Dynamic Privilege Management for Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face challenges in managing overly broad privileges on client devices, leading to security risks and cumbersome revocation processes, as employees often require temporary administrative access for specific tasks.

Innovation Solution

A privilege management system that monitors user actions, compares actual privileges with desired sets defined by administrators, and automatically revokes or elevates privileges as needed, using an agent on client devices to implement and manage privilege manifests, with auditing and machine learning for proactive security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees are granted broad administrative privileges to perform business tasks, then productivity and ease of operation are improved, but security risks and harmful factors increase

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements dynamic privilege management where administrative privileges are not static but change over time based on user actions. The system monitors user behavior and automatically adjusts privilege levels, granting elevated access only when specific tasks are detected and revoking them afterward. This dynamic approach allows employees to have full productivity when needed while minimizing security risks during non-work periods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of privilege scope from broad and static to narrow and dynamic. By monitoring user actions and adjusting the extent of administrative access based on detected tasks, the system transforms the privilege parameter to match actual business needs, thereby maintaining productivity while reducing the window of opportunity for security breaches.

Inventive Principle:
Principle #35Parameter changes

2Object-generated harmful factors

If administrative privileges are revoked to improve security, then security risks are reduced, but ease of operation and productivity worsen due to cumbersome access requests

Engineering Contradiction:
Improvesecurity risksVSAvoidease of operation
Core Design Contradiction:
Object-generated harmful factorsVSEase of operation

Solution Approach 1:

The system implements self-service automatic privilege management where the privilege management system autonomously monitors user actions, detects administrative tasks, and adjusts privileges without requiring manual user requests or administrator intervention. This eliminates the cumbersome process of requesting and approving access while maintaining security through automated monitoring and revocation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop where user actions are continuously monitored and fed back to the privilege management system. Based on this feedback, the system automatically adjusts privilege levels, granting access when administrative tasks are detected and revoking when they are completed. This closed-loop feedback mechanism ensures ease of operation by eliminating manual requests while maintaining security through continuous monitoring.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If administrative privileges are granted for extended periods, then ease of operation is improved, but the duration of harmful factors increases

Engineering Contradiction:
Improveease of operationVSAvoidduration of privilege access
Core Design Contradiction:
Ease of operationVSDuration of action of moving object

Solution Approach 1:

The system implements periodic privilege access rather than continuous access. By monitoring user actions in real-time and granting elevated privileges only during detected administrative tasks, the system creates periodic windows of access that are brief and task-specific. This reduces the duration of harmful factors while maintaining ease of operation through automated task detection and privilege adjustment.

Inventive Principle:
Principle #19Periodic action

4Device complexity

If manual privilege revocation processes are used, then device complexity is reduced, but loss of time and productivity worsen

Engineering Contradiction:
Improvesystem complexityVSAvoidtime for privilege management
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The privilege management system performs automatic monitoring and revocation without requiring manual administrator intervention. The system self-services by continuously monitoring user actions, detecting administrative tasks, and automatically adjusting privileges, thereby eliminating time-consuming manual processes while keeping the underlying system architecture relatively simple.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary monitoring of user actions to detect administrative tasks before they are completed. By proactively identifying when elevated privileges are needed and automatically granting them, the system eliminates time loss associated with manual request-and-approve processes, while the automated nature keeps complexity manageable.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10715507B1Privilege revocation for client devices
Publication Date: 2020.07.14 AMAZON TECH INC
  • US10715507B1 patent drawing
  • US10715507B1 patent drawing
  • US10715507B1 patent drawing

AI summary

A privilege management system receives a manifest specifying a first set of privileges implemented on a client device. Based at least in part on a characteristic of the client device, the privilege management system identifies a second set of privileges that are to be implemented on the client device. The privilege management system processes the first set of privileges and the second set of privileges to identify a set of differences and transmits this set of differences to the client device. In response to receiving this set of differences, the client device implements the second set of privileges.