Remote Privilege Elevation via Agent-Based Credential Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems face security breaches due to shared administrator credentials, which are only as secure as the credentials themselves and pose challenges in managing and tracing access to administrative functions.

Innovation Solution

The implementation of an agent on client devices that requests remote elevation of user privileges without requiring credentials, using a remote management system to evaluate and approve or deny these requests based on predefined rules, eliminating the need for shared credentials and enhancing security by providing temporary, credential-less administrator logons during remote access sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If shared administrator credentials are used for privilege elevation, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the credential verification process from the local system and relocates it to a remote management server. The agent on the client device requests elevation without embedding credentials, instead transmitting the elevation request to the remote server which verifies authorization and returns approval. This removes credentials from the operational flow entirely, eliminating the security risk while maintaining ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The remote management server acts as an intermediary between the client device and the privilege elevation process. Instead of directly using shared credentials locally, the system introduces a mediator that receives elevation requests, verifies them against stored policies and user authorizations, and returns approval or denial. This intermediary layer eliminates the need for credential transmission while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote elevation requests are manually approved, then security is improved, but productivity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic approval rules that automatically adjust the elevation approval process based on contextual factors such as user role, time of day, requested privileges, and device state. For routine operations during business hours from authorized users, the system automatically approves elevation requests. For unusual or high-risk requests, it requires manual review. This dynamic approach maintains security while maximizing productivity for legitimate operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of the approval process based on the specific context of each elevation request. Rather than a static manual approval requirement for all requests, the system evaluates multiple parameters (user authorization level, requested privilege scope, time constraints, device state) and adjusts the approval mechanism accordingly. This allows automatic approval for low-risk scenarios while maintaining manual review for high-risk scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240333723A1Systems and Methods for Anonymous Administrative Login
Publication Date: 2024.10.03 CONNECTWISE LLC
  • US20240333723A1 patent drawing
  • US20240333723A1 patent drawing
  • US20240333723A1 patent drawing

AI summary

Systems and methods for end user elevation and anonymous administrative login are disclosed. An agent executing on a client device can provide a graphical element within a user interface presented by the client device upon detection of a request for elevated user privileges. Upon an interaction with the graphical element, the agent transmits, to a server, data corresponding to the request for elevated user privileges, and receives, from the server, a message indicating approval of the request for elevated user privileges. The agent provides, to the operating system of the client device, an indication that the request for elevated user privileges is approved. In an embodiment, the agent determines that a remote