Dynamic Scope Adjustment for IT Support Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ITSM systems face security threats due to broad authorization granted to IT support providers, allowing unauthorized access and operation of user devices without real-time visibility or control, leading to vulnerabilities, especially when provided by external organizations.

Innovation Solution

Implementing a dynamic scope adjustment method within an incident management system that dynamically elevates user device access privileges for IT support providers only when a technical issue occurs, allowing temporary remote access and control, and subsequently relegating access once the issue is resolved, with optional restrictions on access periods or conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If broad authorization is granted to IT support providers for efficient service implementation, then service efficiency is improved, but network security is compromised due to unauthorized access and operation of user devices

Engineering Contradiction:
Improveservice efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic scope adjustment that allows IT support providers to access user devices only when incidents are actively being resolved. The authorization scope expands to include the affected user device during incident mitigation, then automatically contracts back to baseline restrictions after resolution. This dynamic adjustment resolves the contradiction by providing broad access only temporarily when service efficiency is needed, while maintaining security during normal operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authorization parameter (scope of access) based on the incident state. When an incident is detected, the scope parameter expands to include the user device and relevant system components. As the incident is resolved, the scope parameter contracts back to restricted levels. This parameter change approach allows efficient service delivery during incidents while maintaining security posture during normal states.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If continuous authorization is provided to IT support providers, then incident mitigation efficiency is improved, but security risk increases due to potential unauthorized operations and lack of real-time visibility

Engineering Contradiction:
Improveincident mitigation efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements periodic authorization where IT support providers receive access rights only during the active incident resolution period. The authorization is granted at the start of incident mitigation and automatically revoked upon resolution. This periodic action pattern ensures continuous access when needed for efficient mitigation while eliminating continuous authorization risks during normal operations.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system preemptively limits the scope of authorization to only what is necessary for incident resolution. By default, IT support providers have restricted access, and the system proactively expands scope only to the minimum required resources for the specific incident. This preliminary anti-action prevents excessive authorization from being granted in the first place, reducing security risk while maintaining mitigation efficiency.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If IT support providers are assigned access privileges to user devices, then remote troubleshooting capability is improved, but security vulnerabilities are introduced through anonymous operations and data access

Engineering Contradiction:
Improveremote troubleshooting capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by granting IT support providers access privileges only to the specific user device and related system components affected by the incident, rather than broad access across the entire network. The scope of authorization is localized to the incident context, enabling effective remote troubleshooting of the specific issue while minimizing security vulnerabilities associated with wide-ranging access rights.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11570064B2Dynamic scope adjustment
Publication Date: 2023.01.31 IVANTI INC
  • US11570064B2 patent drawing
  • US11570064B2 patent drawing
  • US11570064B2 patent drawing

AI summary

An embodiment includes a method of secured, remote device access through dynamic scope adjustment in an incident management system. The method includes receiving an incident report indicative of a technical issue at a first device. Responsive to receipt of the incident report, the method includes determining that the first device is assigned an information technology (IT) support provider and dynamically elevating the first device to a scope of the IT support provider. Following a correction of at least a portion of the technical issue by the IT support provider, the method includes dynamically relegating the first device from the scope to prevent remote access to the first device following the correction.