IP Library › Granted Patent US 11,206,268
Granted Patent B2
US 11,206,268 · App. 16/224,038 · Granted Dec 21, 2021

Account lifecycle management

Inventors: Christopher Festa (Jersey City, NJ); Jody Spearing (Jersey City, NJ)
Assignee: JPMORGAN CHASE BANK, N.A.
H04L63/102G06F21/604H04L63/101H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,206,268
App. No.
16/224,038
Granted
Dec 21, 2021
Kind
B2
Abstract

An account lifecycle management system is provided. The system includes a discovery engine configured to discover and identify an account. The system further includes a policy engine configured to identify privileged access data granted to the account identified by the discovery engine. The system further includes a data modeling engine configured to associate the identified privileged access data with organizational information. The system further includes a remediation engine configured to remediate the account based on the associated privileged access data.

Claims (45)

1. A system for managing user access privileges within a computer network, wherein the system comprises at least one processor in communication with a memory, the at least one processor configured to implement:

a discovery engine configured to discover and identify an existing user account from a source list, the source list comprising a list of at least one account repository that is curated based on a predetermined preference;

a policy engine configured to identify privileged access data granted to the existing user account, the privileged access data including at least one access privilege level that corresponds to a system control level, an update data level, an appropriate access level, an unvetted access level, and a sensitive read level;

a data modeling engine configured to:

determine recommended organizational data to associate with the privileged access data based on a likelihood that the existing user account is associated with a business unit with a corresponding business unit access privilege; and

associate the privileged access data with the recommended organizational data, the recommended organizational data comprising associated application data, support team data, and business unit data; and

a remediation engine configured to modify access privileges of the existing user account.

2. The system of claim 1 , wherein the at least one processor is further configured to implement a mitigation engine configured to apply an exception to the modified access privileges of the existing user account.

3. The system of claim 2 , wherein the mitigation engine is configured to split the existing user account into multiple new user accounts.

4. The system of claim 1 , wherein the discovery engine is configured to identify the existing user account as a single user account or a functional account.

5. The system of claim 4 , wherein the existing user account is a single user account associated with a Security Identifier (SID).

6. The system of claim 5 , wherein the existing user account is a functional account, wherein the functional account includes a shared interactive account, an application-to-application account, a hybrid account, a platform default account, and an active directory primary account.

7. The system of claim 5 , wherein remediation engine is configured to modify access privileges of the existing user account based on the type of functional account identified by the discovery engine.

8. The system of claim 7 , wherein the remediation engine is configured to modify access privileges of the existing user account identified as a shared interactive account by: disabling the existing user account, removing the existing user account, reducing privileges of the existing user account, or onboard the existing user account to an Enterprise Password Vault (EPV).

9. The system of claim 7 , wherein the remediation engine is configured to modify access privileges of the existing user account identified as a hybrid account by splitting the existing user account into a shared interactive account and an application-to-application account.

10. A computer implemented method for account lifecycle management, the method comprising:

identifying an existing account that is associated with a user from a source list, the source list comprising a list of at least one account repository that is curated based on a predetermined preference;

identifying privileged access data granted to the existing user account, the privileged access data including at least one access privilege level that corresponds to a system control level, an update data level, an appropriate access level, an unvetted access level, and a sensitive read level;

determining recommended organizational information to associate with the privileged access data based on a likelihood that the existing user account is associated with a business unit with a corresponding business unit access privilege;

associating the privileged access data with the recommended organizational information, the recommended organizational information comprising associated application information, support team information, and business unit information; and

modifying access privileges of the existing user account.

11. The method of claim 10 , further comprising:

applying an exception to the modified access privileges of the existing user account.

12. The method of claim 11 , further comprising:

splitting the existing user account into multiple new user accounts.

13. The method of claim 10 , further comprising:

identifying the existing user account as a single user account or a functional account.

14. The method of claim 13 , further comprising:

identifying the existing user account as a single user account associated with a Security Identifier (SID).

15. The method of claim 14 , further comprising:

identifying the existing user account as a functional account, wherein the functional account includes a shared interactive account, an application-to-application account, a hybrid account, a platform default account, and an active directory primary account.

16. The method of claim 15 , further comprising:

modifying access privileges of the existing user account based on the type of functional account identified by the discovery engine.

17. The method of claim 16 , further comprising:

modifying access privileges of the existing user account identified as a shared interactive account by: disabling the existing user account, removing the existing user account, reducing privileges of the existing user account, or onboard the existing user account to an Enterprise Password Vault (EPV).

18. The method of claim 16 , further comprising:

modifying the access privileges of the existing user account identified as a hybrid account by splitting the existing user account into a shared interactive account and an application-to-application account.

19. The method of claim 10 , further comprising:

modifying access privileges of the existing user account based on at least one input received from a dashboard user interface.

20. A non-transitory computer readable medium having instructions stored thereon for executing a method of account lifecycle management, that, when executed by a processor, cause the processor to perform operations comprising:

identifying an existing account that is associated with a user from a source list, the source list comprising a list of at least one account repository that is curated based on a predetermined preference;

identifying privileged access data granted to the existing user account, the privileged access data including at least one access privilege level that corresponds to a system control level, an update data level, an appropriate access level, an unvetted access level, and a sensitive read level;

determining recommended organizational information to associate with the privileged access data based on a likelihood that the existing user account is associated with a business unit with a corresponding business unit access privilege;

associating the privileged access data with the recommended organizational information, the recommended organizational information comprising associated application information, support team information, and business unit information; and

modifying access privileges of the existing user account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2019
From: FESTA, CHRISTOPHER; SPEARING, JODY
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 048632/0581 →
Continuity (1)
Related Publication 20200195651A1 · Jun 18, 2020