Privileged Identity Management Session Extension via Mobile Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often experience session timeouts in computer systems and software applications due to missed notifications for privilege extensions, leading to lost information and the need for re-authentication, especially when they are distracted or not actively monitoring their devices.

Innovation Solution

A privileged identity management system that allows users to request and manage elevated privileges, with the ability to extend sessions via another device, such as a mobile device, which is typically more responsive to notifications, thereby preventing session expirations and reducing the need for re-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system uses self-service authorization extension requiring user attention, then security is maintained, but user productivity decreases due to missed notifications and session timeouts

Engineering Contradiction:
Improvesession continuityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a mobile device as an intermediary communication channel between the authorization system and the user. When a session is about to expire, the system sends notifications to the mobile device, which alerts the user and provides extension options. This intermediary approach ensures reliable session continuity while maintaining user productivity by delivering notifications through a device the user is likely to be checking.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops by monitoring session expiration times and actively notifying users through multiple channels (browser pop-ups, mobile device notifications, emails). This feedback mechanism ensures users are informed of impending session endings and can take action to extend their authorization, thereby maintaining both security and productivity.

Inventive Principle:
Principle #23Feedback

2Reliability

If the system provides multiple notification channels, then notification reliability improves, but system complexity increases

Engineering Contradiction:
Improvenotification deliveryVSAvoidnotification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal presence of mobile devices in users' lives to deliver notifications through multiple channels (SMS, push notifications, emails). Rather than building complex notification infrastructure, the system utilizes existing communication platforms that users already interact with, thereby achieving high notification reliability without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the system requires re-authentication after timeout, then security is strengthened, but user time and productivity are lost

Engineering Contradiction:
ImprovesecurityVSAvoidtime for re-authentication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by sending advance notifications before session expiration occurs. Users are alerted of impending timeouts and given the opportunity to extend their sessions in advance, preventing the need for re-authentication and time loss. This preliminary warning approach maintains security while eliminating the time penalty associated with post-timeout re-authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11757899B2Privileged identity management
Publication Date: 2023.09.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11757899B2 patent drawing
  • US11757899B2 patent drawing
  • US11757899B2 patent drawing

AI summary

Aspects of a privileged identity management system and method provide users with the ability to request elevated privileges to perform tasks on computing systems and software applications. The privileged identity management system and method also provides users with the ability to extend the elevated privileges to access privileged features or perform tasks using elevated privileges. The privileged identity management system and method utilize a different device that is readily available to the user in order to provide communications relating to the elevated privileges.