Privileged Account Access With Dynamic Enablement and MFA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Privileged accounts pose a significant cybersecurity risk due to their elevated rights, making systems vulnerable to compromise and potential data leakage if not properly controlled.

Innovation Solution

An account privilege manager is implemented to disable privileged accounts by default, requiring user authentication through a mobile device using a random number or one-time password before enabling elevated rights, thereby reducing the risk of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If privileged accounts are kept enabled for ease of access, then ease of operation is improved, but system security deteriorates due to increased vulnerability to compromise

Engineering Contradiction:
Improveease of accessVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic privilege management where account enablement status changes based on real-time conditions. Privileged accounts transition between enabled and disabled states according to authentication outcomes, time-of-day rules, and approval workflows, allowing the system to adapt access levels dynamically rather than maintaining static enablement states

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication and approval actions before enabling privileged accounts. Pre-approval workflows, multi-factor authentication, and manager approvals are executed in advance to verify user legitimacy before granting elevated rights, preventing unauthorized access before it can occur

Inventive Principle:
Principle #10Preliminary action

2Reliability

If privileged accounts are disabled by default to improve security, then system security is improved, but ease of operation deteriorates due to reduced access availability

Engineering Contradiction:
Improvesystem securityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces intermediary components including approval workflows and multi-factor authentication mechanisms that mediate between the disabled state and privileged access. These intermediaries verify user identity and authority before transitioning accounts from disabled to enabled states, ensuring security while enabling legitimate access when needed

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication requirements are increased to verify user identity, then system security is improved, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improveuser identity verificationVSAvoidauthentication mechanisms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service authentication capabilities where users independently complete multi-factor authentication using their own mobile devices. Users generate and verify one-time passwords without requiring manual intervention from administrators, automating the authentication process and reducing operational complexity despite enhanced security verification

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12598187B2System and method for managing privileged account access
Publication Date: 2026.04.07 SAUDI ARABIAN OIL CO
  • US12598187B2 patent drawing
  • US12598187B2 patent drawing
  • US12598187B2 patent drawing

AI summary

A system and method is described that reduces a likelihood that a privileged account at a system (e.g., device, network, and/or application) for a user is compromised. For example, the privileged account for the user at the system is disabled in response to being created. The user can provide a request for at least one elevated right at the system corresponding to a request to use the privileged account at the system. An identity of the user is authenticated in response to receiving the request to confirm that the user is requesting the privileged account at the system. The privileged account for the user is enabled at the system to allow the user to perform at least one action that the user was not previously allowed to perform.