IP Library Granted Patent US 8,631,477
Granted Patent B2
US 8,631,477 · App. 12/508,102 · Granted Jan 14, 2014

Lifecycle management of privilege sharing using an identity management system

Inventors: Leanne L. Chen (Laguna Niguel, CA); Alexander P. Ames (Irvine, CA); Prema Vivekanandan (Kansas City, MO)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,631,477
App. No.
12/508,102
Granted
Jan 14, 2014
Kind
B2
Abstract

Managing a lifecycle of a shared privileged account via a proxy service which comprises an Identity Management (IdM) system that defines and manages identity services, which in turn manage privileged accounts used to access managed targets. Each of the identity services is mapped to a privilege group of the proxy service and an ID pool manager is implemented to manage sharing of the privileged accounts. A request is generated to access a managed target with a privileged account. A shared privileges module generates a shared ID authorization account and associates it with the requestor. The shared ID authorization account is populated with sign out information for a shared privileged account, which the requestor uses to access the corresponding managed target. When use of the shared privileged account is ended, the shared privileges module disassociates the requestor with the shared privileged account by deleting the shared ID authorization account.

Claims (58)

1. A system comprising:

a processor;

a data bus coupled to the processor; and

a computer-usable medium embodying computer program code, the computer-usable medium being coupled to the data bus, the computer program code providing lifecycle management of privilege sharing and comprising instructions executable by the processor and configured for:

providing a proxy service to a plurality of identity services, each identity service being defined in an identity management system and managing a plurality of privileged accounts;

defining a filter to specify the identity services whose privileged accounts will be hosted by the proxy service;

assigning a group of the proxy service to a shared ID authorization account, the assigning to the respective account being managed by an identification (ID) pool manager; and

sharing the use of the privileged account with the shared ID authorization account;

wherein the lifecycle of a shared privileged account is managed by performing:

an account access authorization request operation in response to a shared privileged account being received by the proxy service, wherein the access request operation obtains approval of access;

an account sign-out operation in response to a shared ID authorization account request being received by the proxy service, wherein the account sign-out operation:

generates a shared ID authorization account record comprising the shared usage relationship of the shared ID authorization account and the requestor and account sign-out information;

associates the shared ID authorization account with the requestor;

generates a new password for use of the shared ID authorization account by the requestor; and

an account sign-in operation upon expiration of the shared ID authorization account or its end of use by the requestor, wherein the account sign-in operation:

disassociates the shared privileged account from the requestor;

disables the use of the new password with the shared privileged account;

updates the shared ID authorization account record with account sign-in information; and

an authorization removal operation deleting the shared ID authorization account when access to the system is no longer needed.

2. The system of claim 1 , further comprising:

mapping respective systems and applications to the group, wherein the shared privileged account is used by the group to access the respective systems and applications.

3. The system of claim 1 , further comprising managing the lifecycle of the shared privileged account.

4. The system of claim 3 , further comprising deleting the Shared ID authorization account and its associated access to the respective systems and applications.

5. The system of claim 1 , wherein the password of the privileged account is automatically reset upon deletion of the shared ID authorization account.

6. The system of claim 1 , wherein recertification and requested use justification operations related to the requestor are performed to recertify the requestor and justify the use of the privileged account by the requestor.

7. The system of claim 1 , wherein: the account sign-out information comprises a starting date and a starting time for the requestor to begin use of the shared privileged account; and

the account sign-in information comprises an ending date and an ending time for the requestor to end use of the shared privileged account.

8. The system of claim 7 , wherein the account sign-out and sign-in information is used to generate shared privileged account usage reports and associated audit trail information related to shared privileged account lifecycle events.

9. The system of claim 1 , wherein each group comprises a predetermined privilege and contains a pool of privileged accounts managed by the pool manager through a pluggable interface.

10. A non-transitory computer-usable medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

providing a proxy service to a plurality of identity services, each identity service being defined in an identity management system and managing a plurality of privileged accounts;

defining a filter to specify the identity services whose privileged accounts will be hosted by the proxy service;

assigning a group of the proxy service to a shared ID authorization account, the assigning to the respective account being managed by an identification (ID) pool manager; and

sharing the use of the privileged account with the shared ID authorization account;

wherein the lifecycle of a shared privileged account is managed by the shared privileges module performing:

an account access authorization request operation in response to a shared privileged account being received by the proxy service, wherein the access request operation obtains approval of access;

an account sign-out operation in response to a shared ID authorization account request being received by the proxy service, wherein the account sign-out operation:

generates a shared ID authorization account record comprising the shared usage relationship of the shared ID authorization account and the requestor and account sign-out information;

associates the shared ID authorization account with the requestor;

generates a new password for use of the shared privileged account by the requestor; and

an account sign-in operation upon expiration of the shared ID authorization account or its end of use by the requestor, wherein the account sign-in operation:

disassociates the shared privileged account from the requestor;

disables the use of the new password with the shared privileged account;

updates the shared ID authorization account record with account sign-in information; and

an authorization removal operation deleting the shared ID authorization account when access to the system is no longer needed.

11. The non-transitory computer usable medium of claim 10 , further comprising:

mapping respective systems and applications to the group, wherein the shared privileged account is used by the group to access the respective systems and applications.

12. The non-transitory computer usable medium of claim 10 , further comprising managing the lifecycle of the shared privileged account.

13. The non-transitory computer usable medium of claim 12 , further comprising deleting the privileged account and its associated access to the respective systems and applications.

14. The non-transitory computer usable medium of claim 10 , wherein the password of the privileged account is automatically reset upon deletion of the shared ID authorization account.

15. The non-transitory computer usable medium of claim 10 , wherein recertification and requested use justification operations related to the requestor are performed to recertify the requestor and justify the use of the privileged account by the requestor.

16. The non-transitory computer usable medium of claim 10 , wherein:

the account sign-out information comprises a starting date and a starting time for the requestor to begin use of the shared privileged account; and

the account sign-in information comprises an ending date and an ending time for the requestor to end use of the shared privileged account.

17. The non-transitory computer usable medium of claim 16 , wherein the account sign-out and sign-in information is used to generate shared privileged account usage reports and associated audit trail information related to shared privileged account lifecycle events.

18. The non-transitory computer usable medium of claim 10 , wherein each group comprises a predetermined privilege and contains a pool of privileged accounts managed by the pool manager through a pluggable interface.

19. The non-transitory computer usable medium of claim 10 , wherein the computer executable instructions are deployable to a client computer from a server at a remote location.

20. The non-transitory computer usable medium of claim 10 , wherein the computer executable instructions are provided by a service provider to a customer on an on-demand basis.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE SECOND ASSIGNOR'S NAME PREVIOUSLY RECORDED AT REEL: 022997 FRAME: 0601. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 11, 2018
From: CHEN, LEANNE L.; AMIES, ALEXANDER P.; VIVEKANANDAN, PREMA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047831/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2009
From: CHEN, LEANNE L.; AMES, ALEXANDER P.; VIVEKANANDAN, PREMA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 022997/0601 →
Continuity (1)
Related Publication 20110023107A1 · Jan 27, 2011