Authentication Information Management System for Automatic Credential Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication systems are vulnerable if terminal authentication information is leaked, as they require manual changes by administrators or users, which can lead to a prolonged system vulnerability.

Innovation Solution

An authentication information management system that automatically changes first authentication information based on stored correspondence information and second authentication information, allowing for secure and timely updates upon request, independent of the application's authentication method.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual change of authentication information by system administrator or user is used, then the system can respond to authentication information leakage, but the response time is prolonged and system vulnerability persists

Engineering Contradiction:
Improvesecurity response capabilityVSAvoidtime to change authentication information
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically changing the first authentication information as soon as leakage is detected, before manual intervention can occur. The management server is pre-configured to execute the change without waiting for administrator or user action, thus eliminating the time delay inherent in manual processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by enabling automatic detection and response to authentication information leakage without requiring manual intervention. The management server autonomously identifies leakage conditions and executes the change of first authentication information, making the system self-protecting rather than relying on external human action.

Inventive Principle:
Principle #25Self-service

2Reliability

If multiple authentication methods are managed in association, then authentication strength is increased, but system complexity increases

Engineering Contradiction:
Improveauthentication strengthVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct components: first authentication information for application access, second authentication information for leakage detection, and a management server for coordination. This segmentation allows each component to have a specific function, simplifying the overall system architecture while maintaining multiple authentication methods.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management server acts as an intermediary that coordinates between the first and second authentication methods. It receives leakage detection results from the second authentication and automatically manages the change of first authentication information, thereby simplifying the complexity of managing multiple authentication methods by centralizing control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8863254B2Authentication information management of associated first and second authentication information for user authentication
Publication Date: 2014.10.14 FUJITSU LTD
  • US8863254B2 patent drawing
  • US8863254B2 patent drawing
  • US8863254B2 patent drawing

AI summary

An authentication information management program of an authentication information management apparatus allowing the authentication information management apparatus to execute: changing the first authentication information in correspondence information which is information including the first authentication information and second authentication information in association with each other and stored in a storage section of the authentication information management apparatus; transmitting the authentication apparatus of the changed first authentication information; determining, in response to a request from the apparatus to be authenticated, whether the second authentication information in the authentication request coincides with the second authentication information in the correspondence information; and returning, in the case where it is determined that the second authentication information in the authentication request coincides with the second authentication information in the correspondence information, the first authentication information associated with the second authentication information read from the storage section.