Privileged Access Management via Protocol Frames

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing privileged access in organizations where multiple individuals share credentials is challenging due to attribution difficulties, increased risk of credential compromise, and complex password management, as well as unrestricted access leading to potential misuse.

Innovation Solution

Implementing a system that allows users to access applications using privileged credentials without having access to them, by creating a container to execute the application, logging in with those credentials, and using protocol frames to display the user interface and process user input, while monitoring and logging interactions for auditing purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple individuals share privileged credentials to access applications, then access availability is improved, but attribution difficulty and security risk increase

Engineering Contradiction:
Improveaccess availabilityVSAvoidattribution difficulty
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication mechanism by introducing unique session identifiers and user-specific protocol frames for each individual accessing privileged credentials. This allows the system to maintain multiple simultaneous access sessions while tracking each user's specific actions through their unique session context, resolving the contradiction between shared access availability and individual attribution capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a protocol frame as an intermediary layer between the privileged credentials and the user interface. This intermediary contains user-specific identifiers and session information, enabling the system to distinguish between multiple users sharing the same privileged credentials while maintaining their individual identities throughout the session.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple individuals have unrestricted access to privileged credentials, then operational flexibility is improved, but security risk and misuse potential increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms through protocol frames that continuously monitor and report user actions, session status, and authentication state. This feedback loop enables real-time detection of suspicious activities and provides audit trails, allowing the system to maintain operational flexibility while detecting and preventing security risks and misuse.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary authentication and session setup actions before allowing access to privileged credentials. By establishing secure session contexts and validating user identities in advance through protocol frames, the system prepares security measures beforehand, enabling flexible operation while preventing unauthorized access and misuse.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If privileged credentials are shared among employees, then access efficiency is improved, but credential management complexity increases

Engineering Contradiction:
Improveaccess efficiencyVSAvoidcredential management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates copies of authentication context through protocol frames for each user session rather than managing shared credentials directly. Each protocol frame contains a copy of user-specific identifiers and session state, allowing efficient access to privileged resources while simplifying credential management by replacing shared password management with individual session context copying.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent adds a session dimension to credential access by introducing time-bound protocol frames that expire after use. This transforms static shared credentials into dynamic, time-limited session contexts, maintaining access efficiency while reducing management complexity through automated session lifecycle management.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Speed

If users can access applications directly with privileged credentials, then access speed is improved, but monitoring and auditing capability decreases

Engineering Contradiction:
Improveaccess speedVSAvoidmonitoring capability
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent introduces protocol frames as an intermediary layer between credential authentication and user interface access. This intermediary captures and records all user actions, session metadata, and authentication events, enabling comprehensive monitoring and auditing while maintaining fast access speeds through optimized frame processing and direct UI rendering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11526587B2Privileged access management for applications
Publication Date: 2022.12.13 ONE IDENTITY LLC
  • US11526587B2 patent drawing
  • US11526587B2 patent drawing
  • US11526587B2 patent drawing

AI summary

A user of a client can access an application using privileged credentials without having direct access to or knowledge of the privileged credentials. The user's access to the application can also be monitored using a custom protocol including recording the user's interactions with the application while logged in with the privileged credentials.