Collaborative Password Management with Segmented Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password management software is designed for single users and does not facilitate secure sharing of credentials between multiple users, posing security risks when team members need to access shared accounts.

Innovation Solution

A collaborative security management system that allows multiple users to access and manage secured information through a processing device and memory device, with defined security rules for access privileges and operations, enabling secure sharing and management of sensitive data like login credentials and cryptographic keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password management software is used for single user, then security is maintained, but credential sharing between multiple users becomes impossible

Engineering Contradiction:
ImprovesecurityVSAvoidcredential sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the single user account into multiple user identities within the password management system. Each user has their own credentials and access permissions, allowing secure multi-user operation without compromising security. The system divides the credential storage and access control into separate user-specific segments while maintaining centralized management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of user management by adding user profiles and access control layers to the traditional single-user password manager. This dimensional expansion allows the system to handle multiple users with different permission levels, transforming the system from 2D (single user, credentials) to 3D (multiple users, credentials, permission levels).

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple users share one account in password management software, then credential sharing is enabled, but confidentiality and security are compromised

Engineering Contradiction:
Improvecredential sharing capabilityVSAvoidconfidentiality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by assigning different access permissions and confidentiality levels to different users. Each user has specific credentials they can access based on their role and needs, rather than having universal access to all credentials. This localized access control ensures that users can only view or modify credentials relevant to their responsibilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary access control mechanism that mediates between multiple users and the credential storage. This intermediary layer verifies user identities, enforces permission policies, and controls access to credentials, preventing direct unauthorized access while enabling legitimate sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If manual credential sharing between team members is performed, then sharing is achieved, but security and efficiency are reduced

Engineering Contradiction:
Improvecredential sharing capabilityVSAvoidsharing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent enables self-service credential sharing through automated authentication and permission management. Users can independently access shared credentials through the password management system without requiring manual intervention from credential owners or IT administrators. The system automatically handles authentication, authorization, and credential distribution.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring user profiles, access permissions, and credential associations before sharing is needed. The system establishes the framework for secure sharing in advance, so when users need to access credentials, the authentication and authorization processes are already in place, eliminating manual setup steps.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If multiple users access all credentials in one account, then complete access is granted, but security and confidentiality are lost

Engineering Contradiction:
Improveaccess simplicityVSAvoidconfidentiality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by implementing user-specific access scopes. Each user has a customized view of credentials based on their permissions, showing only the credentials they are authorized to access. This creates localized access experiences for different users while maintaining centralized security management.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamic access control where user permissions can be adjusted based on their roles, needs, and security requirements. The system dynamically determines which credentials each user can access, rather than using static all-or-nothing access rules. This dynamic approach maintains simplicity for authorized users while protecting confidential credentials.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250023869A1System and method for collaborative password management
Publication Date: 2025.01.16 THE TRAVELERS INDEMNITY
  • US20250023869A1 patent drawing
  • US20250023869A1 patent drawing
  • US20250023869A1 patent drawing

AI summary

A collaborative security management system and methods are presented. The system includes a processor communicating with two or more user devices and memory communicating with the processor. The memory stores instructions that when executed result in the processor storing two or more data structures in memory. Each data structure includes secured information. The processor establishes at least one safe associated with the data structures and defines security rules for the safe. Each rule governs one of an access and an operations privilege. The access privilege grants or denies access to the safe by the user devices via an interface. The operations privilege enables or disables performance of operations upon the safe initiated by the user device from the interface. The processor controls, by the security rules, at least one of access to and operations performed upon the safes and data structures associated therewith by the user devices.