Dynamic creation of user resource access roles within the privileged access management module
The method of dynamically creating user roles in PAM systems addresses manual inefficiencies and vulnerabilities by automating role assignments based on security scores and group memberships, enhancing network security and response efficiency.
Patent Information
- Application Number
- PCT/TR2024/051363
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-11-19
- Publication Date
- 2025-07-03
AI Technical Summary
Existing privileged access management (PAM) systems rely heavily on manual user role assignment, leading to inefficiencies and potential security vulnerabilities, especially in large networks, and lack automation for threat detection and response.
Implementing a method to dynamically create user resource access roles based on security scores and group memberships, using automated discovery and periodic audits, with WinRM protocol, to ensure compliance with Zero Trust principles and reduce human intervention.
Enhances authorization speed and security by automating user role assignments, reducing vulnerabilities, and enabling rapid response to security threats through predefined tightening settings.
Smart Images

Figure TR2024051363_03072025_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] DYNAMIC CREATION OF USER RESOURCE ACCESS ROLES WITHIN THE PRIVILEGED ACCESS MANAGEMENT MODULE
[0003] The present invention relates to a method of dynamically creating the user resource access roles (User Role) within the Privileged Access Management (PAM) Module, in Windows operating systems which are members of the Microsoft active directory or not, by looking at the roles of the group in which the relevant user is located.
[0004] In a more general sense, the present invention relates to the restriction of privileged access to computers whose security level is below the required level, depending on the security scores generated as a result of the security audit and tightening processes, and to ensure that risk warnings are generated if desired.
[0005] STATE OF THE ART
[0006] Today, the most important protection in Zero Trust architecture is human visibility control. Research indicates that 77% of data leaks are caused by abuse of authority. Due to the difficulty of identity management, many different types of threats, from espionage to ransomware, emerge as security threats today.
[0007] In the Privileged Access Management (PAM) architecture, user resource access privileges (User Role) are determined manually by the completely privileged access management (PAM) admin. For this purpose, it is necessary to first add a resource included in the network to the privileged access management database and then authorize the relevant users. This situation creates serious time loss and authorization problems in large networks.
[0008] For this reason, determining authorized access by the system team, in other words, leaving it to human initiative, may create a security vulnerability on the system. Due to the abovementioned disadvantages and the insufficiency of the solutions regarding the subject matter, a development is required to be made in the relevant technical field.
[0009] OBJECT OF THE INVENTION
[0010] In this context, the main purpose of the dynamic creation of user resource access roles (User Role) in privileged access management (PAM) is to provide privileged access to the right person independently of human initiative.
[0011] The main object of the development of the present invention is not only to provide privileged access to the right person, but also to enable the Zero Trust architecture to be used in all Windows operating systems.
[0012] In this context, the dynamic creation of user resource access roles (User Role) in privileged access management (PAM) of the present invention is ensured by restricting the authorized access of computers whose scores are below the acceptable security level by looking at the tightening and security scores produced in the assessment processes. Different scenarios can be created according to the security scores created. Creating risk warnings for devices with insufficient security scores is an example of this.
[0013] Another object of the present invention is to automatically discover new assets added to the system and connected to the network, to perform security audits, to create security tightening scores and to eliminate possible authorization problems and security vulnerabilities by applying predefined tightening settings completely automatically.
[0014] The structural and characteristic features of the present invention will be understood clearly by the following detailed description. Therefore the evaluation shall be made by taking this detailed description into consideration.
[0015] DETAILED DESCRIPTION OF THE INVENTION In this detailed description, the ‘dynamic creation of user resource access roles (User Role) in the privileged access management (PAM) of the present invention’ will be described only for a better understanding of the subject matter and without any limiting effect.
[0016] The members of the Local Administrators and Remote Desktop Users groups of each server with Windows operating system added to the system are continuously checked and recorded in the output database. In this way, it is known which users can access each server. If the member group of Local Administrators and Remote Desktop Users group is an AD Group, it controls the members of this group via Domain and has user information.
[0017] For example, the user Danismanl, who is added to the system today, is determined by the role given by the system team to access which of the hundreds of servers. With the inventive development, the said user role can be dynamically created by looking at the group roles. In this way, both the authorization speed will be much faster since it is given by the system, not by the human, and the human initiative effect on the system will be removed in accordance with the logic of the Zero Trust system.
[0018] The flow of the algorithm for ensuring that the role distribution is dynamically determined by the system which comprises the following process steps;
[0019] • Automatic discovery or manual identification of Windows operating systems on the Domain Controller server (1001),
[0020] • Accessing Windows operating systems and initiating periodic control processes by using AD or Local user without using any terminal tool via the protocol supported by Windows operating systems (WinRM) (1002), • Controlling the users who can access all Windows servers by sending scripts to the Local Administrators and Remote Desktop Users groups with WinRM service and saving them to the database (1003),
[0021] • Controlling the users who can access all Windows servers by sending scripts to the Local Administrators and Remote Desktop Users groups of the member AD groups on the Domain Controller server by sending scripts with WinRM service and saving them to the database (1004),
[0022] • Determining privileged access management (PAM) user resource access roles (user role) and updating the roles on the database based on the outputs saved in the database (1005).
Claims
CLAIMS1. A method of dynamically creating the user resource access roles (User Role) within the Privileged Access Management (PAM) Module, in Windows operating systems which are members of the Microsoft active directory or not, by looking at the roles of the group in which the relevant user is located, comprising the following process steps;• Automatic discovery or manual identification of Windows operating systems on the Domain Controller server,• Accessing Windows operating systems and initiating periodic control processes by using AD (Active Directory) or Local user without using any terminal tool via the protocol supported by Windows operating systems (WinRM), characterized in that, it comprises the following process steps;• Controlling the users who can access all Windows servers by sending scripts to the Local Administrators and Remote Desktop Users groups with WinRM service and saving them to the database,• Controlling the users who can access all Windows servers by sending scripts to the Local Administrators and Remote Desktop Users groups of the member AD groups on the Domain Controller server by sending scripts with WinRM service and saving them to the database,• Determining privileged access management (PAM) user resource access roles (user role) and updating the roles on the database based on the outputs saved in the database.
Citation Information
Patent Citations
Automatic least-privilege access and control for target resources
US20210409421A1
Privileged access request system
WO2023177399A1