Dynamic Privileged Account Management for Credential Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to credential-based attacks due to persistent account access, leading to increased security breaches and compliance issues, and rotating passwords with shared accounts do not adequately address these problems.
Innovation Solution
A computerized access-manager server that gathers privileged-access information from target computer systems, enables multi-factor authentication, and dynamically adds or removes privileged user accounts on a specified interval, reducing vulnerability and improving audit compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If persistent account access is maintained for system accounts, then ease of operation is improved, but security reliability deteriorates due to vulnerability to credential-based attacks
Solution Approach 1:
The patent implements dynamic account access management where privileged accounts are automatically created, activated, and deactivated based on real-time access requests. Instead of static persistent accounts, the system dynamically provisions accounts with specific permissions for specific durations, then automatically revokes access. This dynamic approach maintains operational convenience while eliminating the security risks of persistent credential storage.
Solution Approach 2:
The system employs periodic account lifecycle management where accounts are created on-demand, activated for specific time intervals, and automatically deactivated after expiration. This periodic creation and destruction of access credentials ensures that accounts exist only when needed, preventing credential-based attacks while maintaining ease of operation through automated workflows.
2Reliability
If shared accounts with rotating passwords are used, then security reliability is improved, but audit capability deteriorates due to inability to track individual user actions
Solution Approach 1:
The patent segments shared account access into individual user-specific privileged accounts. Each user receives their own dedicated account with unique credentials and permission sets, eliminating the need for shared accounts. This segmentation enables both strong security through individualized access control and complete auditability through user-specific logging and tracking of all actions.
Solution Approach 2:
The system implements comprehensive audit logging that provides real-time feedback on all privileged account actions. Each user's activities are automatically recorded with timestamps, action types, and target objects, creating a complete audit trail. This feedback mechanism maintains security through continuous monitoring while preserving full audit capability for compliance and forensic analysis.
3Ease of operation
If privileged accounts are permanently stored on target systems, then ease of operation is improved, but data leakage risk increases due to exposed credential information
Solution Approach 1:
The system performs preliminary account provisioning by pre-configuring account templates, permission sets, and security policies before access is needed. When a user requires access, the system automatically instantiates an account based on these pre-configured templates with appropriate credentials. This preliminary preparation ensures immediate account availability while keeping actual credentials secure until the moment of controlled disclosure.
Solution Approach 2:
The patent implements disposable privileged accounts that are created on-demand, used for a specific purpose and time interval, then automatically destroyed. These short-lived accounts replace permanently stored credentials, eliminating data leakage risks associated with persistent credential storage. Each account serves its purpose and is then discarded, with no residual credential information remaining on target systems.
Data Source
AI summary
In one aspect, a computerized system of an access-manager server for managing account access includes a computer store containing data, wherein the data comprises a privileged-access information. The privileged-access information is gathered from a target-computer system on a network. The privileged-access information is used to authorize a privileged user to access to the target-computer system. A computer processor in the access-manager server, which computer processor gathers the privileged-access information from the target-computer system on a network. The computer processor detects that the information is gathered from the target-computer system. The computer processor removes an existing-account access from the target-computer system. The computer processor obtains the privileged-access information from the computer store. The computer processor enables a privileged user to log into the access manager server using multi-factor authentication. When the privileged user requests access to the target-computer system access via the access manager server, the computer processor verifies an account access is allowed for the privileged user. The computer processor adds the privileged user's account to the target-computer system for an interval specified by the access manager server. During the interval specified the privileged user is enabled to log on to the target-computer system.


