Privileged Access Management via Risk-Based Granular Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing privileged access management systems in network systems often rely on fixed sets of permissions and durations, which can be inadequate for diverse user purposes, leading to security risks and user burden, especially in complex environments with multiple vendors and devices.

Innovation Solution

A privileged access management system that allows users to request customized sets of permissions based on specific purposes, enabling granular control over access levels and durations, and integrating with a centralized API to manage access across multiple devices and vendors in an Open RAN environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fixed sets of permissions and durations are used for privileged access, then management is simplified, but security risks increase and user needs are not met

Engineering Contradiction:
Improveaccess management simplicityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments privileged access into granular permission sets that can be individually selected and configured. Instead of providing fixed blanket permissions, the system divides access rights into specific categories and allows administrators to assign only the necessary permissions for each user's task, thereby maintaining simplicity while reducing security risks through precise control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic permission duration that adjusts based on task requirements and user behavior. Access permissions are not static but can be extended, revoked, or modified in real-time based on ongoing task needs and security events, allowing the system to adapt to changing conditions while maintaining security oversight.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If fixed sets of permissions are provided, then administrative overhead is reduced, but user efficiency decreases due to inadequate access control

Engineering Contradiction:
Improveadministrative overheadVSAvoiduser efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent applies local quality by providing customized permission sets tailored to each user's specific role, task, and device context. Instead of uniform permission allocation, the system configures localized access rights that match the precise requirements of each user scenario, improving user efficiency without significantly increasing administrative burden through automated profiling.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables parameter changes in permission configurations based on task requirements, user credentials, and device types. The system dynamically adjusts permission parameters such as access scope, duration, and level based on real-time conditions, allowing users to receive appropriate access control without manual customization for each scenario.

Inventive Principle:
Principle #35Parameter changes

3Duration of action of moving object

If privileged access is granted for longer durations, then user convenience is improved, but security exposure increases

Engineering Contradiction:
Improveaccess durationVSAvoidsecurity exposure
Core Design Contradiction:
Duration of action of moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic review and automatic expiration of privileged access permissions. Access rights are granted for specific time periods that align with task completion, and the system periodically reassesses the need for continued access. This creates a rhythm of granted and revoked permissions that maintains user convenience for legitimate tasks while limiting security exposure through automatic time-bound expiration.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12255899B2Privileged access request system
Publication Date: 2025.03.18 RAKUTEN SYMPHONY INC
  • US12255899B2 patent drawing
  • US12255899B2 patent drawing
  • US12255899B2 patent drawing

AI summary

Privileged access is managed by receiving a request for privileged access to a device connected to a network, determining a risk level associated with the request based on a duration of the privileged access, a device identifier, a first user identifier, and a requested privilege level included in the request, identifying a second user to control authorization of the device based on the risk level, and scheduling, in response to receiving authorization from the second user, a process to modify an entry in a permissions database to associate the first user identifier and the device identifier with the requested privilege level for the duration.