Automatic Account Management System for Credential Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small and medium-sized enterprises face challenges in adopting automatic account management systems due to high implementation costs and usability issues, which are exacerbated by the risk of cybersecurity threats from hacked privileged accounts.

Innovation Solution

An automatic account management system with a storage unit and processing unit that includes modules for credential modification, remote login, and account verification, allowing for secure and efficient management of accounts and credentials across a network environment, with features like credential splitting and synchronization to ensure availability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If large enterprises adopt automatic account management systems, then account security and management efficiency are improved, but implementation cost and system complexity increase significantly

Engineering Contradiction:
Improveaccount securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automatic credential management where the account management system autonomously generates, distributes, rotates, and revokes credentials without requiring manual administrative intervention. This self-service mechanism reduces operational complexity while maintaining high security standards through automated workflows that execute credential lifecycle management tasks based on predefined policies and triggers.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary account management system that sits between human users and the target systems, managing credentials as a separate layer. This intermediary layer handles sensitive credential operations (generation, rotation, revocation) and mediates access requests, thereby reducing the complexity burden on both enterprises and users while centralizing security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automatic account management systems are implemented, then credential management efficiency is improved, but implementation cost increases

Engineering Contradiction:
Improvecredential management efficiencyVSAvoidimplementation cost
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The account management system is designed as a universal platform that can manage credentials across multiple systems, applications, and devices through standardized interfaces. This multi-functionality allows small and medium-sized enterprises to implement a single system that serves diverse credential management needs, reducing overall implementation cost compared to deploying separate solutions for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows flexible configuration of credential parameters such as rotation frequency, validity periods, and access policies that can be adjusted based on enterprise size and requirements. This parameter flexibility enables organizations to optimize security measures according to their specific needs and budget constraints, making the system economically viable for smaller enterprises.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If privileged accounts are widely used for system management, then operational flexibility is improved, but cybersecurity risk increases

Engineering Contradiction:
Improveoperational flexibilityVSAvoidcybersecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments privileged access by creating temporary, purpose-specific credentials with limited scopes and durations rather than using broad, long-lived administrative accounts. Credentials are divided into fine-grained permissions that match specific operational needs, reducing the attack surface while maintaining operational flexibility through role-based and task-based access segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements periodic credential rotation where credentials are automatically renewed or revoked at predetermined intervals. This periodic action ensures that even if credentials are compromised, the window of opportunity for attackers is limited by the rotation schedule, thereby reducing cybersecurity risk while maintaining continuous operational flexibility through automated reissuance.

Inventive Principle:
Principle #19Periodic action

4Ease of manufacture

If manual credential management is used, then implementation cost is reduced, but usability and security deteriorate

Engineering Contradiction:
Improveimplementation costVSAvoidusability
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The system provides self-service capabilities where users can autonomously request, receive, and manage their own credentials through automated workflows. This eliminates the need for manual credential distribution while maintaining ease of operation, as users can obtain credentials on-demand without administrative intervention, improving usability without significantly increasing implementation cost.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system automatically generates and distributes credential copies to authorized users based on predefined access policies. Instead of manually creating and distributing unique credentials, the system automates the copying and allocation process, maintaining security through centralized control while improving usability through automated delivery and reducing manual administrative burden.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240205230A1Automatic account management system
Publication Date: 2024.06.20 GLOBAL WISDOM SOFTWARE TECH CO LTD
  • US20240205230A1 patent drawing
  • US20240205230A1 patent drawing
  • US20240205230A1 patent drawing

AI summary

An automatic account management system includes a storage unit and a processing unit. The storage unit stores personnel information and device information. The personnel information corresponds to an authorized person and includes their identification name and contact details, while the device information corresponds to a managed device and includes multiple accounts and credentials for login. The processing unit includes a credential modification module, a remote login module, and an account verification module. The credential modification module is adapted to modify one of the credentials through a credential modification algorithm, and the modified credential is then stored in the storage unit and updated to the managed device through the remote login module. The account verification module, referencing the identification name and contact details, contacts the authorized person through an electronic process for verifying validities of these accounts.