Identity Change Control Agent for Shared Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing shared accounts in IT systems do not effectively prevent unauthorized access when users bypass the security measures by switching from individual accounts to shared accounts using identity change instructions, leading to security issues.

Innovation Solution

Implementing an identity change control agent that detects and verifies whether a shared account is checked out before allowing or blocking identity changes, ensuring that only authorized users can access shared accounts by intercepting and managing identity change instructions and sending notifications for failed attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to switch to shared accounts using identity change instructions from individual accounts, then ease of operation is improved, but security is worsened due to bypassing server security measures

Engineering Contradiction:
Improveease of access to shared accountsVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary between individual accounts and shared accounts. The server intercepts identity change instructions, verifies authorization, and controls the switching process. This mediator prevents direct bypass of security measures while maintaining operational ease through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server performs preliminary verification before allowing identity change to shared accounts. By checking authorization status and account checkout state in advance, the system prevents unauthorized access while enabling legitimate users to switch accounts efficiently.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the server manages and controls access to shared accounts through checkout/checkin processes, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server implements a universal access management mechanism that handles multiple functions: authorization verification, checkout status checking, identity change instruction interception, and security control. This multi-functional approach consolidates complexity into a single centralized system rather than requiring separate controls for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If one-time passwords are issued for each checkout, then security is improved, but loss of time increases due to repeated password generation and distribution

Engineering Contradiction:
ImprovesecurityVSAvoidtime for password management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automates the one-time password generation and distribution process. The server automatically generates, sends, and manages passwords without requiring manual intervention. Users simply need to request access, and the system handles the entire password management process autonomously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9268917B1Method and system for managing identity changes to shared accounts
Publication Date: 2016.02.23 CA TECH INC
  • US9268917B1 patent drawing
  • US9268917B1 patent drawing
  • US9268917B1 patent drawing

AI summary

A method includes detecting an identity change instruction. The method also includes identifying a target account associated with the identity change instruction. The method also includes determining whether the target account is checked out. The method also includes passing the identity change instruction to a kernel in response to determining that the target account is checked out. The method also includes blocking the identity change instruction in response to determining that the target account is not checked out.