Credential Delivery Application for Shared Account Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional operating system logon sessions require new authentication for each user in a shared environment, leading to sub-optimal wait times and security issues in time-sensitive locations, and make it difficult to maintain accountability and prevent unauthorized access.

Innovation Solution

A credential delivery application manages permission-based access by using a shared account with a default user profile, allowing rapid switching between users without requiring a new logon session, and altering the locking mechanism to restrict access while maintaining security and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new operating system logon session is generated for each user, then security and accountability are maintained, but user wait time increases and productivity decreases

Engineering Contradiction:
Improvesecurity and accountabilityVSAvoiduser wait time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the authentication process into two independent layers: (1) operating system level using a shared service account, and (2) application level using individual user credentials. This allows the OS session to be reused while maintaining user-specific security boundaries at the application layer, thus reducing wait time without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential storage mechanism that holds multiple user credential sets. When a user accesses the system, their credentials are retrieved from this intermediary storage and used to establish application-level authentication, eliminating the need to restart the entire OS logon session while maintaining security accountability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a shared account is used for multiple users, then user wait time is reduced, but security and unauthorized access prevention deteriorate

Engineering Contradiction:
Improveuser access speedVSAvoidsecurity and unauthorized access prevention
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides authentication into OS-level (shared account) and application-level (individual credentials). The shared account provides fast access to the OS, while individual user credentials stored in secure credential sets maintain security boundaries at the application level, preventing unauthorized access even though the OS session is shared.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different layers of the system. The OS layer uses a shared account with basic access controls, while the application layer uses user-specific credentials with individual permission levels. This local differentiation of security qualities allows fast access while maintaining appropriate security for each user.

Inventive Principle:
Principle #3Local quality

3Productivity

If rapid user switching is implemented, then productivity improves, but maintaining user privacy and application security becomes difficult

Engineering Contradiction:
Improveuser switching speedVSAvoiduser privacy and application security
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary credential delivery application that manages user credentials securely. This intermediary retrieves stored credential sets for authenticated users and delivers them to applications without exposing the underlying shared OS session, thus enabling rapid user switching while protecting user privacy and application security through controlled credential delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7562226B2System and method for permission-based access using a shared account
Publication Date: 2009.07.14 CITRIX SYSTEMS INC
  • US7562226B2 patent drawing
  • US7562226B2 patent drawing
  • US7562226B2 patent drawing

AI summary

A mechanism for rapidly authenticating an interactive user in an operating system logon session based on a shared account by using a credential delivery application to enable permission-based access to a user's remote session from the shared account is disclosed. The present invention provides the ability to switch local interactive users, authenticate the new interactive user, and switch the remote session without requiring the client to first establish a new logon session tied to the new local interactive user. The present invention also alters the normal locking mechanism found in operating system logon sessions so as to restrict access to an interactive local user's applications (both local and remote) while still allowing the rapid switching of interactive users at the client device.