Credential Auditing via Hash Comparison for Policy Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security administrators face difficulties in demonstrating compliance of user and administrator chosen passwords with configured password policies, as existing password management systems lack a mechanism for analyzing and reporting compliance with current and previous credentials.
Innovation Solution
A credential auditing method that inspects a principal's credential history within a secure environment, generates a report indicating compliance with a policy, and masks sensitive information to ensure security, using hash values for comparison and maintaining secrecy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password management systems store and manage passwords with policies, then password security is improved, but the ability to audit and demonstrate compliance with policies deteriorates
Solution Approach 1:
The system segments password auditing into individual credential-level audits, examining each password's compliance with policy rules separately. This allows comprehensive security verification while providing granular audit reports that demonstrate compliance without exposing sensitive password data.
Solution Approach 2:
The patent introduces an intermediary auditing mechanism that sits between password storage and compliance verification. This intermediary layer analyzes password policies and credential histories to generate compliance reports without requiring direct access to or exposure of actual password values, thus maintaining security while enabling auditability.
2Reliability
If password policies are configured to enforce security rules, then credential security is improved, but the complexity of verifying and reporting compliance deteriorates
Solution Approach 1:
The auditing system performs self-service compliance verification by automatically evaluating stored credentials against configured password policies. The system autonomously generates compliance reports without requiring manual verification processes, reducing the complexity of compliance demonstration while maintaining rigorous security standards.
Solution Approach 2:
The system implements feedback mechanisms where audit results are automatically generated and reported based on credential evaluations. This feedback loop provides security administrators with clear compliance information without manual intervention, simplifying the verification process while ensuring continuous security policy adherence.
3Reliability
If credential histories are stored to prevent password reuse, then security is improved, but the difficulty of auditing compliance with password policies increases
Solution Approach 1:
The system creates copies of credential history data specifically for auditing purposes, separating the audit function from the security-critical credential storage. These audit copies enable comprehensive compliance analysis of password reuse prevention without compromising the security of actual credential data or requiring access to sensitive information.
Data Source
AI summary
Techniques for credential auditing are provided. Histories for credentials are evaluated against a principal credential policy for a user and an enterprise credential policy for an enterprise as a whole. An audit trail is produced within a report for the histories. The report indicates whether compliance with the principal and enterprise credential policies occurred and if not at least one reason is provided as to why compliance was not met within the histories.


