Unified Super-Session for Multi-Service Access and Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing session management solutions fail to provide a unified user experience and comprehensive auditing for multiple sessions, leading to fragmented monitoring and lack of correlation between actions across sessions.

Innovation Solution

An intermediate element manages access to target services by establishing sub-sessions and unifying them into a single super-session, providing interactive control to the user while ensuring authorization and credential management, and offering monitoring and auditing capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate sessions are established to target services, then each session can be monitored and audited individually, but the user experience is fragmented and actions across sessions are not correlated

Engineering Contradiction:
Improvemonitoring and auditing capabilityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate sessions into a unified super-session that provides a single user interface while maintaining individual session monitoring. The session manager combines multiple target service sessions into one unified session experience, allowing users to interact with multiple services through a single interface while the system continues to monitor and audit each underlying session separately. This resolves the contradiction by combining sessions for user convenience while preserving individual session tracking for reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The session manager acts as an intermediary between the user and multiple target services, establishing a super-session that mediates between the user's unified interface requirement and the individual session monitoring requirement. The intermediary correlates actions across sessions and provides a unified user experience while maintaining separate monitoring capabilities for each target service session.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate credentials are provided for each target service, then access control is precise, but the authentication process becomes complex and time-consuming

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The session manager performs preliminary authentication by obtaining credentials from a privileged account management system before establishing sessions with target services. Instead of requiring users to provide credentials for each service, the system pre-authenticates and retrieves appropriate credentials in advance, then uses these pre-obtained credentials to establish multiple sessions automatically. This resolves the contradiction by performing authentication ahead of time, reducing user effort while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service authentication where the session manager automatically retrieves and manages credentials without requiring user intervention for each target service. The privileged account management system automatically provides appropriate credentials to the session manager, which then uses them to establish sessions with target services, eliminating the need for users to manually provide credentials for each service while maintaining precise access control.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If privileged credentials are stored for automatic session establishment, then user interaction is simplified, but credential security is compromised

Engineering Contradiction:
Improvesession establishment simplicityVSAvoidcredential exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The session manager serves as a secure intermediary that handles privileged credentials without exposing them to users or storing them in insecure locations. Instead of users storing or handling privileged credentials locally, the session manager retrieves credentials from a secure privileged account management system and uses them temporarily to establish sessions with target services. The credentials never reside in the user's environment, eliminating the security risk while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts privileged credentials from the user's control environment and stores them securely in a dedicated privileged account management system. The session manager temporarily retrieves these credentials only when needed to establish sessions with target services, and the credentials are immediately discarded after use. This extraction of credentials from the user environment eliminates the security vulnerability of storing privileged credentials locally while maintaining the ability to automatically establish sessions when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9712514B2Super-session access to multiple target services
Publication Date: 2017.07.18 CYBER ARK SOFTWARE LTD
  • US9712514B2 patent drawing
  • US9712514B2 patent drawing
  • US9712514B2 patent drawing

AI summary

A method of establishing privileged communication sessions to target services unifies multiple sub-sessions into a single super-session. The user client requests access to target services. The request includes authentication credentials. Using the authentication credentials, privileged credentials are retrieved for target services requiring privileged access. Interactive sub-sessions are established between an intermediate element and respective target services. Required credentials are provided by the intermediate element to the target services. The interactive sub-sessions are unified into a single super-session on the intermediate element, and the super-session is established with the user client. The super-session provides the user client with interactive control of each of the interactive sub-sessions. Data communication between the user client and the target services is conducted via the intermediate element.