Dynamic Privileged Account Management for Credential Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are vulnerable to credential-based attacks due to persistent account access, leading to increased security breaches and compliance issues, and rotating passwords with shared accounts do not adequately address these problems.

Innovation Solution

A computerized access-manager server that gathers privileged-access information from target computer systems, enables multi-factor authentication, and dynamically adds or removes privileged user accounts on a specified interval, reducing vulnerability and improving audit compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If persistent account access is maintained for system accounts, then ease of operation is improved, but security reliability deteriorates due to vulnerability to credential-based attacks

Engineering Contradiction:
Improveaccount access convenienceVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic account access management where privileged accounts are automatically created, activated, and deactivated based on real-time access requests. Instead of static persistent accounts, the system dynamically provisions accounts with specific permissions for specific durations, then automatically revokes access. This dynamic approach maintains operational convenience while eliminating the security risks of persistent credential storage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic account lifecycle management where accounts are created on-demand, activated for specific time intervals, and automatically deactivated after expiration. This periodic creation and destruction of access credentials ensures that accounts exist only when needed, preventing credential-based attacks while maintaining ease of operation through automated workflows.

Inventive Principle:
Principle #19Periodic action

2Reliability

If shared accounts with rotating passwords are used, then security reliability is improved, but audit capability deteriorates due to inability to track individual user actions

Engineering Contradiction:
Improvesecurity protectionVSAvoidaudit trail information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments shared account access into individual user-specific privileged accounts. Each user receives their own dedicated account with unique credentials and permission sets, eliminating the need for shared accounts. This segmentation enables both strong security through individualized access control and complete auditability through user-specific logging and tracking of all actions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements comprehensive audit logging that provides real-time feedback on all privileged account actions. Each user's activities are automatically recorded with timestamps, action types, and target objects, creating a complete audit trail. This feedback mechanism maintains security through continuous monitoring while preserving full audit capability for compliance and forensic analysis.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If privileged accounts are permanently stored on target systems, then ease of operation is improved, but data leakage risk increases due to exposed credential information

Engineering Contradiction:
Improveaccount availabilityVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary account provisioning by pre-configuring account templates, permission sets, and security policies before access is needed. When a user requires access, the system automatically instantiates an account based on these pre-configured templates with appropriate credentials. This preliminary preparation ensures immediate account availability while keeping actual credentials secure until the moment of controlled disclosure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements disposable privileged accounts that are created on-demand, used for a specific purpose and time interval, then automatically destroyed. These short-lived accounts replace permanently stored credentials, eliminating data leakage risks associated with persistent credential storage. Each account serves its purpose and is then discarded, with no residual credential information remaining on target systems.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10505939B2System account access manager
Publication Date: 2019.12.10 NETWRIX CORP
  • US10505939B2 patent drawing
  • US10505939B2 patent drawing
  • US10505939B2 patent drawing

AI summary

In one aspect, a computerized system of an access-manager server for managing account access includes a computer store containing data, wherein the data comprises a privileged-access information. The privileged-access information is gathered from a target-computer system on a network. The privileged-access information is used to authorize a privileged user to access to the target-computer system. A computer processor in the access-manager server, which computer processor gathers the privileged-access information from the target-computer system on a network. The computer processor detects that the information is gathered from the target-computer system. The computer processor removes an existing-account access from the target-computer system. The computer processor obtains the privileged-access information from the computer store. The computer processor enables a privileged user to log into the access manager server using multi-factor authentication. When the privileged user requests access to the target-computer system access via the access manager server, the computer processor verifies an account access is allowed for the privileged user. The computer processor adds the privileged user's account to the target-computer system for an interval specified by the access manager server. During the interval specified the privileged user is enabled to log on to the target-computer system.