Credential Management System for Secure SSO Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in allowing individual users access to remote servers while keeping credentials and session information secure, and in implementing single sign-on (SSO) across multiple remote servers without disclosing credentials or session data to client devices.

Innovation Solution

A computer-implemented method and system that provides credentialed access to remote servers by transmitting and managing credentials and session secrets, with restricted access to client devices, using encryption, proxy servers, and selective routing, allowing for SSO across multiple servers without exposing credentials or session data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials and session information are disclosed to client devices for access authentication, then access control functionality is achieved, but security is compromised as users can access or misuse credentials

Engineering Contradiction:
ImprovesecurityVSAvoidaccess management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential management system that acts as an intermediary between users and remote servers. This system stores credentials securely on a server, transmits them during authentication, and then restricts client device access to the credentials while maintaining session functionality. The intermediary manages the credential lifecycle without exposing sensitive data to end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the credential management process into distinct components: credential storage, credential transmission, session management, and client device operation. By separating these functions, the system can securely manage credentials on the server side while allowing clients to interact with session data without accessing underlying credentials.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If individual user access to remote servers is enabled with unique credentials, then personalized access control is achieved, but credential management complexity increases significantly

Engineering Contradiction:
Improveindividual access controlVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal credential management system that handles multiple users, multiple remote servers, and various authentication scenarios through a single centralized platform. This system provides multi-functionality by supporting individual user credentials, organizational credentials, session management, and restricted client access all through one system, eliminating the need for separate credential management for each user-server pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If session information is made accessible to client devices for subsequent access, then convenience of repeated access is improved, but security risks increase as session data may be exposed or misused

Engineering Contradiction:
Improveconvenience of accessVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system uses the credential management system as an intermediary that controls session information flow. The intermediary transmits necessary session data to clients for convenient access while simultaneously filtering and restricting what session information reaches the client device, preventing exposure of sensitive session secrets while maintaining functional access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11665150B2System and method for credentialed access to a remote server
Publication Date: 2023.05.30 PLEASANT SOLUTIONS
  • US11665150B2 patent drawing
  • US11665150B2 patent drawing
  • US11665150B2 patent drawing

AI summary

Credentials for an account on a remote server requiring credentialed access by a client device are created, credentials are transmitted to the remote server, and response data including the credentials is received from the remote server, while restricting access to the credentials by the client device at all times. Session data transmitted by the remote server is also restricted from the client device to prevent side loading of session secrets onto client devices that may be used to attempt to gain unauthorized access to the remote server. Cookies are used to allow the client device to access more than one remote server without having to authenticate individually to each remote server.