Ticket Management Service for Dynamic Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network authentication systems, such as Kerberos, issue session tickets that remain valid for extended periods, leaving systems vulnerable to unauthorized access when users temporarily leave their devices, as these systems do not consider user presence or system state information for ticket management.
Innovation Solution
Implementing an information handling system with a ticket management service that receives user presence and system state information, compares it to policies in a ticket management policy database, and performs actions such as ticket revocation or power state control if the information is not compliant, ensuring secure access and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If session tickets are issued for extended periods to enable continuous access, then ease of operation is improved, but security is worsened as unauthorized access becomes possible when users leave their devices
Solution Approach 1:
The ticket management system dynamically adjusts ticket validity and access rights based on real-time user presence detection and system state monitoring, transitioning from static extended-period tickets to adaptive tickets that remain valid only when authorized users are present and the system is in a secure state
Solution Approach 2:
The system implements continuous feedback loops by monitoring user presence via sensors, evaluating system state through security checks, and adjusting ticket validity accordingly - when users are detected as absent or the system enters an insecure state, tickets are automatically revoked or invalidated
2Reliability
If tickets are revoked frequently to maintain security, then security is improved, but ease of operation is worsened as legitimate users may be locked out
Solution Approach 1:
The system performs self-verification by continuously monitoring its own security state and user presence, automatically making informed decisions about ticket validity without requiring external intervention or risking false revocations of legitimate access
Solution Approach 2:
The system performs preliminary security evaluations and user presence checks before revoking tickets, ensuring that revocation actions are taken only when genuinely necessary and not due to transient or resolvable conditions
Data Source
AI summary
Embodiments of information handling systems (IHSs) and methods are provided herein for managing tickets based on contextual information and ticket management policy. Although not strictly limited to such, the embodiments disclosed herein may be used to manage tickets, which are issued by a network authentication service and stored within a key store of an IHS. In one embodiment, tickets are managed by receiving user presence information and system state information, comparing the user presence information and system state information to policies contained within a ticket management policy database, and performing one or more actions specified in the policies if the user presence information or the system state information is not compliant with at least one of the policies. The one or more actions specified in the policies may include actions for managing the tickets stored within the key store and/or actions for controlling a power state of the IHS.


