Dynamic Privileged Access Management via Risk-Based Scheduling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current privileged access management systems in network systems often rely on fixed permissions and durations, which can be inadequate for diverse user purposes and may expose the system to security threats due to inflexible access controls, especially in complex environments like Open Radio Access Networks (RAN) with multiple vendors and devices.
Innovation Solution
A privileged access management system that allows users to request customizable permissions and time-limited access through an API, enabling granular control of access levels (read-only, read-write) and scheduling access for specific purposes, using a centralized API to reduce network intrusion risks by managing access via a cloud architecture with inventory and permissions databases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If fixed permissions and durations are used for privileged access, then system security is maintained through standardized controls, but the system cannot accommodate diverse user purposes and reduces operational flexibility
Solution Approach 1:
The patent implements dynamic privileged access management where permission durations and scopes are adjustable based on user requests and risk assessments. The system transitions from static fixed-time access to dynamic time-limited access with customizable durations, allowing the system to adapt to diverse user purposes while maintaining security through automated revocation and approval workflows.
Solution Approach 2:
The system allows modification of access permission parameters including duration, scope, and privilege level based on user needs and risk evaluation. Administrators can adjust these parameters dynamically, and the system automatically revokes access when parameters expire or are modified, resolving the contradiction between flexibility and security.
2Adaptability or versatility
If customizable time-limited access is implemented, then diverse user purposes are accommodated, but system complexity increases due to additional management mechanisms
Solution Approach 1:
The patent implements self-service mechanisms where users can request their own privileged access with specified durations and purposes. The system automatically processes requests, performs risk assessments, and revokes access when time limits are reached, reducing the need for manual administrative intervention and managing complexity through automation rather than human processes.
Solution Approach 2:
The system incorporates automated feedback loops including risk assessment evaluations, approval notifications, and automatic revocation triggers. When access permissions are granted, the system continuously monitors time expiration and automatically revokes access or notifies administrators, managing complexity through systematic feedback rather than manual tracking.
3Reliability
If automated access revocation is implemented, then security is enhanced by limiting exposure time, but additional monitoring and control mechanisms increase system complexity
Solution Approach 1:
The patent implements preliminary action by pre-defining access duration parameters and automatic revocation triggers at the time of permission granting. The system sets expiration times and automated revocation conditions in advance, eliminating the need for continuous manual monitoring and reducing complexity through pre-configured security measures rather than active management.
Data Source
AI summary
Centralized privileged access is managed by receiving a request for privileged access to a device connected to a network, the request including a device identifier and a first user identifier, determining a role risk associated with the request based on a requested privilege level included in the request, determining an impact risk associated with the request based on potentially impacted devices other than the device, determining a risk level associated with the request based on the role risk and the impact risk, identifying a second user to control authorization of the device based on the risk level, and scheduling, in response to receiving authorization from the second user, a process to modify an entry in a permissions database to associate the first user identifier and the device identifier with the requested privilege level for the duration.


