manual intervention. The automated workflow engine then processes these requests, performs separation of duties verification, and provisions access rights automatically, eliminating manual errors while maintaining flexibility for complex scenarios through configurable policies.
Solution Approach 2:
The patent replaces manual mechanical processes with an automated computer-implemented system. The workflow engine automatically routes access requests, the separation of duties verifier automatically checks for conflicts, and the system automatically provisions or denies access rights. This substitution of manual mechanics with automated electronic processes maintains adaptability while significantly improving reliability.
2Ease of operation
If business personnel directly manage technical access infrastructure, then control over access rights is improved, but operational complexity increases due to lack of technical expertise
Solution Approach 1:
The patent introduces an intermediary access management system that sits between business personnel and the technical infrastructure. Business personnel interact with a simplified portal interface to request access rights in business terms. The system automatically translates these requests into technical provisioning actions, performing separation of duties verification and coordinating with underlying infrastructure systems. This intermediary layer shields users from technical complexity while maintaining control.
Solution Approach 2:
The system segments the access management process into distinct functional components: a user-facing portal for request submission, a workflow engine for process orchestration, a separation of duties verifier for security validation, and infrastructure integration layers for technical provisioning. This segmentation allows business personnel to interact only with the simplified portal interface while the backend components handle technical complexity independently.
3Productivity
If automated systems are used for access provisioning, then efficiency and consistency are improved, but the ability to handle nuanced business scenarios may be reduced
Solution Approach 1:
The system employs dynamic, configurable policies and workflows that can adapt to different business scenarios. The separation of duties verification rules, access request approval workflows, and provisioning parameters are all configurable to accommodate nuanced business requirements. The system can dynamically adjust its behavior based on the specific context of each access request, maintaining high efficiency while preserving adaptability to complex scenarios.
Solution Approach 2:
The patent utilizes configurable parameters and policies that can be modified to accommodate different business scenarios. The separation of duties verification can be configured with different rule sets, the workflow engine can be parameterized with different approval thresholds and routing logic, and the provisioning system can adapt parameters based on resource types and user roles. This parametric approach enables automated efficient processing while maintaining versatility for nuanced scenarios.
Data Source
AI summary
Systems and methods of verifying separation-of-duties (SoD) for requested access rights to physical computing resources are provided. An SoD verifier may receive and access request and obtain a set of current permissions associated with a requestee specified in the access request. The SoD verifier may also obtain a set of new permissions to provision for the requestee based on the access request. The SoD verifier may determine whether one of the current permissions is incompatible with one of the new permissions. The SoD verifier may provide an indication of whether the access request represents an SoD violation.


