Privileged Access Delegation via Resource Group Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for managing access to resources within an organization often result in administrative entities having global privileges, leading to inefficient and uncontrolled access to all resources, which can be cumbersome and insecure.
Innovation Solution
A privileged account management system that allows administrators to create resource groups, assigning specific privileges to administrative entities based on roles, enabling delegation of privileges with location and temporal conditions, thereby controlling access to subsets of resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If global administration privileges are provided to all administrative entities, then access to all resources is enabled, but security and access control efficiency deteriorate
Solution Approach 1:
The patent segments global administration privileges into domain-specific privileges by creating administrative domains that are further divided into resource groups. Each administrative entity receives privileges only for specific domains and resource groups rather than global access, thereby maintaining security while enabling necessary access control flexibility
Solution Approach 2:
The patent implements local quality by assigning different privilege levels and access rights to different administrative entities based on their specific roles and requirements. Each administrative entity receives customized privileges for specific resource groups rather than uniform global access, improving both security and operational efficiency
2Adaptability or versatility
If global administration privileges are provided to all administrative entities, then access to all resources is enabled, but administrative burden and complexity increase
Solution Approach 1:
The patent divides the administration system into hierarchical segments including administrative domains, resource groups, and individual privileges. This segmentation allows administrators to manage access rights at multiple levels, reducing the complexity of tracking and managing individual privileges across the entire system
Solution Approach 2:
The patent creates a universal privilege management framework where a single administrative domain can encompass multiple resource groups and privilege types. This multi-functional structure allows one domain to serve multiple purposes (e.g., security management, user management, system administration) without requiring separate complex management systems for each function
3Productivity
If resource groups are created with specific privileges, then access control efficiency improves, but system complexity increases
Solution Approach 1:
The patent implements a nested structure where administrative domains contain resource groups, which in turn contain individual privileges and administrative entities. This nesting allows for hierarchical organization of access rights, enabling efficient inheritance and delegation while maintaining manageable system complexity through structured organization
Solution Approach 2:
The patent introduces dynamic privilege assignment where administrative entities can be granted, removed from, or modified in their privilege access to resource groups based on changing organizational needs. This dynamic capability allows the system to adapt to evolving requirements without requiring complete system reconfiguration, improving efficiency while managing complexity through flexibility
Data Source
AI summary
A privileged account management system is provided that controls the management and access of resources within the organization. Resources may include target systems and accounts of the organization. In an embodiment, the privileged account management system is configured to enable the creation of one or more resource groups. A resource group includes a subset of a plurality of resources provided by the organization. In certain embodiments, the privileged account management system is configured to define one or more groups of administrative entities within the organization and assign to each administrative entity in a group of administrative entities, a set of privileges on a resource group. In certain embodiments, the privileged account manager system may be configured to enable an administrative entity from a group of administrative entities to delegate a subset of privileges associated with a resource group to a user entity not in the group of administrative entities.


