SQL Permission Graph Modeling for Inherited Access Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems struggle to efficiently manage and analyze complex access entitlements in large enterprises, particularly in SQL Server databases, due to the convoluted nature of indirect or effective access inheritance, leading to scalability issues and security risks.

Innovation Solution

A SQL permissions collector that automatically discovers and models all database objects and their permissions within an identity management system, associating them with corresponding identities, providing a unified interface to view and query direct, inherited, and implicitly assigned entitlements across multiple SQL servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity management systems implement comprehensive access entitlement management across multiple SQL servers, then security control and compliance capability are improved, but system complexity and difficulty of analysis increase due to indirect access inheritance

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex access entitlement analysis by introducing a collector component that divides the system into distinct functional units: collectors that gather entitlement data from multiple SQL servers, a graph database that stores the segmented access relationship data, and analysis components that process specific aspects of access patterns separately. This segmentation reduces overall system complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a graph database as an intermediary layer between the SQL servers and the analysis components. This intermediary stores access entitlement data in a standardized format, enabling efficient querying and analysis without directly connecting analysis components to multiple SQL servers, thereby reducing system complexity while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If the system collects and analyzes access entitlements from multiple SQL servers, then visibility and understanding of user access rights are improved, but data collection time and processing resources increase

Engineering Contradiction:
Improveaccess entitlement visibilityVSAvoiddata collection time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having collectors continuously gather and store access entitlement data in the graph database before analysis is needed. This pre-collection approach ensures that when analysis is required, the data is already available in a standardized format, reducing analysis time while maintaining complete visibility of access entitlements across multiple SQL servers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of access entitlement data from multiple SQL servers and stores them in a centralized graph database. This copying approach enables efficient querying and analysis of access patterns without requiring direct access to the original SQL servers during analysis, reducing processing time while maintaining complete data visibility.

Inventive Principle:
Principle #26Copying

3Measurement precision

If the system provides detailed forensics and reporting capabilities for access entitlements, then security analysis precision is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveforensics precisionVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the analysis components query the graph database for specific access patterns and return detailed forensic information. This feedback loop enables precise security analysis by providing targeted information about user access rights, inherited permissions, and potential security risks without requiring the entire system to be overly complex.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies local quality by enabling different levels of analysis precision for different security needs. The system can provide detailed forensic analysis when needed while maintaining simpler overview capabilities for routine monitoring, allowing precise measurement of access entitlements without requiring the entire system to operate at maximum complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260079929A1System and method for SQL server resources and permissions analysis in identity management systems
Publication Date: 2026.03.19 SAILPOINT TECH ISRAEL LTD
  • US20260079929A1 patent drawing
  • US20260079929A1 patent drawing
  • US20260079929A1 patent drawing

AI summary

Embodiments as disclosed allow identity management with respect to SQL database by discovering substantially database objects and their entitlements and associating them with corresponding identities within the identity management system, thus providing insights into such SQL server entitlements and their associated identities, even across multiple SQL servers within an enterprise environment.