Dynamic Privileged Access Workstation Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing privileged access workstation (PAW) security measures require dedicated proxy servers and can decrease workstation performance, and users often need separate machines for daily and privileged tasks, which is costly and inconvenient.
Innovation Solution
The system automatically provisions dynamic privileged access resources by creating temporary, isolated workstations or virtual computing resources with restricted access rights and functionalities, eliminating the need for dedicated servers and allowing users to switch between normal and privileged tasks on the same device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated proxy servers are used for privileged access, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines the privileged access workstation functionality with the user's regular endpoint device, eliminating the need for separate dedicated proxy servers. The system merges privileged and non-privileged operations into a single device through virtualization, reducing device complexity while maintaining security through isolation of privileged sessions.
Solution Approach 2:
The endpoint device is transformed into a multi-functional system that can handle both regular user tasks and privileged administrative tasks. By implementing a privileged session manager on the same device, the system allows the endpoint to serve universal purposes without requiring separate dedicated servers for privileged access.
2Reliability
If separate machines are used for privileged and daily tasks, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system merges privileged and non-privileged work environments into a single endpoint device, allowing users to switch between regular and privileged tasks without physically moving between machines. The privileged session manager enables seamless transitions while maintaining security isolation.
Solution Approach 2:
The system dynamically creates and destroys privileged session environments based on user needs. When privileged access is required, an isolated session is created; when not needed, the session is destroyed. This dynamic behavior provides security when needed while maintaining ease of operation by eliminating the need for permanent separate machines.
3Reliability
If dedicated PAWs are deployed, then security is improved, but loss of substance increases due to additional hardware requirements
Solution Approach 1:
Instead of deploying physical dedicated PAW hardware, the system creates virtual copies of privileged work environments through software-based session isolation. The privileged session manager creates virtualized session environments that consume minimal additional hardware resources while providing the security isolation of dedicated machines.
Solution Approach 2:
The system changes the parameter of resource allocation from fixed physical hardware to dynamic virtual resources. By using virtualization and on-demand session creation, the hardware resources required for privileged access are minimized to only what is needed during active privileged sessions, rather than requiring dedicated hardware available at all times.
Data Source
AI summary
Disclosed embodiments include techniques for automatically provisioning dynamic privileged access resources. Aspects may involve receiving a notification that an identity is seeking to participate in a privileged session with an access-restricted network resource, and automatically provisioning, in response to the notification, a privileged access resource for use by the identity in participating in the privileged session with the access-restricted network resource. Further, aspects may include determining that the privileged session with the access-restricted network resource has ended, and automatically deprovisioning, based on the determination, the privileged access resource.


