Dynamic User Privilege Profiles for Network-Connected Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing device privileges lack a convenient way to dynamically add and remove access rights, leading to security risks due to users having excessive privileges, which can compromise devices and networks, especially in dynamic environments where additional privileges are frequently required but often not properly reverted.

Innovation Solution

A system and method for generating and managing user privilege profiles on devices, which include rules for granting and revoking privileges based on network connections, location, and time, enabling temporary administrative rights while connected to a specific LAN and disabling them upon disconnection or expiration, thereby enforcing the principle of least privilege.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users are granted administrative privileges to perform tasks, then task completion capability is improved, but security risk increases due to excessive privileges

Engineering Contradiction:
Improvetask completion capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic privilege management where administrative privileges are not permanently granted but are activated temporarily based on real-time conditions. The system continuously monitors network connection status, location, and time, dynamically enabling or disabling privileges accordingly. This resolves the contradiction by providing adaptability only when needed while maintaining security during other periods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary evaluation of conditions (network connectivity, location verification, time checks) before granting privileges. The privilege framework pre-establishes the rules and conditions that must be satisfied, and only after verification does it activate the administrative rights. This preliminary action ensures security is maintained while enabling capability when prerequisites are met.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If privileges are granted temporarily based on conditions, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the privilege management system into distinct independent modules: a privilege framework that handles policy enforcement, a monitoring module that tracks conditions, and an execution module that applies changes. This segmentation allows each component to be developed, maintained, and updated independently, reducing overall system complexity while maintaining enhanced security through coordinated operation of these modular components.

Inventive Principle:
Principle #1Segmentation

3Manufacturing precision

If manual privilege management is used, then control precision is improved, but productivity decreases due to time-consuming operations

Engineering Contradiction:
Improvecontrol precisionVSAvoidprivilege management efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system implements self-service privilege management where the automated framework continuously monitors conditions and applies privilege changes without manual intervention. The monitoring module automatically detects network connection status, location changes, and time expiration, and the framework automatically grants or revokes privileges accordingly. This self-service mechanism maintains precise control through rule-based decision-making while dramatically improving productivity by eliminating manual operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11108781B2Systems and methods for managing device privileges
Publication Date: 2021.08.31 THE HUNTINGTON NAT BANK
  • US11108781B2 patent drawing
  • US11108781B2 patent drawing
  • US11108781B2 patent drawing

AI summary

Systems and methods are described herein for managing device privileges.