최소 단어 이상 선택하여야 합니다.
최대 10 단어까지만 선택 가능합니다.
다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
NTIS 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
DataON 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
Edison 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
Kafe 바로가기국가/구분 | United States(US) Patent 등록 |
---|---|
국제특허분류(IPC7판) |
|
출원번호 | US-0680400 (2003-10-07) |
등록번호 | US-7376838 (2008-05-20) |
발명자 / 주소 |
|
출원인 / 주소 |
|
대리인 / 주소 |
|
인용정보 | 피인용 횟수 : 18 인용 특허 : 495 |
A method that provides access to Privileged Accounts to users with Privileged Account access permission. A message is sent to a Privileged Accounts manager when a user logs into a Privileged Account. The user must enter a reason for access. All keystrokes are logged. At the conclusion of the user s
A method that provides access to Privileged Accounts to users with Privileged Account access permission. A message is sent to a Privileged Accounts manager when a user logs into a Privileged Account. The user must enter a reason for access. All keystrokes are logged. At the conclusion of the user session, the log file is closed and another message is sent to the Privileged Accounts manager. The log file may be sent to the manager at this time or saved for a batch transfer periodically.
What is claimed is: 1. A method for allowing a user to temporarily gain access to a privileged account on a computer system to perform a maintenance task, the method being a replacement for a conventional switch user command, comprising: receiving a switch user command login with a user id and an a
What is claimed is: 1. A method for allowing a user to temporarily gain access to a privileged account on a computer system to perform a maintenance task, the method being a replacement for a conventional switch user command, comprising: receiving a switch user command login with a user id and an account name as an argument; retrieving a list of privileged account names; determining whether the account name is in a list of privileged account names and diverting the user to the conventional switch user command prompt if the account name is not in the privileged account list; otherwise, determining whether the user id is in a list of user ids having permission to access privileged accounts and allowing access to the account if the user id is in the list of user ids having permission to access privileged accounts; prompting for a reason for accessing the account; recording a reason for accessing the account; notifying a manager of the privileged account of the login; recording keystrokes in a log file while logged into the account; terminating the login; and notifying the manager of the privileged account of the login termination. 2. A method for allowing a user to temporarily gain access to a privileged account on a computer system to perform a maintenance task, the method being a replacement for a conventional switch user command, comprising: receiving a switch user command login with a user id and an account name as an argument; retrieving a list of privileged account names; determining whether the account name is in a list of privileged account names and diverting the user to the conventional switch user command prompt if the account name is not in the privileged account list; otherwise, determining whether the user id belongs to a privileged group located in a group list on the computer system having permission to access privileged accounts; denying access to privileged accounts and notifying the manager if the user id does not belong to the privileged group, otherwise, allowing; prompting for a reason for accessing the account; recording a reason for accessing the account; notifying a manager by email of the access of the privileged account of the switch user login along with the name of a first log file; recording keystrokes in the first log file while logged into the account; recording keystrokes in a duplicate log file while logged into the account; determining whether the first log file was tampered with and if so recording that the first log file was tampered with in the duplicate log file and transmitting the duplicate log file to the manager; terminating the switch user login; and notifying the manager by email of the privileged account of the switch user login termination. 3. A method in accordance with claim 2 further comprising: denying write permission to the log file after the step of terminating the login. 4. A method in accordance with claim 2 further comprising: transmitting the log file to the account manager. 5. A method in accordance with claim 2 further comprising: receiving a password in order to access the privileged account; determining whether the password associated with the user id matches the entered password; and permitting access only if the password associated with the user id matches the entered password. 6. A method in accordance with claim 2 further comprising: notifying the manager of the privileged account if the login is not successful. 7. A method in accordance with claim 2 further comprising: compressing the log file after terminating the login. 8. A method in accordance with claim 2 further comprising: deleting the duplicate log file responsive to a determination that the log file has not been tampered with.
Copyright KISTI. All Rights Reserved.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.