Agentless Authorization for Network Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity methods face challenges in managing and securing privileged access to network resources, as standing privileged accounts can be difficult to track and manage, leading to increased security risks due to the potential for credentials to be forgotten, duplicated, or stolen, and providing just-in-time access systems are complex for large organizations.

Innovation Solution

The implementation of a non-transitory computer-readable medium that provides native agentless authorization for network resources, using a native client and communication protocol to authenticate and authorize access based on access policies, generating ephemeral credentials, and enabling access without the need for dedicated agents or VPN clients, allowing for real-time authorization and minimizing the number of standing privileged accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standing privileged accounts are provided for network resource access, then user convenience and access simplicity are improved, but security risks increase due to difficulty in tracking and managing credentials

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic credential generation where standing privileged accounts are replaced with ephemeral credentials that are created on-demand and automatically expire. This transforms the static credential model into a dynamic one where access rights are temporary and automatically revoked, maintaining ease of access while improving security through automatic credential lifecycle management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an intermediary credential management layer that sits between users and network resources. This intermediary automatically generates, manages, and revokes ephemeral credentials without requiring users to manually handle standing privileged accounts, thus maintaining user convenience while eliminating the security risks associated with long-lived credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If just-in-time privileged access systems are implemented, then security is improved by minimizing standing privileged accounts, but system complexity increases requiring agents and VPN clients

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex agent and VPN client components from the just-in-time access system, retaining only the essential credential generation and revocation functionality. This simplifies the system by removing unnecessary complexity while preserving the core security benefit of minimizing standing privileged accounts through ephemeral credential management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service automated credential management where ephemeral credentials are automatically generated, distributed, and revoked without requiring complex manual configuration or dedicated client software. This reduces system complexity by making the security mechanism self-managing rather than requiring extensive administrative overhead and user-side agents.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If long-lived credentials are provided for network resource access, then ease of access is improved, but credential management difficulty increases leading to forgotten, duplicated, or stolen credentials

Engineering Contradiction:
Improveease of accessVSAvoidcredential management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements periodic credential renewal and automatic expiration where credentials are valid only for specific time periods or specific actions. This transforms long-lived static credentials into periodic, self-expiring credentials that automatically become invalid after use or time expiration, eliminating the need for manual tracking and reducing the risk of forgotten or stolen credentials.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system automatically discards (revokes) credentials after they have been used or after their expiration period, and recovers (regenerates) new credentials as needed. This automated credential lifecycle management eliminates manual tracking requirements and prevents the accumulation of orphaned or compromised credentials that plague long-lived credential systems.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS20240179184A1Enhanced authorization layers for native access to secure network resources
Publication Date: 2024.05.30 CYBER ARK SOFTWARE LTD
  • US20240179184A1 patent drawing
  • US20240179184A1 patent drawing
  • US20240179184A1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for providing native agentless authorization for network resources. Techniques include receiving a request from a network identity to access a network resource; authenticating the network identity; authorizing the network identity based on one or more access policy comprising rules for accessibility of the network resource and an additional set of rules providing an authorization layer not natively supported by the network resource; identifying an account having a secret; accessing the network resource using the secret; enabling the network identity to access the network resource; analyzing data transferred by identifying one or more action or command requested by the network identity; and authorizing the one or more requested action or command in real-time based on the one or more access policy.