SQL Permission Graph Modeling for Inherited Access Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems struggle to efficiently manage and analyze complex access entitlements in large enterprises, particularly in SQL Server databases, due to the convoluted nature of indirect or effective access inheritance, leading to scalability issues and security risks.
Innovation Solution
A SQL permissions collector that automatically discovers and models all database objects and their permissions within an identity management system, associating them with corresponding identities, providing a unified interface to view and query direct, inherited, and implicitly assigned entitlements across multiple SQL servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identity management systems implement comprehensive access entitlement management across multiple SQL servers, then security control and compliance capability are improved, but system complexity and difficulty of analysis increase due to indirect access inheritance
Solution Approach 1:
The patent segments the complex access entitlement analysis by introducing a collector component that divides the system into distinct functional units: collectors that gather entitlement data from multiple SQL servers, a graph database that stores the segmented access relationship data, and analysis components that process specific aspects of access patterns separately. This segmentation reduces overall system complexity while maintaining comprehensive security control.
Solution Approach 2:
The patent introduces a graph database as an intermediary layer between the SQL servers and the analysis components. This intermediary stores access entitlement data in a standardized format, enabling efficient querying and analysis without directly connecting analysis components to multiple SQL servers, thereby reducing system complexity while maintaining security control.
2Loss of information
If the system collects and analyzes access entitlements from multiple SQL servers, then visibility and understanding of user access rights are improved, but data collection time and processing resources increase
Solution Approach 1:
The patent implements preliminary action by having collectors continuously gather and store access entitlement data in the graph database before analysis is needed. This pre-collection approach ensures that when analysis is required, the data is already available in a standardized format, reducing analysis time while maintaining complete visibility of access entitlements across multiple SQL servers.
Solution Approach 2:
The patent creates copies of access entitlement data from multiple SQL servers and stores them in a centralized graph database. This copying approach enables efficient querying and analysis of access patterns without requiring direct access to the original SQL servers during analysis, reducing processing time while maintaining complete data visibility.
3Measurement precision
If the system provides detailed forensics and reporting capabilities for access entitlements, then security analysis precision is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent implements feedback mechanisms where the analysis components query the graph database for specific access patterns and return detailed forensic information. This feedback loop enables precise security analysis by providing targeted information about user access rights, inherited permissions, and potential security risks without requiring the entire system to be overly complex.
Solution Approach 2:
The patent applies local quality by enabling different levels of analysis precision for different security needs. The system can provide detailed forensic analysis when needed while maintaining simpler overview capabilities for routine monitoring, allowing precise measurement of access entitlements without requiring the entire system to operate at maximum complexity.
Data Source
AI summary
Embodiments as disclosed allow identity management with respect to SQL database by discovering substantially database objects and their entitlements and associating them with corresponding identities within the identity management system, thus providing insights into such SQL server entitlements and their associated identities, even across multiple SQL servers within an enterprise environment.


