Agentless Authorization for Network Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity methods face challenges in managing and securing privileged access to network resources, as standing privileged accounts can be difficult to track and manage, leading to increased security risks due to the potential for credentials to be forgotten, duplicated, or stolen, and providing just-in-time access systems are complex for large organizations.
Innovation Solution
The implementation of a non-transitory computer-readable medium that provides native agentless authorization for network resources, using a native client and communication protocol to authenticate and authorize access based on access policies, generating ephemeral credentials, and enabling access without the need for dedicated agents or VPN clients, allowing for real-time authorization and minimizing the number of standing privileged accounts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standing privileged accounts are provided for network resource access, then user convenience and access simplicity are improved, but security risks increase due to difficulty in tracking and managing credentials
Solution Approach 1:
The patent implements dynamic credential generation where standing privileged accounts are replaced with ephemeral credentials that are created on-demand and automatically expire. This transforms the static credential model into a dynamic one where access rights are temporary and automatically revoked, maintaining ease of access while improving security through automatic credential lifecycle management.
Solution Approach 2:
The system introduces an intermediary credential management layer that sits between users and network resources. This intermediary automatically generates, manages, and revokes ephemeral credentials without requiring users to manually handle standing privileged accounts, thus maintaining user convenience while eliminating the security risks associated with long-lived credentials.
2Reliability
If just-in-time privileged access systems are implemented, then security is improved by minimizing standing privileged accounts, but system complexity increases requiring agents and VPN clients
Solution Approach 1:
The patent extracts the complex agent and VPN client components from the just-in-time access system, retaining only the essential credential generation and revocation functionality. This simplifies the system by removing unnecessary complexity while preserving the core security benefit of minimizing standing privileged accounts through ephemeral credential management.
Solution Approach 2:
The system implements self-service automated credential management where ephemeral credentials are automatically generated, distributed, and revoked without requiring complex manual configuration or dedicated client software. This reduces system complexity by making the security mechanism self-managing rather than requiring extensive administrative overhead and user-side agents.
3Ease of operation
If long-lived credentials are provided for network resource access, then ease of access is improved, but credential management difficulty increases leading to forgotten, duplicated, or stolen credentials
Solution Approach 1:
The patent implements periodic credential renewal and automatic expiration where credentials are valid only for specific time periods or specific actions. This transforms long-lived static credentials into periodic, self-expiring credentials that automatically become invalid after use or time expiration, eliminating the need for manual tracking and reducing the risk of forgotten or stolen credentials.
Solution Approach 2:
The system automatically discards (revokes) credentials after they have been used or after their expiration period, and recovers (regenerates) new credentials as needed. This automated credential lifecycle management eliminates manual tracking requirements and prevents the accumulation of orphaned or compromised credentials that plague long-lived credential systems.
Data Source
AI summary
Disclosed embodiments relate to systems and methods for providing native agentless authorization for network resources. Techniques include receiving a request from a network identity to access a network resource; authenticating the network identity; authorizing the network identity based on one or more access policy comprising rules for accessibility of the network resource and an additional set of rules providing an authorization layer not natively supported by the network resource; identifying an account having a secret; accessing the network resource using the secret; enabling the network identity to access the network resource; analyzing data transferred by identifying one or more action or command requested by the network identity; and authorizing the one or more requested action or command in real-time based on the one or more access policy.


