Privileged Activity Manager for Just-in-Time Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Privileged Access Management (PAM) solutions are too expensive, complex, and focus on controlling access to accounts rather than the activities needed, leading to a minimal reduction in the attack surface and requiring organizations to purchase full stacks of offerings, which can be risky and costly to remove and replace.

Innovation Solution

A Privileged Activity Manager that provides task-based administrative access using a just-in-time and just-enough privilege approach, adding and removing privileges in discrete modular steps based on specific activities, ensuring that users have the necessary permissions only when performing a task and reverting to a no-access-by-default state immediately after completion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PAM solutions control access to accounts, then account security is improved, but the attack surface is minimally reduced and complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidPAM solution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments privileged access control into discrete modular steps that can be individually added or removed based on specific activity requirements. Instead of managing entire account privileges, the system breaks down access control into granular permission units that are allocated temporarily for specific tasks, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic privilege allocation where permissions are added and removed in real-time based on activity needs. Privileges are not statically assigned to accounts but are dynamically granted for specific tasks and automatically revoked afterward, making the security system adaptable and reducing the permanent attack surface.

Inventive Principle:
Principle #15Dynamics

2Reliability

If full stack PAM offerings are purchased, then comprehensive security coverage is improved, but cost and replacement risk increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidPAM offering complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent decomposes comprehensive PAM functionality into separate, independently deployable modules. Organizations can selectively implement only the security controls needed for specific activities rather than purchasing entire PAM stacks, reducing cost and complexity while maintaining essential security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides universal activity-based privilege management that can be applied across multiple contexts and platforms. The same core mechanism of adding/removing privileges based on activities can serve various security needs without requiring separate specialized solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If privileges are continuously assigned to accounts, then administrative task completion is improved, but attack surface increases

Engineering Contradiction:
Improvetask completion efficiencyVSAvoidattack surface
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements periodic privilege allocation where permissions are granted temporarily for specific time periods or task durations, then automatically revoked. This periodic granting and revoking of privileges maintains productivity during active tasks while minimizing the attack surface when privileges are not in use.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Privilege states are dynamically changed based on task requirements - privileges are added when needed for task completion and removed afterward. This dynamic approach ensures continuous productivity during authorized tasks while reducing the persistent attack surface by eliminating standing privileges.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12028346B1Privileged activity manager
Publication Date: 2024.07.02 STEALTHBITS TECHNOLOGIES LLC
  • US12028346B1 patent drawing
  • US12028346B1 patent drawing
  • US12028346B1 patent drawing

AI summary

A method is described. The method includes adding privileges using discrete modular steps to an account based on a requested activity to be performed during a session. The method also includes logging the account into the session with the added privileges. The method further includes removing the privileges using discrete modular steps from the account after the session.