Identity Change Control Agent for Shared Account Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for managing shared accounts in IT systems do not effectively prevent unauthorized access when users bypass the security measures by switching from individual accounts to shared accounts using identity change instructions, leading to security issues.
Innovation Solution
Implementing an identity change control agent that detects and verifies whether a shared account is checked out before allowing or blocking identity changes, ensuring that only authorized users can access shared accounts by intercepting and managing identity change instructions and sending notifications for failed attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are allowed to switch to shared accounts using identity change instructions from individual accounts, then ease of operation is improved, but security is worsened due to bypassing server security measures
Solution Approach 1:
The patent introduces a server as an intermediary between individual accounts and shared accounts. The server intercepts identity change instructions, verifies authorization, and controls the switching process. This mediator prevents direct bypass of security measures while maintaining operational ease through centralized management.
Solution Approach 2:
The server performs preliminary verification before allowing identity change to shared accounts. By checking authorization status and account checkout state in advance, the system prevents unauthorized access while enabling legitimate users to switch accounts efficiently.
2Reliability
If the server manages and controls access to shared accounts through checkout/checkin processes, then security is improved, but device complexity increases
Solution Approach 1:
The server implements a universal access management mechanism that handles multiple functions: authorization verification, checkout status checking, identity change instruction interception, and security control. This multi-functional approach consolidates complexity into a single centralized system rather than requiring separate controls for each function.
3Reliability
If one-time passwords are issued for each checkout, then security is improved, but loss of time increases due to repeated password generation and distribution
Solution Approach 1:
The system automates the one-time password generation and distribution process. The server automatically generates, sends, and manages passwords without requiring manual intervention. Users simply need to request access, and the system handles the entire password management process autonomously.
Data Source
AI summary
A method includes detecting an identity change instruction. The method also includes identifying a target account associated with the identity change instruction. The method also includes determining whether the target account is checked out. The method also includes passing the identity change instruction to a kernel in response to determining that the target account is checked out. The method also includes blocking the identity change instruction in response to determining that the target account is not checked out.


