Access Sponsor Mechanism for Secure Remote Support

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote support technologies face challenges in providing adequate access and privileges to IT professionals while minimizing security risks, as conventional approaches often require granting elevated privileges that are not needed for all scenarios, leading to potential security vulnerabilities.

Innovation Solution

A system and method for securely providing access and elevated rights using an access sponsor mechanism that allows for restricted privileges to be granted on an as-needed basis, either through a request mechanism or automated pre-configured processes, isolating the need for representatives to know actual credentials and ensuring only necessary access is provided.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If elevated privileges are granted to remote support representatives, then their ability to perform troubleshooting and problem solving tasks is improved, but security risks to the organization's systems increase

Engineering Contradiction:
Improverepresentative's ability to perform troubleshooting tasksVSAvoidsecurity risks to organization's systems
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the credential granting process into two distinct modes: a restricted credentials mode for routine support tasks and an elevated credentials mode for advanced troubleshooting. The system divides credential management into multiple levels (restricted vs. elevated) and implements separate authentication pathways, allowing representatives to operate with minimal privileges by default and request elevated privileges only when necessary and approved by the access sponsor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access sponsor acts as an intermediary between the representative and the organization's systems. When a representative needs elevated credentials, the access sponsor receives the request, validates it against pre-configured policies, and selectively grants or denies access. This intermediary layer prevents direct unauthorized access while enabling legitimate elevated operations when business needs require them.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If restricted credentials are provided to representatives, then security risks are minimized, but the representative cannot access critical applications or perform advanced troubleshooting

Engineering Contradiction:
Improvesecurity risks to organization's systemsVSAvoidrepresentative's access to critical applications
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic credential management where the level of access is not fixed but can change based on operational needs. Representatives start with restricted credentials for routine tasks, and when advanced troubleshooting is required, they can dynamically request and receive elevated credentials through the access sponsor approval process. This dynamic adjustment allows the system to adapt access levels to match the actual task requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The organization pre-configures access policies, credential sets, and approval workflows before they are needed. The access sponsor has pre-defined rules about when elevated credentials should be granted, what applications require elevated access, and which representatives are authorized to request them. This preliminary configuration enables rapid response to troubleshooting needs while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If automated access sponsorship is implemented, then the complexity of credential management is reduced, but granular control over permissions may be limited

Engineering Contradiction:
Improvecredential management complexityVSAvoidgranular control over permissions
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The access sponsor system serves multiple functions: it automatically manages credential distribution, enforces security policies, provides audit logging, and handles approval workflows all through a single unified platform. The system can operate in different modes (fully automated, semi-automated with approval, or manual) depending on the organization's needs, making it adaptable to various operational contexts while maintaining consistent security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9742779B2Method and apparatus for securely providing access and elevated rights for remote support
Publication Date: 2017.08.22 BEYONDTRUST CORP
  • US9742779B2 patent drawing
  • US9742779B2 patent drawing
  • US9742779B2 patent drawing

AI summary

An approach is provided to allow remote support representatives to carry out remote support session with minimal access and privileges to remote systems. An attempt is detected to establish a remote support session via a remote support appliance that is configured to establish the remote support session between a first device associated with a support representative and a second device associated with a user. A credential that provides an elevated access privilege is retrieved in response to the detection. The credential is provided to the first device for use in the establishment of the remote support session.