IP Library › Granted Patent US 12,619,765
Granted Patent B2
US 12,619,765 · App. 17/708,341 · Granted May 5, 2026

Existing policy determinations for an identity set

Inventor: Atiye Alaeddini (Kirkland, WA)
Assignee: Amazon Technologies, Inc.
G06F21/6245G06F21/30G06F21/604G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,765
App. No.
17/708,341
Filed
Mar 30, 2022
Granted
May 5, 2026
Kind
B2
Art Unit
2426
USPC
726/28
Abstract

A plurality of identities may be added to a new policy identity pool associated with new policy generation. Each identity of the plurality of identities may have respective selected permissions associated with permission usage by the identity. A new policy may be generated, based on a set of new policy constraints, that corresponds to a largest group of identities within the new policy identity pool for which the set of new policy constraints is satisfied. The set of new policy constraints may include a first constraint that the new policy includes the respective selected permissions for each identity within the largest group of identities and a second constraint that the new policy does not exceed one or more maximum additional permission thresholds. One or more indications may be provided, to a user, to attach the new policy to each identity within the largest group of identities.

Claims (41)

1 . A computing system comprising:

one or more processors; and

one or more memories having stored therein instructions that, upon execution by the one or more processors, cause the one or more processors to perform operations comprising:

adding a plurality of user sets to a user set pool associated with new policy generation, wherein each user set of the plurality of user sets has respective permissions associated with permission usage by the user set, wherein the respective permissions include one or more permissions that have been used by the user set within a prior time window;

generating, based on a set of new policy constraints, a new policy that corresponds to a largest group of user sets within the user set pool for which the set of new policy constraints is satisfied, wherein the set of new policy constraints includes a first constraint that the new policy includes the respective permissions for each user set within the largest group of user sets and a second constraint that the new policy does not exceed one or more additional permission thresholds;

providing, to a user, one or more indications to attach the new policy to each user set within the largest group of user sets;

removing the largest group of user sets from the user set pool; and

repeating the generating, the providing, and the removing until the user set pool is empty.

2 . The computing system of claim 1 , wherein the operations further comprise:

determining, individually for each user set of the plurality of user sets, that there is no group of one or more existing policies that satisfies a set of existing policy constraints for the user set.

3 . The computing system of claim 2 , wherein each user set of the plurality of user sets is added to the user set pool based on there being no group of one or more existing policies that satisfies the set of existing policy constraints for the user set.

4 . The computing system of claim 1 , wherein the set of new policy constraints further includes a third constraint that the new policy does not exceed a permission quantity threshold.

5 . A computer-implemented method comprising:

adding a plurality of user sets to a user set pool associated with new policy generation, wherein each user set of the plurality of user sets has respective permissions associated with permission usage by the user set, wherein the respective permissions include one or more permissions that have been used by the user set within a prior time window;

generating, based on a set of new policy constraints, a new policy that corresponds to a largest group of user sets within the user set pool for which the set of new policy constraints is satisfied, wherein the set of new policy constraints includes a first constraint that the new policy includes the respective permissions for each user set within the largest group of user sets and a second constraint that the new policy does not exceed one or more additional permission thresholds; and

providing, to a user, one or more indications to attach the new policy to each user set within the largest group of user sets.

6 . The computer-implemented method of claim 5 , wherein the one or more additional permission thresholds comprise a plurality of additional permission thresholds, and wherein each user set of the user set pool has a respective additional permission threshold of the plurality of additional permission thresholds.

7 . The computer-implemented method of claim 5 , further comprising:

determining, individually for each user set of the plurality of user sets, that there is no group of one or more existing policies that satisfies a set of existing policy constraints for the user set.

8 . The computer-implemented method of claim 7 , wherein each user set of the plurality of user sets is added to the user set pool based on there being no group of one or more existing policies that satisfies the set of existing policy constraints for the user set.

9 . The computer-implemented method of claim 5 , further comprising:

removing the largest group of user sets from the user set pool; and

repeating the generating, the providing, and the removing until the user set pool is empty.

10 . The computer-implemented method of claim 5 , wherein the set of new policy constraints further includes a third constraint that the new policy does not exceed a permission quantity threshold.

11 . The computer-implemented method of claim 5 , wherein the user set pool is a user set cluster of a plurality of user set clusters formed based on a permission-based clustering of a parent user set pool.

12 . The computer-implemented method of claim 5 , further comprising:

determining, for each user set of the plurality of user sets, the respective permissions.

13 . The computer-implemented method of claim 5 , wherein the respective permissions further include permissions that are estimated to have greater than a threshold probability of being used, by the user set, in a future time period.

14 . One or more non-transitory computer-readable storage media having stored thereon computing instructions that, upon execution by one or more computing devices, cause the one or more computing devices to perform operations comprising:

adding a plurality of user sets to a user set pool associated with new policy generation, wherein each user set of the plurality of user sets has respective permissions associated with permission usage by the user set, wherein the respective permissions include one or more permissions that have been used by the user set within a prior time window;

generating, based on a set of new policy constraints, a new policy that corresponds to a largest group of user sets within the user set pool for which the set of new policy constraints is satisfied, wherein the set of new policy constraints includes a first constraint that the new policy includes the respective permissions for each user set within the largest group of user sets and a second constraint that the new policy does not exceed one or more additional permission thresholds; and

providing, to a user, one or more indications to attach the new policy to each user set within the largest group of user sets.

15 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the one or more additional permission thresholds comprise a plurality of additional permission thresholds, and wherein each user set of the user set pool has a respective additional permission threshold of the plurality of additional permission thresholds.

16 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the operations further comprise:

determining, individually for each user set of the plurality of user sets, that there is no group of one or more existing policies that satisfies a set of existing policy constraints for the user set.

17 . The one or more non-transitory computer-readable storage media of claim 16 , wherein each user set of the plurality of user sets is added to the user set pool based on there being no group of one or more existing policies that satisfies the set of existing policy constraints for the user set.

18 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the operations further comprise:

removing the largest group of user sets from the user set pool; and

repeating the generating, the providing, and the removing until the user set pool is empty.

19 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the set of new policy constraints further includes a third constraint that the new policy does not exceed a permission quantity threshold.

20 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the respective permissions further include permissions that are estimated to have greater than a threshold probability of being used, by the user set, in a future time period.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2022
From: ALAEDDINI, ATIYE
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 059441/0511 →
Continuity (1)
Related Publication 20230315898A1 · Oct 5, 2023
References Cited (30)
US 10122757B1 · Kruse et al. · 2018 [cited by applicant]
US 10581919B2 · Kruse et al. · 2020 [cited by applicant]
US 10778691B1 · Kissell · 2020 [cited by examiner]
US 20030088786A1 · Moran · 2003 [cited by examiner]
US 20050138420A1 · Sampathkumar · 2005 [cited by examiner]
US 20080109897A1 · Moran · 2008 [cited by examiner]
US 20140215604A1 · Giblin et al. · 2014 [cited by applicant]
US 20190081954A1 · Xu · 2019 [cited by examiner]
US 20200356682A1 · Gu · 2020 [cited by examiner]
US 20210075794A1 · Gazit · 2021 [cited by examiner]
US 20210203687A1 · Rabin et al. · 2021 [cited by applicant]
US 20220385668A1 · Simonetti · 2022 [cited by examiner]
US 20230216887A1 · Strong · 2023 [cited by examiner]
EP 2631841B1 · 2015 [cited by examiner]
KR 20230146534A · 2023 [cited by examiner]
Kumar, R., Sural, S., Gupta, A. (2010). Mining RBAC Roles under Cardinality Constraint. In: Jha, S., Mathuria, A. (eds) Information Systems Security. ICISS 2010. Lecture Notes in Computer Science, vol. 6503. Springer, B… [cited by examiner]
“IAM Access Analyzer policy generation”; <https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-generation.html> webpage with Jan. 29, 2022 capture date, retrieved from Internet Archive Wayback Machine… [cited by applicant]
Chandra Chekuri; CS 598CSC: Approximation Algorithms; Lecture; Jan. 2011; 7 pages. [cited by applicant]
https://www.cs.cmu.edu/˜avrim/451f12/lectures/lect1106.pdf; Lecture 21—Approximation Algorithms, Nov. 2012; p. 91-95. [cited by applicant]
Land et al.; “An Automatic Method of Solving Discrete Programming Problems”; Econometrica; vol. 28 No. 3; Jul. 1960; p. 497-520. [cited by applicant]
Padberg et al; “A Branch-and-Cut Algorithm for the Resolution of Large-Scale Symmetric Traveling Salesman Problems”; SIAM Review; vol. 33(1); Mar. 1991; p. 60-100. [cited by applicant]
Savelsberg; “A Branch-and-Price Algorithm for the Generalized Assignment Problem”; Operations Research; vol. 45 No. 6; 1997; 23 pages. [cited by applicant]
“Reviewing and applying recommendations”; https://cloud.google.com/iam/docs/recommender-managing; Oct. 2020; accessed Oct. 21, 2020; 5 pages. [cited by applicant]
“Enforce least privilege with recommendations”; https://cloud.google.com/iam/docs/recommender-overview; Oct. 2020; accessed Oct. 20, 2020; 13 pages. [cited by applicant]
Wang et al.; “Exploring the machine learning models behind Cloud IAM Recommender”; https://cloud.google.com/blog/products/identity-security/exploring-the-machine-learning-models-behind-cloud-iam-recommender; Google; Nov… [cited by applicant]
Mesquita et al.; “Set partitioning/covering-based approaches for the integrated vehicle and crew scheduling problem”; Computers & Operations Research; vol. 35; May 2008; p. 1562-1575. [cited by applicant]
International Patent Application No. PCT/US2023/065105; Int'l Search Report and the Written Opinion; dated Jul. 14, 2023; 18 pages. [cited by applicant]
Kumar et al.; “Mining RBAC Roles under Cardinality Constraint”; 18 [cited by applicant]
Mitra et al.; “A Survey of Role Mining”; ACM Computing Surveys; vol. 48 No. 4; Feb. 2016; 37 pages. [cited by applicant]
International Patent Application No. PCT/US2023/065105; Int'l Preliminary Report on Patentability; dated Oct. 10, 2024; 11 pages. [cited by applicant]