Access Control Center Workflow for IT Infrastructure Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face risks such as data loss and unauthorized access when granting third-party or internal technical support personnel access to their IT infrastructure and business applications, necessitating a solution for controlled and limited access.

Innovation Solution

Establishing an access control center with thin client terminals that provide indirect and temporary access through virtual desktops, managed by an ACC application to control connections and minimize security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If direct access to IT infrastructure and business applications is granted to technical support personnel, then service efficiency and technical expertise are improved, but security risks such as data loss and unauthorized access increase

Engineering Contradiction:
Improveservice efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an Access Control Center (ACC) as an intermediary system between technical support personnel and the IT infrastructure. The ACC provides controlled access through virtual desktops and thin client terminals, allowing support personnel to access systems remotely while maintaining security boundaries. This mediator architecture enables service efficiency without direct access risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access architecture into distinct layers: thin client terminals for support personnel, virtual desktops as intermediate computing environments, and the protected IT infrastructure. This segmentation isolates support personnel from direct access to critical systems, maintaining productivity while reducing security exposure through architectural separation.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If full access is provided to technical support personnel, then technical expertise and problem-solving capability are improved, but the risk of unauthorized access to critical systems increases

Engineering Contradiction:
Improvetechnical expertiseVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic access control where the ACC can adjust and modify access permissions in real-time based on incident requirements. Access rights are not static but can be expanded or restricted as needed, allowing full technical expertise when required while maintaining reliability through flexible, controlled permission management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The ACC incorporates monitoring and approval workflows that provide feedback mechanisms. Access requests are reviewed and approved based on incident requirements, and the system continuously monitors access activities. This feedback loop ensures technical expertise is utilized appropriately while preventing unauthorized access through active control and monitoring.

Inventive Principle:
Principle #23Feedback

3Reliability

If access is granted on an as-needed basis, then security control is improved, but access approval time and workflow complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess approval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary configuration of access templates and approval workflows within the ACC. Common access scenarios are pre-defined with appropriate permission sets and approval chains, allowing rapid deployment when incidents occur. This preliminary preparation maintains strict security control while reducing approval time through pre-configured access pathways.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8978104B1Access control center workflow and approval
Publication Date: 2015.03.10 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US8978104B1 patent drawing
  • US8978104B1 patent drawing
  • US8978104B1 patent drawing

AI summary

Methods and systems are disclosed for providing indirect and temporary access to a company's IT infrastructure and business applications. The methods/systems involve establishing an access control center (ACC) to control the access that technical support personnel may have to the company's IT infrastructure and business applications. Thin client terminals with limited functionality may then be set up in the ACC for use by the technical support personnel. The thin client terminals connect the technical support personnel to workstations outside the ACC that operate as virtual desktops. The virtual desktops in turn connect the technical support personnel to the IT infrastructure and business applications. An ACC application may be used to control the connection between the thin client terminals and the virtual desktops and the virtual desktops and the IT infrastructure and business applications.