Credential-Free Access via Cloud Intermediary and Mobile Auth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges with managing multiple passwords for various online services, leading to security risks and the burden of remembering each login identifier and password, especially in enterprise contexts where frequent password changes are cumbersome.

Innovation Solution

A cloud-based credential management system that allows secure, credential-free access to resources by using a mobile device for authentication, eliminating the need for users to remember or provide passwords through a zero password login (ZPL) mechanism, which includes registration of authentication information, selection of security policies, and multi-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users utilize the same password or code for every service, then it is easier to remember login credentials, but security risk increases

Engineering Contradiction:
Improveease of remembering credentialsVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud-based credential management system that acts as an intermediary between users and multiple services. The system stores credentials securely in the cloud and automatically retrieves them when needed, eliminating the need for users to remember multiple passwords while maintaining security through centralized management and encrypted storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically handling credential retrieval and population without user intervention. The credential management system autonomously fills login forms and manages authentication across multiple services, freeing users from the burden of remembering credentials while maintaining security protocols.

Inventive Principle:
Principle #25Self-service

2Reliability

If users use different login identifiers and passwords for each online account, then security risk is reduced, but the burden of remembering each credential increases

Engineering Contradiction:
ImprovesecurityVSAvoidburden of remembering credentials
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud-based credential management system serves as an intermediary that handles the complexity of multiple unique credentials. It securely stores and manages distinct login identifiers and passwords for each service while providing users with a single point of access, thereby maintaining security through credential differentiation while eliminating the memory burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The credential management system provides universal access across multiple services through a single interface. It manages diverse credentials for different online accounts uniformly, allowing users to access various services without needing to remember each specific credential set, thus achieving both security through differentiation and ease of use through universality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If passwords are regularly modified for security, then security risk is reduced, but operational burden increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The credential management system performs password modification automatically without requiring user action. When security updates or expiration occurs, the system self-manages the credential rotation process, maintaining enhanced security through regular password changes while eliminating the operational burden from users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively managing password updates before they become due. It anticipates security requirements and automatically refreshes credentials in advance, ensuring continuous security enhancement without requiring users to initiate or remember password change schedules.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If a cloud-based credential management system is implemented, then security is enhanced by not storing credentials on access system, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based credential management system that acts as an intermediary between users and multiple services. The system stores credentials securely in the cloud and automatically retrieves them when needed, eliminating the need for users to remember multiple passwords while maintaining security through centralized management and encrypted storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10515232B2Techniques for facilitating secure, credential-free user access to resources
Publication Date: 2019.12.24 THYCOTIC SOFTWARE LLC
  • US10515232B2 patent drawing
  • US10515232B2 patent drawing
  • US10515232B2 patent drawing

AI summary

Techniques are disclose herein for facilitating secure user access to resources without user-provided credentials. More specifically, the techniques described herein eliminate the need for end users to remember and provide privileged resource authentication information (e.g., credentials) at the time of resource access. The system accepts and securely stores registration information for accessing privileged resources during a registration process. As discussed herein, the registration information can include identification and authentication information for each privileged resource. The authentication process can also include registration of one or more secondary authentication devices that are used to verify the identity of the end user in lieu of the end user providing credentials.