Privileged Account Management System Using Elapsed Time Thresholds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current privileged account management (PAM) systems lack effective means to detect unauthorized, risky, or inefficient usage of admin credentials, particularly in monitoring elapsed time for task completion, which can lead to potential security breaches or inefficiencies.

Innovation Solution

A PAM system maintains a database with normal time thresholds for each reason code, tracking and comparing elapsed times for admin credential usage to identify and mitigate excessive usage, taking appropriate actions when thresholds are exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If admin credentials are shared among administrators for server access, then ease of operation is improved, but security and accountability deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the shared admin credentials into individual administrator accounts, where each administrator has their own unique credentials. This is achieved through automated credential generation and assignment to multiple administrators, allowing each to access the server independently while maintaining security accountability through individual authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms by automatically monitoring and logging each administrator's usage of admin credentials. The system tracks authentication events, task completion times, and credential usage patterns, providing continuous feedback to detect anomalies, unauthorized access attempts, or inefficient usage patterns that indicate security risks.

Inventive Principle:
Principle #23Feedback

2Reliability

If administrators are monitored during server access, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service monitoring where the PAM system automatically performs authentication, credential management, usage tracking, and anomaly detection without requiring external monitoring infrastructure. The system self-manages the entire monitoring process including automated logging, time-based analysis, and security policy enforcement, reducing the need for additional monitoring devices or complex external systems.

Inventive Principle:
Principle #25Self-service

3Productivity

If elapsed time for task completion is monitored, then productivity is improved, but measurement precision requirements increase

Engineering Contradiction:
ImproveproductivityVSAvoidmeasurement precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent transforms the monitoring approach by changing the parameter from precise task-level timing to aggregate elapsed time measurement. Instead of tracking exact completion times of individual tasks, the system measures the total elapsed time between credential authentication and credential return, using statistical thresholds to identify anomalies. This parameter change reduces measurement precision requirements while maintaining productivity monitoring effectiveness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9813422B2Detecting unauthorized risky or inefficient usage of privileged credentials through analysis of task completion timing
Publication Date: 2017.11.07 ONE IDENTITY LLC
  • US9813422B2 patent drawing
  • US9813422B2 patent drawing
  • US9813422B2 patent drawing

AI summary

A privileged account management system can maintain a database that defines a normal amount of time that it takes to perform a task associated with a reason code. When an administrator requests admin credentials for accessing a server, the administrator can provide a reason code which defines a task that the administrator intends to accomplish. A PAM system can maintain a database that defines, for each reason code, a normal amount of time that is required to accomplish the task associated with the reason code. The PAM system can then monitor an elapsed time over which the admin credentials are checked out to an administrator to determine whether the elapsed time exceeds the corresponding normal amount of time. If the elapsed time exceeds the normal amount, the PAM system can take appropriate action to mitigate any potential harm to the server.