Access Control Center Workflow for IT Infrastructure Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face risks such as data loss and unauthorized access when granting third-party or internal technical support personnel access to their IT infrastructure and business applications, necessitating a solution for controlled and limited access.
Innovation Solution
Establishing an access control center with thin client terminals that provide indirect and temporary access through virtual desktops, managed by an ACC application to control connections and minimize security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If direct access to IT infrastructure and business applications is granted to technical support personnel, then service efficiency and technical expertise are improved, but security risks such as data loss and unauthorized access increase
Solution Approach 1:
The patent introduces an Access Control Center (ACC) as an intermediary system between technical support personnel and the IT infrastructure. The ACC provides controlled access through virtual desktops and thin client terminals, allowing support personnel to access systems remotely while maintaining security boundaries. This mediator architecture enables service efficiency without direct access risks.
Solution Approach 2:
The patent segments the access architecture into distinct layers: thin client terminals for support personnel, virtual desktops as intermediate computing environments, and the protected IT infrastructure. This segmentation isolates support personnel from direct access to critical systems, maintaining productivity while reducing security exposure through architectural separation.
2Adaptability or versatility
If full access is provided to technical support personnel, then technical expertise and problem-solving capability are improved, but the risk of unauthorized access to critical systems increases
Solution Approach 1:
The patent implements dynamic access control where the ACC can adjust and modify access permissions in real-time based on incident requirements. Access rights are not static but can be expanded or restricted as needed, allowing full technical expertise when required while maintaining reliability through flexible, controlled permission management.
Solution Approach 2:
The ACC incorporates monitoring and approval workflows that provide feedback mechanisms. Access requests are reviewed and approved based on incident requirements, and the system continuously monitors access activities. This feedback loop ensures technical expertise is utilized appropriately while preventing unauthorized access through active control and monitoring.
3Reliability
If access is granted on an as-needed basis, then security control is improved, but access approval time and workflow complexity increase
Solution Approach 1:
The patent implements preliminary configuration of access templates and approval workflows within the ACC. Common access scenarios are pre-defined with appropriate permission sets and approval chains, allowing rapid deployment when incidents occur. This preliminary preparation maintains strict security control while reducing approval time through pre-configured access pathways.
Data Source
AI summary
Methods and systems are disclosed for providing indirect and temporary access to a company's IT infrastructure and business applications. The methods/systems involve establishing an access control center (ACC) to control the access that technical support personnel may have to the company's IT infrastructure and business applications. Thin client terminals with limited functionality may then be set up in the ACC for use by the technical support personnel. The thin client terminals connect the technical support personnel to workstations outside the ACC that operate as virtual desktops. The virtual desktops in turn connect the technical support personnel to the IT infrastructure and business applications. An ACC application may be used to control the connection between the thin client terminals and the virtual desktops and the virtual desktops and the IT infrastructure and business applications.


