Account Management Using Activity Usage Restrictions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of user accounts and devices connected to the Internet creates a large attack surface, making them vulnerable to malicious attacks, particularly brute-force attempts and lateral movement by attackers, which poses a significant security risk for both financial and personal information.

Innovation Solution

Implementing account rules that limit user account activity to specified times, dates, infrastructure, locations, or usage, such as activating or deactivating accounts on-demand, or restricting access to specific times or applications, to reduce the attack surface by monitoring and enforcing permitted parameters like time, location, and usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user accounts are kept active and accessible to maintain operational availability, then system availability is improved, but the attack surface increases and security vulnerability worsens

Engineering Contradiction:
Improvesystem availabilityVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic account management where user accounts are activated or deactivated based on real-time conditions such as current time, scheduled time windows, and user presence status. This dynamic approach allows accounts to be available when needed while automatically restricting access during periods of low usage or outside authorized timeframes, thereby reducing the attack surface without permanently compromising system availability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic account activation and deactivation based on scheduled time windows. Accounts are periodically enabled during authorized timeframes and disabled outside these windows, creating a rhythmic pattern of accessibility that maintains operational availability during business hours while reducing exposure to attacks during off-hours or unauthorized periods.

Inventive Principle:
Principle #19Periodic action

2Object-affected harmful factors

If account access is restricted to specific time windows and conditions to reduce vulnerability, then security is improved, but account accessibility and operational flexibility worsen

Engineering Contradiction:
ImprovevulnerabilityVSAvoidaccount accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system incorporates feedback mechanisms that monitor user presence, device status, and account activity in real-time. Based on this feedback, the system dynamically adjusts account accessibility - activating accounts when users are present and devices are authorized, and deactivating them when users are absent or devices are compromised. This feedback-driven approach maintains ease of operation for authorized users while automatically restricting access to reduce vulnerability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The account management system operates autonomously by automatically activating and deactivating accounts based on predefined policies and real-time conditions without requiring manual intervention. The system self-adjusts accessibility based on user presence detection, scheduled time windows, and security conditions, thereby maintaining operational flexibility for authorized users while reducing vulnerability through automated restriction.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If accounts are deactivated when not in use to reduce attack surface, then security is improved, but system productivity and response time worsen

Engineering Contradiction:
Improveattack surfaceVSAvoidsystem response time
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system performs preliminary account activation based on scheduled time windows and predicted user needs. Accounts are proactively enabled before anticipated usage periods begin, ensuring immediate accessibility when users need to access the system. This preliminary action prevents delays in system response time while maintaining security by keeping accounts disabled outside of authorized timeframes, thus reducing the overall attack surface.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11159568B2Account management using account activity usage restrictions
Publication Date: 2021.10.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11159568B2 patent drawing
  • US11159568B2 patent drawing
  • US11159568B2 patent drawing

AI summary

Methods, systems, and media are shown for reducing the vulnerability of user accounts to attack that involve creating a rule for a user account that includes a permitted parameter corresponding to a user account activity property, monitoring the account activity of the user account. If it is determined that account activity property is inconsistent with the permitted parameter, then the user account is disabled. An example of a permitted parameter is a permitted time period, such as a start time, an end time, a recurrence definition, a days of the week definition, a start date, an end date, and a number of occurrences definition. Other examples are a physical parameter, such as a permitted geographic location, device, or network, or a permitted usage parameter, such as a permitted application, data access, or domain.