Unified Access Path Graphs for Cloud Data Governance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face difficulties in understanding and managing data access paths in cloud environments, making it challenging to identify which users have access to sensitive data and potential vulnerabilities, both within and outside the organization.

Innovation Solution

A system that utilizes data scanners to obtain permissions and access control data, construct a unified access path graph, and visualize user access to data stores at varying levels of granularity, identifying interdependencies for remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data scanners are used to obtain and analyze permissions data and access control data to identify access paths, then data security posture management capability is improved, but system complexity increases

Engineering Contradiction:
Improvedata security posture management capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between the complex access control data sources and the security analysis requirements. This intermediary system consolidates permissions data and access control data from multiple sources, processes them through standardized methods, and presents unified access path information. By inserting this intermediary layer, the system manages complexity while maintaining reliable security posture management capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If a unified access path graph is constructed to visualize user access to data stores at varying levels of granularity, then visibility and understanding of access paths is improved, but computational resources and time increase

Engineering Contradiction:
Improvevisibility of access pathsVSAvoidcomputational time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent segments the access path visualization into multiple levels of granularity, allowing users to view information at different detail levels (e.g., high-level summary views versus detailed access path views). This segmentation enables the system to provide comprehensive visibility without always processing and displaying the maximum amount of detail, thereby reducing computational time and resource usage while maintaining information visibility when needed.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive access path analysis is performed to identify all users with access to sensitive data, then security risk identification is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity risk identification accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements partial action by performing comprehensive access path analysis selectively rather than continuously. The system identifies and analyzes access paths based on specific triggers, events, or risk thresholds, performing full analysis only when necessary. This approach maintains high security risk identification accuracy for critical scenarios while improving processing efficiency by avoiding unnecessary comprehensive analyses in routine situations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250272417A1Computing System Access Path Detection And Governance For Data Security Posture Management
Publication Date: 2025.08.28 GOLDMAN SACHS BANK USA
  • US20250272417A1 patent drawing
  • US20250272417A1 patent drawing
  • US20250272417A1 patent drawing

AI summary

A system for detection and organization of access paths in a computing environment includes a processor and memory accessible by the processor. The memory includes instructions executable to access permissions data and access control data for one or more computing resources in the computing environment, assemble a set of access paths to the one or more computing resources based on the permissions data and the access control data, trace the set of access paths to enumerate constituent elements along the access paths to the one or more computing resources, and automatically construct a unified access path graph representing the set of access paths. The unified access path graph includes node display elements connected by edge display elements to represent interdependencies between the constituent elements at one or more levels of granularity along the access paths to the one or more computing resources.