Privileged Access Management via Protocol Frames
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing privileged access in organizations where multiple individuals share credentials is challenging due to attribution difficulties, increased risk of credential compromise, and complex password management, as well as unrestricted access leading to potential misuse.
Innovation Solution
Implementing a system that allows users to access applications using privileged credentials without having access to them, by creating a container to execute the application, logging in with those credentials, and using protocol frames to display the user interface and process user input, while monitoring and logging interactions for auditing purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple individuals share privileged credentials to access applications, then access availability is improved, but attribution difficulty and security risk increase
Solution Approach 1:
The patent segments the authentication mechanism by introducing unique session identifiers and user-specific protocol frames for each individual accessing privileged credentials. This allows the system to maintain multiple simultaneous access sessions while tracking each user's specific actions through their unique session context, resolving the contradiction between shared access availability and individual attribution capability.
Solution Approach 2:
The patent introduces a protocol frame as an intermediary layer between the privileged credentials and the user interface. This intermediary contains user-specific identifiers and session information, enabling the system to distinguish between multiple users sharing the same privileged credentials while maintaining their individual identities throughout the session.
2Adaptability or versatility
If multiple individuals have unrestricted access to privileged credentials, then operational flexibility is improved, but security risk and misuse potential increase
Solution Approach 1:
The patent implements feedback mechanisms through protocol frames that continuously monitor and report user actions, session status, and authentication state. This feedback loop enables real-time detection of suspicious activities and provides audit trails, allowing the system to maintain operational flexibility while detecting and preventing security risks and misuse.
Solution Approach 2:
The patent performs preliminary authentication and session setup actions before allowing access to privileged credentials. By establishing secure session contexts and validating user identities in advance through protocol frames, the system prepares security measures beforehand, enabling flexible operation while preventing unauthorized access and misuse.
3Productivity
If privileged credentials are shared among employees, then access efficiency is improved, but credential management complexity increases
Solution Approach 1:
The patent creates copies of authentication context through protocol frames for each user session rather than managing shared credentials directly. Each protocol frame contains a copy of user-specific identifiers and session state, allowing efficient access to privileged resources while simplifying credential management by replacing shared password management with individual session context copying.
Solution Approach 2:
The patent adds a session dimension to credential access by introducing time-bound protocol frames that expire after use. This transforms static shared credentials into dynamic, time-limited session contexts, maintaining access efficiency while reducing management complexity through automated session lifecycle management.
4Speed
If users can access applications directly with privileged credentials, then access speed is improved, but monitoring and auditing capability decreases
Solution Approach 1:
The patent introduces protocol frames as an intermediary layer between credential authentication and user interface access. This intermediary captures and records all user actions, session metadata, and authentication events, enabling comprehensive monitoring and auditing while maintaining fast access speeds through optimized frame processing and direct UI rendering.
Data Source
AI summary
A user of a client can access an application using privileged credentials without having direct access to or knowledge of the privileged credentials. The user's access to the application can also be monitored using a custom protocol including recording the user's interactions with the application while logged in with the privileged credentials.


