Cloud-Based Shadow Admin Group for On-Premise Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity tools face challenges in managing elevated access to on-premise resources efficiently and securely, particularly in large enterprises, where setting up and maintaining privileged access management (PAM) technologies can be costly and complex, and there is a need for secure, cloud-based solutions that integrate with existing systems without compromising security.
Innovation Solution
The implementation of a cloud-based privileged access management (CBPAM) system that creates a secured cloud-based shadow administrating group (SCBSAG) with a unique security identification, allowing administrative actions on on-premise resources from the cloud, ensuring secure management control through tailored software and hardware configurations, including enrollment requests, secure authentication, and policy-based access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-based privileged access management is implemented, then security and cost-effectiveness are improved, but system complexity increases
Solution Approach 1:
The patent introduces a cloud-based privileged access management service as an intermediary between administrators and on-premise resources. This service mediates authentication and authorization requests, creating a shadow administrating group in the cloud that acts as a secure intermediary layer. The shadow group contains copied security identifiers from the on-premise domain, allowing the cloud service to authenticate with on-premise resources without exposing credentials or increasing on-premise system complexity.
2Productivity
If cloud-based shadow administrating group is created, then management efficiency is improved, but integration complexity with on-premise systems increases
Solution Approach 1:
The patent creates a cloud-based shadow administrating group that contains copied security identifiers (SIDs) from the on-premise domain. Instead of implementing complex integration protocols or bidirectional synchronization, the system copies the necessary authentication data one-way from the on-premise domain to the cloud. This copying approach enables the cloud service to impersonate or authenticate as the on-premise domain while maintaining simplicity and avoiding complex integration requirements.
Data Source
AI summary
A secure cloud-based privileged access management (CBPAM) service manages on-premise resources. While enrolling an on-premise authentication domain admin group, a secured cloud-based shadow administrating group (SCBSAG) is created; a SCBSAG security identification includes at least part of the enrollee's security identification. The SCBSAG belongs to a clean CBPAM authentication domain which may be secured by defense in depth controls such as time limits on authentication or authorization, password avoidance, least privilege, one-way syncing, and one-way trust. Management via the configured SCBSAG may be fostered by emptying the on-premise admin group, although a break glass account may be kept. CBPAM services direct administrative actions toward on-premise resources through SCBSAGs for cloud tenants, providing secure management control as a service, with broader geographic scope and lower maintenance burdens and costs than privileged access management approaches that are not cloud-based.


