Credential Manager for Computing Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IT equipment devices often come with default username and password combinations that are not changed by users, leaving them vulnerable to security threats as these credentials can be easily accessed by unauthorized parties, compromising device and network security.
Innovation Solution
A system where a credential manager assigns unique credential sets to computing devices, mapping them to device identifier keys stored in a secure database, eliminating the need for default credentials and ensuring that users must establish new credentials upon activation, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If default credential sets are provided for computing devices, then ease of installation and initial configuration is improved, but device security and vulnerability to unauthorized access deteriorates
Solution Approach 1:
The system performs preliminary actions by pre-assigning and securely storing unique credential sets in a credential data store before device delivery. The credential manager proactively provisions credentials to the device during manufacturing, eliminating the need for users to manually configure default credentials while ensuring security is established in advance.
Solution Approach 2:
The patent extracts the credential provisioning function from the end-user configuration process and relocates it to the credential manager system. By taking out the default credential assignment from user responsibility and placing it under controlled management, the system eliminates security vulnerabilities associated with unchanged default credentials while maintaining ease of initial device setup.
2Reliability
If users are required to change default credentials upon activation, then device security is improved, but user operation complexity and time consumption increases
Solution Approach 1:
The credential manager system provides self-service by automatically provisioning unique credential sets to devices during manufacturing and making them available through the provisioning service. The system handles credential assignment, storage, and retrieval automatically, eliminating the need for users to manually change default credentials while reducing setup time through automated credential delivery.
Solution Approach 2:
The credential manager acts as an intermediary between the device manufacturer and the end-user. It manages the entire credential lifecycle including generation, secure storage in the credential data store, and automated delivery to the device. This intermediary system eliminates direct user involvement in credential configuration while maintaining security, thereby reducing both time loss and operational complexity.
3Ease of operation
If credential data is stored locally on the device, then ease of access and authentication speed is improved, but security vulnerability to unauthorized access and data breaches increases
Solution Approach 1:
The credential manager serves as a secure intermediary that handles credential storage and distribution. Instead of storing credentials locally on the device, the system uses a remote credential data store accessible through a secure provisioning service. This intermediary architecture enables fast authentication by retrieving pre-provisioned credentials while maintaining security through centralized controlled access and eliminating local storage vulnerabilities.
Data Source
AI summary
Methods, systems, and computer readable mediums for securely establishing credential data for a computing device are disclosed. According to one example, a method includes assigning, by a credential manager, credential set data to a computing device and mapping the credential set data to a device identifier key associated with the computing device in a credential data store accessible by the credential manager. The method further includes receiving, from a provisioning service client, a credential set request message including the device identifier key by the credential manager in response to an activation of the computing device at a customer location site and sending, by the credential manager to the provisioning service client, the credential set data for authenticating the computing device at the customer location site.


