Break Glass Credential Synchronization for Disconnected Remote Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial automation systems, remote devices disconnected from their host network cannot access directory services, preventing technicians from reviewing diagnostics and event history, and requiring manual, time-consuming processes for resetting user credentials.
Innovation Solution
The method involves remote devices accessing a break glass synchronization account before disconnection, storing break glass user credentials, and allowing access to protected information upon successful comparison with user-entered credentials after reconnection, with periodic updates to credentials if usage limits are exceeded.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote devices check credentials with a central directory service when connected, then security is maintained, but access is denied when disconnected from the network
Solution Approach 1:
The system performs preliminary action by caching break glass user credentials on the remote device before network disconnection occurs. This allows the device to authenticate users locally using stored credentials when disconnected, eliminating the need for real-time directory service access while maintaining security through pre-established credential validation
Solution Approach 2:
The patent introduces a break glass user account as an intermediary credential store on the remote device. This intermediary allows authentication to proceed locally without direct connection to the central directory service, acting as a mediator between the user login attempt and the authentication decision when network access is unavailable
2Reliability
If manual credential resetting is performed when disconnected, then security can be restored, but significant time and resources are required
Solution Approach 1:
The system implements self-service by enabling the remote device to automatically reset break glass user credentials without requiring manual intervention from technicians. When the device reconnects to the network, it autonomously retrieves updated credentials from the directory service and replaces expired or compromised credentials, eliminating time-consuming manual reset procedures
Solution Approach 2:
The patent establishes a feedback mechanism where the remote device monitors its connection status and automatically initiates credential updates upon network reconnection. This feedback loop ensures credentials remain current and secure without requiring manual tracking or intervention, as the system self-corrects based on its own operational state
3Ease of operation
If break glass credentials are stored on remote devices, then access is enabled during disconnection, but security risk increases if credentials are compromised
Solution Approach 1:
The system applies dynamics by making break glass credentials temporary and automatically rotating them. Credentials are cached on remote devices for a limited duration or usage count, then automatically updated when the device reconnects to the network. This dynamic credential rotation minimizes the window of vulnerability if credentials are compromised, as they expire and are replaced automatically
Solution Approach 2:
The patent implements discarding and recovering by automatically invalidating and replacing break glass credentials on remote devices. When credentials are used beyond a permitted count or after a time threshold, they are discarded and new credentials are recovered from the directory service during the next network connection, ensuring compromised credentials are promptly replaced
Data Source
AI summary
A method to access a disconnected remote device is provided. The method includes, prior to being disconnected from a network, the remote device accessing a break glass synchronization (sync) account stored by a directory server, reading break glass user credentials stored in association with the break glass sync account, the break glass user credentials including a secure password mechanism, and storing the break glass user credentials defined for the remote device on the remote device. The method further includes, after being disconnected from the network, the remote device receiving login credentials by a user attempting to log in to the remote device, including a user-entered secure password mechanism, comparing the login credentials to the break glass user credentials, and allowing access to the protected information stored by or functionality provided by the remote device based on a result of the comparison.


