Policy Enforcement Point for Dynamic Privileged Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mechanisms for proxy authentication and activity monitoring in emergency access scenarios are inflexible and inadequate for accommodating temporary or emergency access across various applications and systems, particularly in web and mobile access environments, failing to support end-to-end monitoring and compliance requirements.
Innovation Solution
A policy-based privileged user access management system utilizing a rule engine as a Policy Enforcement Point (PEP) to dynamically manage access, allowing user selection of pre-configured IDs or dynamically generated IDs based on user input, with federated authentication and supplemental activity logging to ensure compliance and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional proxy authentication mechanisms are used, then access control is maintained, but flexibility for emergency access scenarios is insufficient
Solution Approach 1:
The patent introduces a Policy Enforcement Point (PEP) as an intermediary component that sits between the user and the target system. The PEP receives authentication assertions from an Identity Provider, evaluates them against defined policies using a rule engine, and makes access decisions. This intermediary architecture allows flexible emergency access while maintaining security through centralized policy control, resolving the contradiction between adaptability and complexity.
Solution Approach 2:
The patent implements dynamic access control by allowing policies to be evaluated at runtime based on authentication assertions. The rule engine can dynamically determine access parameters such as logging levels, session timeouts, and permission scopes based on the specific authentication context. This dynamic evaluation enables the system to adapt to emergency scenarios while maintaining a structured policy framework.
2Reliability
If strict access control is implemented for security and compliance, then monitoring is improved, but business flexibility for emergency access is reduced
Solution Approach 1:
The patent defines access policies and authentication assertions in advance before actual access is needed. Organizations can pre-configure emergency access scenarios with appropriate logging levels and monitoring parameters. When emergency access is required, the system retrieves the pre-defined authentication assertion and applies the corresponding policy, enabling rapid access while maintaining security and compliance through预先 established controls.
Solution Approach 2:
The patent allows dynamic adjustment of access parameters based on the authentication assertion and policy evaluation. The rule engine can modify parameters such as logging intensity, session duration, and permission scope according to the specific emergency scenario. This parameter flexibility enables the system to balance security monitoring requirements with business operational needs in emergency situations.
3Ease of operation
If conventional emergency access systems focus on user management, then user access control is improved, but end-to-end activity monitoring is insufficient
Solution Approach 1:
The patent segments the access management function into distinct components: authentication (handled by the Identity Provider), authorization (handled by the PEP and rule engine), and activity monitoring (handled by the system's activity log). This segmentation allows each component to specialize in its function, ensuring that user access control and activity monitoring are both thoroughly implemented without interfering with each other.
Solution Approach 2:
The patent implements feedback mechanisms through supplemental activity logging that captures user actions during emergency access sessions. The PEP logs detailed activity information and makes this feedback available for review by administrators. This feedback loop ensures complete activity monitoring while maintaining ease of operation for users during emergency scenarios.
Data Source
AI summary
Embodiments dynamically manage privileged access to a computer system according to policies enforced by rule engine. User input to the rule engine may determine an extent of system access, as well as other features such as intensity of user activity logging (including logging supplemental to a system activity log). Certain embodiments may provide access based upon user selection of a pre-configured ID at a dashboard, while other embodiments may rely upon direct user input to the rule engine to generate an ID at a policy enforcement point. Embodiments of methods and apparatuses may be particularly useful in granting and/or logging broad temporary access rights allowed based upon emergency conditions.


