Access Sponsor Mechanism for Secure Remote Support
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote support technologies face challenges in providing adequate access and privileges to IT professionals while minimizing security risks, as conventional approaches often require granting elevated privileges that are not needed for all scenarios, leading to potential security vulnerabilities.
Innovation Solution
A system and method for securely providing access and elevated rights using an access sponsor mechanism that allows for restricted privileges to be granted on an as-needed basis, either through a request mechanism or automated pre-configured processes, isolating the need for representatives to know actual credentials and ensuring only necessary access is provided.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If elevated privileges are granted to remote support representatives, then their ability to perform troubleshooting and problem solving tasks is improved, but security risks to the organization's systems increase
Solution Approach 1:
The patent segments the credential granting process into two distinct modes: a restricted credentials mode for routine support tasks and an elevated credentials mode for advanced troubleshooting. The system divides credential management into multiple levels (restricted vs. elevated) and implements separate authentication pathways, allowing representatives to operate with minimal privileges by default and request elevated privileges only when necessary and approved by the access sponsor.
Solution Approach 2:
The access sponsor acts as an intermediary between the representative and the organization's systems. When a representative needs elevated credentials, the access sponsor receives the request, validates it against pre-configured policies, and selectively grants or denies access. This intermediary layer prevents direct unauthorized access while enabling legitimate elevated operations when business needs require them.
2Object-affected harmful factors
If restricted credentials are provided to representatives, then security risks are minimized, but the representative cannot access critical applications or perform advanced troubleshooting
Solution Approach 1:
The system implements dynamic credential management where the level of access is not fixed but can change based on operational needs. Representatives start with restricted credentials for routine tasks, and when advanced troubleshooting is required, they can dynamically request and receive elevated credentials through the access sponsor approval process. This dynamic adjustment allows the system to adapt access levels to match the actual task requirements.
Solution Approach 2:
The organization pre-configures access policies, credential sets, and approval workflows before they are needed. The access sponsor has pre-defined rules about when elevated credentials should be granted, what applications require elevated access, and which representatives are authorized to request them. This preliminary configuration enables rapid response to troubleshooting needs while maintaining security controls.
3Device complexity
If automated access sponsorship is implemented, then the complexity of credential management is reduced, but granular control over permissions may be limited
Solution Approach 1:
The access sponsor system serves multiple functions: it automatically manages credential distribution, enforces security policies, provides audit logging, and handles approval workflows all through a single unified platform. The system can operate in different modes (fully automated, semi-automated with approval, or manual) depending on the organization's needs, making it adaptable to various operational contexts while maintaining consistent security management.
Data Source
AI summary
An approach is provided to allow remote support representatives to carry out remote support session with minimal access and privileges to remote systems. An attempt is detected to establish a remote support session via a remote support appliance that is configured to establish the remote support session between a first device associated with a support representative and a second device associated with a user. A credential that provides an elevated access privilege is retrieved in response to the detection. The credential is provided to the first device for use in the establishment of the remote support session.


