Dynamic Privileged Access Workstation Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing privileged access workstation (PAW) security measures require dedicated proxy servers and can decrease workstation performance, and users often need separate machines for daily and privileged tasks, which is costly and inconvenient.

Innovation Solution

The system automatically provisions dynamic privileged access resources by creating temporary, isolated workstations or virtual computing resources with restricted access rights and functionalities, eliminating the need for dedicated servers and allowing users to switch between normal and privileged tasks on the same device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated proxy servers are used for privileged access, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the privileged access workstation functionality with the user's regular endpoint device, eliminating the need for separate dedicated proxy servers. The system merges privileged and non-privileged operations into a single device through virtualization, reducing device complexity while maintaining security through isolation of privileged sessions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The endpoint device is transformed into a multi-functional system that can handle both regular user tasks and privileged administrative tasks. By implementing a privileged session manager on the same device, the system allows the endpoint to serve universal purposes without requiring separate dedicated servers for privileged access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate machines are used for privileged and daily tasks, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges privileged and non-privileged work environments into a single endpoint device, allowing users to switch between regular and privileged tasks without physically moving between machines. The privileged session manager enables seamless transitions while maintaining security isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically creates and destroys privileged session environments based on user needs. When privileged access is required, an isolated session is created; when not needed, the session is destroyed. This dynamic behavior provides security when needed while maintaining ease of operation by eliminating the need for permanent separate machines.

Inventive Principle:
Principle #15Dynamics

3Reliability

If dedicated PAWs are deployed, then security is improved, but loss of substance increases due to additional hardware requirements

Engineering Contradiction:
ImprovesecurityVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

Instead of deploying physical dedicated PAW hardware, the system creates virtual copies of privileged work environments through software-based session isolation. The privileged session manager creates virtualized session environments that consume minimal additional hardware resources while providing the security isolation of dedicated machines.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the parameter of resource allocation from fixed physical hardware to dynamic virtual resources. By using virtualization and on-demand session creation, the hardware resources required for privileged access are minimized to only what is needed during active privileged sessions, rather than requiring dedicated hardware available at all times.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11316857B2Automated creation of dynamic privileged access resources
Publication Date: 2022.04.26 CYBER ARK SOFTWARE LTD
  • US11316857B2 patent drawing
  • US11316857B2 patent drawing
  • US11316857B2 patent drawing

AI summary

Disclosed embodiments include techniques for automatically provisioning dynamic privileged access resources. Aspects may involve receiving a notification that an identity is seeking to participate in a privileged session with an access-restricted network resource, and automatically provisioning, in response to the notification, a privileged access resource for use by the identity in participating in the privileged session with the access-restricted network resource. Further, aspects may include determining that the privileged session with the access-restricted network resource has ended, and automatically deprovisioning, based on the determination, the privileged access resource.