Client Application Password Mapping for Secure Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password-based secure network access systems face inefficiencies and security risks when authorized users share passwords with non-authorized parties, leading to compromised confidentiality, uncontrolled access, and administrative complexities, especially in providing differentiated access levels to large numbers of users across diverse jurisdictions.

Innovation Solution

A client application maps a child password to a parent password, allowing child users to access secure network resources without revealing the child password to the server, with expiration events, secondary password elements, and access rule monitoring to manage and limit access, thereby maintaining security and administrative efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an authorized user provides their password to a non-authorized third party to enable access to secure resources, then the third party can login and access the secure resource, but the confidentiality of the password is destroyed and cannot be recovered

Engineering Contradiction:
Improveaccess provision to third partyVSAvoidpassword confidentiality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The parent password is segmented into multiple child passwords, each with limited access rights. The authorized user can provide individual child passwords to third parties without exposing the main parent password, thus maintaining confidentiality while enabling controlled access to specific secure resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different child passwords are created with different access permissions and scopes. Each child password has localized access rights to specific resources or time periods, allowing the authorized user to grant precise control to third parties without compromising overall security or the parent password's confidentiality.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If an authorized user provides their password to a non-authorized third party, then the third party can access secure resources, but the authorized user loses the ability to monitor or control the extent of access granted

Engineering Contradiction:
Improvethird party accessVSAvoidaccess control monitoring
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Access control parameters such as expiration dates, resource limitations, and usage restrictions are predetermined and embedded in each child password before it is provided to the third party. This preliminary configuration enables automatic monitoring and control of access without requiring continuous administrative intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback mechanisms that allow the authorized user to monitor third-party access through logs and usage reports. The system tracks when child passwords are used, what resources are accessed, and automatically enforces access limitations, providing visibility and control over third-party activities.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the secure resource provider system configures differentiated access levels for different users at the server level, then different users can have different security permissions, but the administrative complexity and costs increase greatly

Engineering Contradiction:
Improvedifferentiated access levelsVSAvoidserver administration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a new dimension of password hierarchy by creating child passwords under a parent password. This dimensional change allows differentiated access control to be implemented at the client application level rather than requiring complex server-level configuration for each user permission scenario.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The client application acts as an intermediary between the user and the secure server. It manages the child passwords and their associated access controls locally, eliminating the need for the server to handle complex differentiated permission configurations. The intermediary handles access control logic before requests reach the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7996885B2Password application
Publication Date: 2011.08.09 KYNDRYL INC
  • US7996885B2 patent drawing
  • US7996885B2 patent drawing

AI summary

Methods, systems, and program products for a client application provide child passwords mapped to a parent password authorized for login to a secure network resource server. A child user logs in to the client application by entering the child password. When a child user properly requests a secure resource from the secure network resource server, the client application uses the authorized parent password to login to the secure server and retrieve a secure resource without communicating the child password to the secure server. The child user login session is administered by the local application pursuant to access rules or limitation parameters associated with the child password. Child passwords may be set to expire. The client application may also monitor secure server access by a child user; monitored use may also be reported, and an access rule or password limitation parameter may be revised in response to monitoring and use reporting.