Ticket Management Service for Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication systems, such as Kerberos, issue session tickets that remain valid for extended periods, leaving systems vulnerable to unauthorized access when users temporarily leave their devices, as these systems do not consider user presence or system state information for ticket management.

Innovation Solution

Implementing an information handling system with a ticket management service that receives user presence and system state information, compares it to policies in a ticket management policy database, and performs actions such as ticket revocation or power state control if the information is not compliant, ensuring secure access and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If session tickets are issued for extended periods to enable continuous access, then ease of operation is improved, but security is worsened as unauthorized access becomes possible when users leave their devices

Engineering Contradiction:
Improvecontinuous accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The ticket management system dynamically adjusts ticket validity and access rights based on real-time user presence detection and system state monitoring, transitioning from static extended-period tickets to adaptive tickets that remain valid only when authorized users are present and the system is in a secure state

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous feedback loops by monitoring user presence via sensors, evaluating system state through security checks, and adjusting ticket validity accordingly - when users are detected as absent or the system enters an insecure state, tickets are automatically revoked or invalidated

Inventive Principle:
Principle #23Feedback

2Reliability

If tickets are revoked frequently to maintain security, then security is improved, but ease of operation is worsened as legitimate users may be locked out

Engineering Contradiction:
ImprovesecurityVSAvoidaccess continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-verification by continuously monitoring its own security state and user presence, automatically making informed decisions about ticket validity without requiring external intervention or risking false revocations of legitimate access

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary security evaluations and user presence checks before revoking tickets, ensuring that revocation actions are taken only when genuinely necessary and not due to transient or resolvable conditions

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11575664B2Information handling systems and methods to manage tickets based on user presence, system state and ticket management policy
Publication Date: 2023.02.07 DELL PROD LP
  • US11575664B2 patent drawing
  • US11575664B2 patent drawing
  • US11575664B2 patent drawing

AI summary

Embodiments of information handling systems (IHSs) and methods are provided herein for managing tickets based on contextual information and ticket management policy. Although not strictly limited to such, the embodiments disclosed herein may be used to manage tickets, which are issued by a network authentication service and stored within a key store of an IHS. In one embodiment, tickets are managed by receiving user presence information and system state information, comparing the user presence information and system state information to policies contained within a ticket management policy database, and performing one or more actions specified in the policies if the user presence information or the system state information is not compliant with at least one of the policies. The one or more actions specified in the policies may include actions for managing the tickets stored within the key store and/or actions for controlling a power state of the IHS.