Privileged Account Management System for Access Accountability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face security risks due to shared passwords among users, making it impossible to track individual user transactions and account for system usage, leading to unaccountable access and potential insider threats.

Innovation Solution

A method that generates unique user IDs and passwords for each user while tracking transactions and comparing them to access permissions, ensuring accountability by flagging and logging user activities and permissions within the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single password is shared among a group of users, then equal system access is ensured for all team members, but individual user transaction tracking becomes impossible and security accountability is lost

Engineering Contradiction:
Improvesystem accessVSAvoidsecurity accountability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the shared group password into multiple individual user passwords. Each user within a group is assigned a unique password that is derived from or associated with the group password, allowing individual identification while maintaining group-level access control. This segmentation enables both equal access (all group members can access) and individual tracking (each user's transactions are identifiable).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication system that sits between the user and the system resources. This intermediary component generates and manages individual user passwords, tracks their usage, and logs transactions. The intermediary maintains the connection to the original group password while enabling detailed individual accountability through its mediation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individual user passwords are implemented, then user transaction tracking and security accountability are improved, but system complexity and password management overhead increase

Engineering Contradiction:
Improvesecurity accountabilityVSAvoidpassword management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal password management system that handles multiple functions: it generates individual user passwords, manages group assignments, tracks transactions, and provides authentication. This multi-functional system consolidates what would otherwise be separate complex systems into a single integrated solution, reducing overall complexity while maintaining individual accountability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service capabilities where users can autonomously authenticate using their individual passwords without requiring manual intervention from administrators. The system automatically tracks transactions and manages password validity periods, reducing the operational overhead for password management while maintaining security accountability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9832184B2Controls and administration of privileged accounts system
Publication Date: 2017.11.28 BANK OF AMERICA CORP
  • US9832184B2 patent drawing
  • US9832184B2 patent drawing
  • US9832184B2 patent drawing

AI summary

Apparatus and methods for enhancing group access accountability are provided. The method may include receiving a request from a user to access a system and user-identifying information associated with the user. The method may also include querying a database to retrieve a group ID number associated with at least a portion of the user-identifying information and access permissions associated with the group ID number. The method may further include querying a database to retrieve a user ID and password associated with the group ID number. The user ID and password may be selected from a group of usernames and passwords associated with the group ID number. The method may additionally include flagging the user ID and password with a flag, the flag indicating that the user ID and password are in use, and transmitting the user ID and password to the user.