Automated Credential Management via Remote Protocol Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise computer systems face challenges in automating account and credential management across numerous machines, requiring manual intervention for policy enforcement and updates, which is impractical due to the complexity and variability of machines and user accounts.

Innovation Solution

A method for managing authentication credentials and determining credential management protocols via remote connections, allowing for automated password generation and updates based on accessed credential parameters and password complexity rules, ensuring consistency with enterprise policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of accounts and credentials is implemented, then security control and policy enforcement can be achieved, but the complexity and time consumption increase significantly when managing large numbers of machines and user accounts

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service automation where the credential management system automatically discovers machines, identifies accounts, determines protocols, and updates credentials without requiring manual administrator intervention for each machine. The system serves itself by autonomously navigating the credential management process across the enterprise network.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The credential management system performs multiple functions including machine discovery, account identification, protocol determination, credential updating, and policy enforcement through a single automated process. This universal approach handles diverse machine types and account configurations without requiring separate manual procedures for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If automated credential management is implemented, then efficiency and scalability improve, but the system must handle diverse machine configurations and protocols which increases system complexity

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts its behavior based on discovered machine parameters and configurations. By changing operational parameters according to the specific machine type, account configuration, and protocol requirements encountered during automated credential updates, the system handles diversity without requiring hard-coded complexity for each scenario.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The automated system incorporates feedback mechanisms where the credential management process receives information about machine responses, protocol requirements, and account configurations, then uses this feedback to adapt its subsequent actions. This feedback loop enables the system to handle diverse configurations autonomously while maintaining efficiency.

Inventive Principle:
Principle #23Feedback

3Reliability

If frequent credential updates are performed to maintain security, then security posture improves, but the time and resources required for manual updates across numerous machines become unsustainable

Engineering Contradiction:
Improvesecurity postureVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The automated credential management system enables continuous credential updates across the enterprise network without interruption. By maintaining continuous operational capability to discover, authenticate, and update credentials on multiple machines simultaneously, the system sustains security posture improvements without the time loss associated with manual batch processing.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary actions by pre-discovering machines, pre-identifying accounts, and pre-determining protocols before credential updates are executed. This preliminary preparation enables rapid sequential credential updates across multiple machines, reducing the total time required for frequent security-mandated credential rotations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10162961B1Automated process of managing and controlling identities on a remote computer machine
Publication Date: 2018.12.25 CYBER ARK SOFTWARE LTD
  • US10162961B1 patent drawing
  • US10162961B1 patent drawing
  • US10162961B1 patent drawing

AI summary

The disclosed embodiments include systems and methods for managing an authentication credential of an account of a machine of a computer system via a remote connection with the machine. A method includes accessing in the computer system, at least one credential parameter for an authentication process for the account of the machine, the at least one credential parameter being included in an authentication file associated with the computer system. The method also includes determining a password complexity rule for the account based at least on the at least one accessed credential parameter, thereby enabling automatic generation of a password consistent with the determined password complexity rule for a user associated with the account of the machine, and determining a credential management protocol, based on interaction with the machine via the remote network connection, thereby enabling updating a password for the account at the machine based on the automatically generated password.