Automated User Clustering for Enterprise Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual administration of access privileges in organizations is burdensome, requires expertise, and is prone to human error, especially when employees switch roles, leading to outdated privileges.

Innovation Solution

Automated user clustering based on personal information such as email communications and meeting data to dynamically impose security classes, reducing manual burden and human error, and enabling ongoing adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access privilege control is implemented, then security management is achieved, but it requires significant human time, expertise, and is prone to errors

Engineering Contradiction:
Improveaccess privilege control accuracyVSAvoidadministrator time and effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically discovers user relationships and determines appropriate access privileges without human intervention. The computer system analyzes communication patterns and organizational data to self-determine which users should have access to which resources, eliminating the need for manual administrator configuration and reducing errors.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of administrators reviewing and configuring access privileges is replaced with an automated computational system that uses algorithms to analyze user relationships and automatically assign permissions, transforming a labor-intensive manual process into an automated electronic system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual access privilege control is used, then initial security setup is achieved, but privileges become outdated quickly when employees switch jobs

Engineering Contradiction:
Improveaccess privilege currencyVSAvoidresponsiveness to organizational changes
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system continuously monitors and analyzes user relationships and organizational changes in real-time, automatically updating access privileges as employees move between departments or roles. This continuous operation ensures privileges remain current without requiring periodic manual reviews or interventions.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system continuously gathers feedback from organizational data sources such as communication patterns and directory services, automatically adjusts access privileges based on detected changes in user relationships, and maintains up-to-date security permissions that reflect current organizational structure.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If automated user clustering is implemented, then access control is improved and manual burden is reduced, but system complexity increases

Engineering Contradiction:
Improveaccess privilege management automationVSAvoidsystem architecture complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system uses a single automated platform that performs multiple functions: discovering user relationships, determining organizational structure, analyzing communication patterns, and assigning access privileges. This multi-functional approach consolidates what would otherwise require multiple separate systems into one unified solution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an automated intermediary layer between organizational data sources and access control systems. This intermediary automatically processes relationship data, determines appropriate privileges, and interfaces with existing security infrastructure, managing complexity internally while presenting a simplified interface to administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9699196B1Providing security to an enterprise via user clustering
Publication Date: 2017.07.04 EMC IP HLDG CO LLC
  • US9699196B1 patent drawing
  • US9699196B1 patent drawing
  • US9699196B1 patent drawing

AI summary

A computer-implemented technique provides security to an enterprise. The technique involves receiving, by processing circuitry, personal information belonging to users of the enterprise. The technique further involves providing, by the processing circuitry, lists of user identifiers based on user relationships defined by the personal information. The lists of user identifiers respectively identify clusters of users of the enterprise. The technique further involves electronically imposing, by the processing circuitry, security classes on the clusters of users of the enterprise based on the lists of user identifiers. Along these lines, such classification can be used for risk assessment (e.g., authentication), alert filtering (e.g., filtering false alarms), and permission/privilege monitoring and/or assignment, among others.