Secure Credential Installation for Video Conferencing via Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Video conferencing devices' authentication credentials are vulnerable to unauthorized access when local IT professionals can view them, and existing methods for remote installation are insecure, allowing potential misuse that jeopardizes the privacy and security of private networks.

Innovation Solution

A system and method that uses a client application downloaded onto an intermediary computing device to securely install Network Access Control (NAC) credentials on video conferencing devices without revealing the credentials to untrusted entities, utilizing a secure website, NAC credential service, and RADIUS server to validate and install device-specific credentials remotely, ensuring only trusted entities can access the private network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local IT professionals are allowed to view authentication credentials to install them on video conferencing devices, then the installation process becomes easier and more accessible, but security is compromised as untrusted entities may gain unauthorized access to the private network

Engineering Contradiction:
Improvecredential installation accessibilityVSAvoidunauthorized network access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary credential installation system that acts as a secure mediator between the credential distribution point and the video conferencing device. This intermediary system receives credentials securely, validates them, and installs them remotely without requiring local IT professionals to view or handle the actual credentials, thus maintaining security while enabling easy installation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service credential installation by allowing video conferencing devices to automatically receive and install credentials through the intermediary system without human intervention. The device can autonomously communicate with the intermediary system to obtain and configure credentials, eliminating the need for local IT professionals while maintaining security.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If authentication credentials are made viewable by local IT professionals for installation purposes, then the installation process becomes simpler, but the credentials can be misused for purposes adverse to network security

Engineering Contradiction:
Improvecredential installation simplicityVSAvoidnetwork security integrity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The intermediary credential installation system serves as a trusted mediator that handles credential distribution securely. It validates credentials before installation and ensures they are properly configured on devices without exposing them to potential misusers. The system maintains an audit trail and enforcement mechanisms to prevent credential misuse while simplifying the installation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of credential installation (where local IT professionals physically handle and configure credentials) with an automated electronic system. The intermediary system electronically distributes and installs credentials remotely, eliminating the need for human handling and reducing the risk of misuse while maintaining installation simplicity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of time

If video conferencing devices are made accessible remotely for credential installation, then on-site IT professional visits are reduced, but security risks increase if proper authentication mechanisms are not in place

Engineering Contradiction:
Improveon-site installation timeVSAvoidremote access security risks
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The intermediary system performs preliminary authentication and validation actions before allowing remote credential installation. It pre-verifies device identities, validates credential appropriateness, and establishes secure communication channels in advance. This preliminary action ensures that remote access is granted only to authorized devices with proper credentials, eliminating security risks while enabling time-efficient remote installation.

Inventive Principle:
Principle #10Preliminary action

4Extent of automation

If traditional methods like telnet, SSH, or web interfaces are used for remote credential installation, then remote installation capability is achieved, but the credentials remain accessible to local IT professionals who can compromise security

Engineering Contradiction:
Improveremote installation capabilityVSAvoidcredential exposure to untrusted entities
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated intermediary credential installation system that acts as a secure bridge between credential distribution and device configuration. This intermediary system handles all credential transactions through secure, controlled channels, preventing exposure to local IT professionals. It automates the entire process while maintaining cryptographic security, ensuring credentials never become accessible to untrusted entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses secure copying mechanisms where credentials are transmitted in encrypted form and directly injected into the device's secure storage without being exposed in plaintext. The intermediary system creates secure copies of credentials through encrypted channels, ensuring that even during the copying and installation process, the credentials remain protected from unauthorized access by local IT professionals.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9892244B2System and method for installing authentication credentials on a network device
Publication Date: 2018.02.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9892244B2 patent drawing
  • US9892244B2 patent drawing
  • US9892244B2 patent drawing

AI summary

A method for installing authentication credentials on a network device. An intermediary computing device (e.g., client computer) downloads an application for installing the authentication credentials from a secure website. The application on the intermediary computing device requests authentication credentials from a Network Access Control (NAC) credential service. The application passes the authentication credentials received from the NAC credential service through the intermediary computing device to an endpoint (e.g., video conferencing device). The application installs the authentication credentials on the endpoint.