Credential Management Agent for Secure Resource Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for sharing secure remote resources among users are cumbersome and prone to security issues, such as accidental access by unauthorized parties.

Innovation Solution

A mechanism that allows trusted groups of users to access secure remote resources using the credentials of one member, managed through a platform that validates user permissions and resource ownership, providing a transparent and secure sharing experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share secure resource access by emailing links with usernames and passwords, then resource sharing is enabled, but security risks increase and operational complexity increases

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a credential management service as an intermediary between users and remote resources. This service stores credentials securely and provides them only to authorized users within a trusted group, eliminating the need for users to share credentials directly. The intermediary validates user permissions and manages credential distribution, thereby maintaining security while enabling resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service credential management where users can register their own credentials with the credential management service and define their own trusted groups. Users can independently manage which resources to share and with whom, without requiring manual credential distribution or administrative intervention for each sharing scenario.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If users share credentials manually through communication channels, then resource access is provided, but ease of operation deteriorates and time consumption increases

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidoperational simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Users independently register credentials, define trusted groups, and manage resource sharing preferences through the platform. The system automatically handles credential distribution and validation, eliminating manual credential sharing through emails or messages and significantly improving operational simplicity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Users pre-register their credentials and define their trusted groups in advance with the credential management service. This preliminary setup enables automatic credential provision to any member of the trusted group without requiring real-time manual intervention, making the sharing process seamless and operationally simple.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If individual credential management is used for each user, then security is maintained, but device complexity and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges individual credential management into a centralized credential management service that handles multiple users' credentials uniformly. Instead of each user managing separate credential systems, a single unified service manages all credentials, validates permissions, and provisions access, thereby reducing overall system complexity while maintaining security through standardized processes.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12273347B2Techniques and architectures for sharing remote resources among a trusted group of users
Publication Date: 2025.04.08 SALESFORCE INC
  • US12273347B2 patent drawing
  • US12273347B2 patent drawing
  • US12273347B2 patent drawing

AI summary

Various techniques and mechanisms for sharing remote resources among a trusted group are disclosed. A credential management agent utilizes a resource credential for a first user to access a secure resource corresponding to the first user for a second user by at least validating a second user and validating a consent of the first user to allow the second user to access the secure resource using the resource credential for the first user. The secure resource resides on a remote server system accessible via one or more application program interfaces (APIs). A platform management agent provides an interface for shared resource-agnostic credential sharing. The platform management agent validates credentials for the second user as belonging to a trusted group and forwards a request for access to the secure resource for the second user to the credential management agent. In response to receiving the resource credential for the first user to access the secure resource, the platform management agent accesses the secure resource on behalf of the second user to allow the second user to utilize the secure resource.