Problem-Based Account Generation for Secure Remote Support
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods for computing systems, such as servers and storage systems, are inadequate due to shared and static passwords, leading to security vulnerabilities and delays in technical support, especially when external parties are involved.
Innovation Solution
A method and apparatus for providing problem-based access, where a user account is automatically generated and tied to a detected issue, enabling remote access for service technicians while ensuring secure communication and temporary access termination post-resolution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single pre-defined service account with a static password is used for access control, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent implements dynamic password generation where passwords automatically change over time and are tied to specific service accounts. Each service account has a unique password that is periodically regenerated, transforming the static password system into a dynamic one that adapts to security requirements while maintaining operational ease through automated account management.
Solution Approach 2:
The patent segments the single service account into multiple individual service accounts, each with its own unique password and specific authorization scope. This segmentation allows different technicians to access only the systems they need for their specific problems, improving security while maintaining ease of operation through targeted access control.
2Reliability
If passwords are frequently changed to improve security, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system implements automated password generation and distribution where service accounts automatically receive new passwords without manual intervention. The password management system autonomously handles generation, distribution, and expiration, eliminating the manual overhead of password changes while maintaining strong security through frequent automatic updates.
Solution Approach 2:
The system pre-generates and stores multiple passwords for each service account before they are needed. When a password change is required, the system simply transitions to the next pre-generated password, eliminating the time-consuming process of creating and distributing new passwords manually while maintaining security through regular rotation.
3Reliability
If customer controls user accounts and passwords to improve security, then security is improved, but productivity deteriorates
Solution Approach 1:
The patent introduces an intermediary password management system that bridges customer security requirements and vendor support needs. This intermediary system allows vendor technicians to obtain temporary access credentials through an automated process without requiring customer intervention, while the customer maintains ultimate control through system-wide security policies and account management.
Solution Approach 2:
The system pre-establishes service accounts and authorization frameworks before support incidents occur. When a technical issue arises, pre-configured service accounts can be automatically activated with appropriate permissions, eliminating the need for real-time customer intervention while maintaining security through pre-approved access levels.
4Productivity
If vendor creates service accounts to improve support efficiency, then productivity is improved, but security deteriorates
Solution Approach 1:
The patent implements local quality by giving each service account specific authorization scopes tailored to the particular problem or system being serviced. Instead of broad administrative privileges, each service account receives only the minimum necessary permissions for its specific function, maintaining security while enabling efficient technical support through appropriately scoped access.
Data Source
AI summary
A method to provide problem-based access to a computing device is disclosed herein. In one embodiment of the invention, such a method includes detecting a problem on a computing device. The method automatically generates a user account on the computing device in response to detecting the problem. The problem is then tied to the user account. A support provider is then notified of the problem and the user account associated with the problem. This user account may be assigned to a service technician to enable access to the computing device. The service technician may then log into the computing device using the user account and address the problem. A corresponding apparatus and computer program product are also disclosed herein.


