Authenticator Information Management in Computer Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing authenticator information across large computing environments is challenging due to disparate storage locations and lack of complete awareness of authenticators, leading to issues with outdated keys and access management.

Innovation Solution

A method and apparatus for managing authenticator information that involves analyzing access requests, searching both an authenticator management host and a local directory for information, and modifying the information accordingly, with the ability to grant or reject access based on the search results and receiving control instructions from the authenticator management host.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authenticator information is stored locally in hosts and directories, then access management is flexible and distributed, but complete awareness and control of authenticators becomes difficult and outdated keys may remain in use

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidawareness of authenticators
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent combines distributed local authenticator storage with centralized management by having hosts search both their local directories and the authenticator management host. This merging approach maintains the flexibility of distributed storage while achieving centralized awareness and control, resolving the contradiction between local flexibility and global visibility.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where hosts report found authenticators to the authenticator management host, which then provides control instructions back to hosts. This feedback loop ensures complete awareness of authenticators across the system while maintaining proper access control, addressing the issue of outdated keys remaining in use.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple storage locations are used for authenticators, then access flexibility is improved, but management complexity increases

Engineering Contradiction:
Improveaccess flexibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments authenticator management into two parts: local storage on hosts for flexible access, and centralized management on the authenticator management host for coordinated control. This segmentation allows the system to maintain access flexibility while reducing management complexity through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authenticator management host acts as an intermediary between multiple hosts and their local directories. It coordinates authenticator information across the system, providing a simplified management interface that reduces complexity while maintaining the benefits of multiple storage locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized management of authenticators is implemented, then control and security are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authenticator management host serves multiple functions: storing authenticator information, receiving search requests from hosts, providing control instructions, and maintaining system-wide awareness. This multi-functionality consolidates management capabilities into a single system component, improving security control while minimizing the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3361764B1Management of authenticator information in a computer system
Publication Date: 2020.10.21 SSH COMMUNICATIONS SECURITY
  • EP3361764B1 patent drawingFigure 1
  • EP3361764B1 patent drawingFigure 2~3
  • EP3361764B1 patent drawingFigure 4~9

AI summary

The disclosure relates to apparatuses and methods for managing authenticator information in a computerized system. An access request to a host comprising an authenticator is processed to cause searching in an authenticator management host for information corresponding to the authenticator and searching in a directory internal to the host for information corresponding to the authenticator. Modification of information corresponding to the authenticator can then be provided based on the searching.