Access Manager Session Ranking for Credential Conflict Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of access management in IT environments, driven by diverse applications, cloud computing, and mobile technologies, leads to resource-intensive patchworks of point solutions, which strain IT resources and compromise security, particularly with the rise of Shadow IT and the need for improved interoperability.
Innovation Solution
An access manager system that assigns ranks to agents handling session requests, determining session precedence based on authentication policies, security levels, and resource types to enforce security policies, such as limiting sessions per user credential, thereby managing communication sessions between user devices and agents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple sessions are allowed per user credential across different agents, then user convenience and access versatility are improved, but security control and session management complexity worsen
Solution Approach 1:
The patent uses session IDs as copies or representations of actual user sessions. Each session is identified by a unique session ID that the access manager can track and manage without directly handling the complex session state, simplifying session management while maintaining versatility
Solution Approach 2:
The patent introduces ranking parameters assigned to different agents to control session behavior. By changing the parameter of agent priority (ranking), the system can dynamically control which sessions are maintained or terminated, simplifying security policy enforcement while allowing multiple session types
2Reliability
If session precedence is determined by complex policies considering multiple agents and resources, then security control is improved, but processing time and system complexity worsen
Solution Approach 1:
The patent pre-assigns rankings to agents before session conflicts occur. This preliminary action stores security policy decisions in advance, so when session conflicts arise, the access manager can quickly compare pre-determined rankings rather than evaluating complex policies in real-time, reducing processing time while maintaining security
Solution Approach 2:
The patent transforms complex security policies into simple comparable parameters (rankings). Each agent is assigned a numerical ranking that represents its priority, converting complex policy evaluation into simple numerical comparison, which significantly reduces processing time while maintaining security control
3Reliability
If the access manager enforces strict session limits per credential, then security is improved, but user convenience and system productivity worsen
Solution Approach 1:
The patent applies different session management rules to different agents based on their rankings. High-ranking agents may allow multiple sessions while low-ranking agents enforce single-session limits. This local differentiation maintains security by applying strict controls where needed while allowing convenience where appropriate, improving overall productivity
Solution Approach 2:
The patent makes session limits dynamic rather than static. The effective session limit for a credential changes based on the rankings of active sessions and current security policies. This dynamic approach allows the system to adapt security strictness to current conditions, maintaining security while improving user convenience and productivity
Data Source
AI summary
A method of handling a plurality of session requests at an access manager may include assigning a rank to each of a plurality of agents. Each of the plurality of agents may forward requests for protected resources to the access manager for authentication and/or authorization, and the access manager may establish a plurality of sessions. The method may also include establishing a first session that is associated with a first agent in the plurality of agents that is assigned a first rank, a first user device, and/or a user credential. The method may additionally include receiving a request to establish a second session that is associated with a second agent in the plurality of agents that is assigned a second rank, a second user device, and/or the user credential. The method may further include determining whether the second session should be established.


