Service Account Dormancy Detection for Automated Disablement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in efficiently, securely, and uniformly managing internal computer systems that exchange information with external systems, particularly in identifying and disabling dormant service accounts, which pose security risks and processing overhead.

Innovation Solution

An automated system identifies dormant service accounts by scanning historical activity records and soliciting user feedback, then automatically disabling them to reduce security risks and computational overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service accounts are maintained for testing and limited uses, then account functionality and versatility are improved, but security risks and computational overhead increase

Engineering Contradiction:
Improveaccount functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing baseline activity metrics and monitoring thresholds for service accounts before dormancy occurs. This allows the system to proactively identify dormant accounts through continuous monitoring of activity levels against predefined criteria, enabling early intervention before security risks escalate.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring service account activity and comparing it against baseline metrics. When activity falls below thresholds indicating dormancy, the system provides feedback through automated notifications to administrators, who can then verify account status and take appropriate action, creating a closed-loop security management process.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual monitoring and disabling of dormant service accounts is performed, then security management control is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity management controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by implementing automated monitoring and identification of dormant service accounts. The system autonomously tracks account activity, compares it against baseline metrics, and generates notifications without requiring continuous manual intervention, thereby reducing time consumption while maintaining reliable security management through automated enforcement of security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical monitoring processes with automated computational mechanisms. Instead of administrators manually reviewing account activity logs, the system uses automated algorithms to analyze activity data, identify dormant accounts, and trigger notifications, significantly reducing time consumption while improving consistency and reliability of security management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive historical activity scanning is performed to identify dormant accounts, then identification accuracy is improved, but computational costs and processing time increase

Engineering Contradiction:
Improveidentification accuracyVSAvoidcomputational costs
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by implementing tiered monitoring strategies that focus computational resources on accounts with higher risk profiles or those showing signs of reduced activity. Instead of uniformly scanning all accounts with equal intensity, the system adjusts monitoring depth based on account criticality and observed activity patterns, maintaining high identification accuracy while reducing overall computational costs through selective deep-dive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250373619A1Dormant Service Account Disablement System
Publication Date: 2025.12.04 BANK OF AMERICA CORP
  • US20250373619A1 patent drawing
  • US20250373619A1 patent drawing
  • US20250373619A1 patent drawing

AI summary

Various aspects of the disclosure relate to identifying and disabling dormant service accounts. An account management system automatically analyzes service account activity records to determine whether each service account defined for an enterprise network is in use. Automated monitoring applications may be used for identifying and authenticating events and/or authentications of service accounts across an enterprise network. When particular service accounts are identified as being potentially dormant, based on an identified date of last use meeting a threshold condition, the associated service accounts are flagged as being dormant. Setting an account as being dormant triggers solicitation of feedback confirming the dormant setting, which causes disablement of the service account. The account management system triggers decommissioning of the dormant service accounts upon expiration of a disablement threshold.