Credential Manager for Computing Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT equipment devices often come with default username and password combinations that are not changed by users, leaving them vulnerable to security threats as these credentials can be easily accessed by unauthorized parties, compromising device and network security.

Innovation Solution

A system where a credential manager assigns unique credential sets to computing devices, mapping them to device identifier keys stored in a secure database, eliminating the need for default credentials and ensuring that users must establish new credentials upon activation, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If default credential sets are provided for computing devices, then ease of installation and initial configuration is improved, but device security and vulnerability to unauthorized access deteriorates

Engineering Contradiction:
Improveease of installationVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-assigning and securely storing unique credential sets in a credential data store before device delivery. The credential manager proactively provisions credentials to the device during manufacturing, eliminating the need for users to manually configure default credentials while ensuring security is established in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the credential provisioning function from the end-user configuration process and relocates it to the credential manager system. By taking out the default credential assignment from user responsibility and placing it under controlled management, the system eliminates security vulnerabilities associated with unchanged default credentials while maintaining ease of initial device setup.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If users are required to change default credentials upon activation, then device security is improved, but user operation complexity and time consumption increases

Engineering Contradiction:
Improvedevice securityVSAvoidcredential setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The credential manager system provides self-service by automatically provisioning unique credential sets to devices during manufacturing and making them available through the provisioning service. The system handles credential assignment, storage, and retrieval automatically, eliminating the need for users to manually change default credentials while reducing setup time through automated credential delivery.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The credential manager acts as an intermediary between the device manufacturer and the end-user. It manages the entire credential lifecycle including generation, secure storage in the credential data store, and automated delivery to the device. This intermediary system eliminates direct user involvement in credential configuration while maintaining security, thereby reducing both time loss and operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If credential data is stored locally on the device, then ease of access and authentication speed is improved, but security vulnerability to unauthorized access and data breaches increases

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The credential manager serves as a secure intermediary that handles credential storage and distribution. Instead of storing credentials locally on the device, the system uses a remote credential data store accessible through a secure provisioning service. This intermediary architecture enables fast authentication by retrieving pre-provisioned credentials while maintaining security through centralized controlled access and eliminating local storage vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11843601B2Methods, systems, and computer readable mediums for securely establishing credential data for a computing device
Publication Date: 2023.12.12 EMC IP HLDG CO LLC
  • US11843601B2 patent drawing
  • US11843601B2 patent drawing
  • US11843601B2 patent drawing

AI summary

Methods, systems, and computer readable mediums for securely establishing credential data for a computing device are disclosed. According to one example, a method includes assigning, by a credential manager, credential set data to a computing device and mapping the credential set data to a device identifier key associated with the computing device in a credential data store accessible by the credential manager. The method further includes receiving, from a provisioning service client, a credential set request message including the device identifier key by the credential manager in response to an activation of the computing device at a customer location site and sending, by the credential manager to the provisioning service client, the credential set data for authenticating the computing device at the customer location site.