Policy Enforcement Point for Dynamic Privileged Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mechanisms for proxy authentication and activity monitoring in emergency access scenarios are inflexible and inadequate for accommodating temporary or emergency access across various applications and systems, particularly in web and mobile access environments, failing to support end-to-end monitoring and compliance requirements.

Innovation Solution

A policy-based privileged user access management system utilizing a rule engine as a Policy Enforcement Point (PEP) to dynamically manage access, allowing user selection of pre-configured IDs or dynamically generated IDs based on user input, with federated authentication and supplemental activity logging to ensure compliance and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional proxy authentication mechanisms are used, then access control is maintained, but flexibility for emergency access scenarios is insufficient

Engineering Contradiction:
Improveflexibility for emergency accessVSAvoidaccess management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Policy Enforcement Point (PEP) as an intermediary component that sits between the user and the target system. The PEP receives authentication assertions from an Identity Provider, evaluates them against defined policies using a rule engine, and makes access decisions. This intermediary architecture allows flexible emergency access while maintaining security through centralized policy control, resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic access control by allowing policies to be evaluated at runtime based on authentication assertions. The rule engine can dynamically determine access parameters such as logging levels, session timeouts, and permission scopes based on the specific authentication context. This dynamic evaluation enables the system to adapt to emergency scenarios while maintaining a structured policy framework.

Inventive Principle:
Principle #15Dynamics

2Reliability

If strict access control is implemented for security and compliance, then monitoring is improved, but business flexibility for emergency access is reduced

Engineering Contradiction:
Improvesecurity and compliance monitoringVSAvoidbusiness flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent defines access policies and authentication assertions in advance before actual access is needed. Organizations can pre-configure emergency access scenarios with appropriate logging levels and monitoring parameters. When emergency access is required, the system retrieves the pre-defined authentication assertion and applies the corresponding policy, enabling rapid access while maintaining security and compliance through预先 established controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent allows dynamic adjustment of access parameters based on the authentication assertion and policy evaluation. The rule engine can modify parameters such as logging intensity, session duration, and permission scope according to the specific emergency scenario. This parameter flexibility enables the system to balance security monitoring requirements with business operational needs in emergency situations.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If conventional emergency access systems focus on user management, then user access control is improved, but end-to-end activity monitoring is insufficient

Engineering Contradiction:
Improveuser access controlVSAvoidactivity monitoring completeness
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the access management function into distinct components: authentication (handled by the Identity Provider), authorization (handled by the PEP and rule engine), and activity monitoring (handled by the system's activity log). This segmentation allows each component to specialize in its function, ensuring that user access control and activity monitoring are both thoroughly implemented without interfering with each other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms through supplemental activity logging that captures user actions during emergency access sessions. The PEP logs detailed activity information and makes this feedback available for review by administrators. This feedback loop ensures complete activity monitoring while maintaining ease of operation for users during emergency scenarios.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8869234B2System and method for policy based privileged user access management
Publication Date: 2014.10.21 SAP SE
  • US8869234B2 patent drawing
  • US8869234B2 patent drawing
  • US8869234B2 patent drawing

AI summary

Embodiments dynamically manage privileged access to a computer system according to policies enforced by rule engine. User input to the rule engine may determine an extent of system access, as well as other features such as intensity of user activity logging (including logging supplemental to a system activity log). Certain embodiments may provide access based upon user selection of a pre-configured ID at a dashboard, while other embodiments may rely upon direct user input to the rule engine to generate an ID at a policy enforcement point. Embodiments of methods and apparatuses may be particularly useful in granting and/or logging broad temporary access rights allowed based upon emergency conditions.