Break Glass Credential Synchronization for Disconnected Remote Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial automation systems, remote devices disconnected from their host network cannot access directory services, preventing technicians from reviewing diagnostics and event history, and requiring manual, time-consuming processes for resetting user credentials.

Innovation Solution

The method involves remote devices accessing a break glass synchronization account before disconnection, storing break glass user credentials, and allowing access to protected information upon successful comparison with user-entered credentials after reconnection, with periodic updates to credentials if usage limits are exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote devices check credentials with a central directory service when connected, then security is maintained, but access is denied when disconnected from the network

Engineering Contradiction:
Improveaccess reliabilityVSAvoidlogin accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by caching break glass user credentials on the remote device before network disconnection occurs. This allows the device to authenticate users locally using stored credentials when disconnected, eliminating the need for real-time directory service access while maintaining security through pre-established credential validation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a break glass user account as an intermediary credential store on the remote device. This intermediary allows authentication to proceed locally without direct connection to the central directory service, acting as a mediator between the user login attempt and the authentication decision when network access is unavailable

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual credential resetting is performed when disconnected, then security can be restored, but significant time and resources are required

Engineering Contradiction:
Improvesecurity restorationVSAvoidcredential reset time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by enabling the remote device to automatically reset break glass user credentials without requiring manual intervention from technicians. When the device reconnects to the network, it autonomously retrieves updated credentials from the directory service and replaces expired or compromised credentials, eliminating time-consuming manual reset procedures

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback mechanism where the remote device monitors its connection status and automatically initiates credential updates upon network reconnection. This feedback loop ensures credentials remain current and secure without requiring manual tracking or intervention, as the system self-corrects based on its own operational state

Inventive Principle:
Principle #23Feedback

3Ease of operation

If break glass credentials are stored on remote devices, then access is enabled during disconnection, but security risk increases if credentials are compromised

Engineering Contradiction:
Improveaccess availabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies dynamics by making break glass credentials temporary and automatically rotating them. Credentials are cached on remote devices for a limited duration or usage count, then automatically updated when the device reconnects to the network. This dynamic credential rotation minimizes the window of vulnerability if credentials are compromised, as they expire and are replaced automatically

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements discarding and recovering by automatically invalidating and replacing break glass credentials on remote devices. When credentials are used beyond a permitted count or after a time threshold, they are discarded and new credentials are recovered from the directory service during the next network connection, ensuring compromised credentials are promptly replaced

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS20250150447A1Systems and methods to distribute, synchronize and reset emergency break glass user credentials for remote devices
Publication Date: 2025.05.08 SCHNEIDER ELECTRIC (AUSTRALIA) PTY LTD
  • US20250150447A1 patent drawing
  • US20250150447A1 patent drawing
  • US20250150447A1 patent drawing

AI summary

A method to access a disconnected remote device is provided. The method includes, prior to being disconnected from a network, the remote device accessing a break glass synchronization (sync) account stored by a directory server, reading break glass user credentials stored in association with the break glass sync account, the break glass user credentials including a secure password mechanism, and storing the break glass user credentials defined for the remote device on the remote device. The method further includes, after being disconnected from the network, the remote device receiving login credentials by a user attempting to log in to the remote device, including a user-entered secure password mechanism, comparing the login credentials to the break glass user credentials, and allowing access to the protected information stored by or functionality provided by the remote device based on a result of the comparison.