Privileged Account Access With Dynamic Enablement and MFA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Privileged accounts pose a significant cybersecurity risk due to their elevated rights, making systems vulnerable to compromise and potential data leakage if not properly controlled.
Innovation Solution
An account privilege manager is implemented to disable privileged accounts by default, requiring user authentication through a mobile device using a random number or one-time password before enabling elevated rights, thereby reducing the risk of unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If privileged accounts are kept enabled for ease of access, then ease of operation is improved, but system security deteriorates due to increased vulnerability to compromise
Solution Approach 1:
The patent implements dynamic privilege management where account enablement status changes based on real-time conditions. Privileged accounts transition between enabled and disabled states according to authentication outcomes, time-of-day rules, and approval workflows, allowing the system to adapt access levels dynamically rather than maintaining static enablement states
Solution Approach 2:
The system performs preliminary authentication and approval actions before enabling privileged accounts. Pre-approval workflows, multi-factor authentication, and manager approvals are executed in advance to verify user legitimacy before granting elevated rights, preventing unauthorized access before it can occur
2Reliability
If privileged accounts are disabled by default to improve security, then system security is improved, but ease of operation deteriorates due to reduced access availability
Solution Approach 1:
The patent introduces intermediary components including approval workflows and multi-factor authentication mechanisms that mediate between the disabled state and privileged access. These intermediaries verify user identity and authority before transitioning accounts from disabled to enabled states, ensuring security while enabling legitimate access when needed
3Reliability
If authentication requirements are increased to verify user identity, then system security is improved, but device complexity increases due to additional authentication mechanisms
Solution Approach 1:
The system implements self-service authentication capabilities where users independently complete multi-factor authentication using their own mobile devices. Users generate and verify one-time passwords without requiring manual intervention from administrators, automating the authentication process and reducing operational complexity despite enhanced security verification
Data Source
AI summary
A system and method is described that reduces a likelihood that a privileged account at a system (e.g., device, network, and/or application) for a user is compromised. For example, the privileged account for the user at the system is disabled in response to being created. The user can provide a request for at least one elevated right at the system corresponding to a request to use the privileged account at the system. An identity of the user is authenticated in response to receiving the request to confirm that the user is requesting the privileged account at the system. The privileged account for the user is enabled at the system to allow the user to perform at least one action that the user was not previously allowed to perform.


