Credential Manager for Unattended Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for computer resources, such as hard-coded passwords, User Identity Management, provisioning systems, Public Key Infrastructures, and Kerberos protocols, fail to provide secure and automated credential management for unattended applications, leading to vulnerabilities and increased maintenance costs.

Innovation Solution

A computer-implemented method and system that securely manages and retrieves credentials for unattended applications by decoding connection requests, encrypting communications, and using a credential manager to establish connections with target resources through native database connectivity components, such as JDBC or ODBC APIs, without requiring code changes to the requestor application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hard-coded passwords are used for application authentication, then applications can access target resources, but security vulnerabilities increase due to clear-text password storage and distribution requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password from the application code by introducing a separate credential manager component. The application no longer contains hard-coded passwords; instead, it retrieves credentials dynamically from an external credential manager, separating authentication data from the application binary and eliminating clear-text password storage in code.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential manager as an intermediary component between the application and the target resource. This mediator handles credential retrieval, management, and rotation dynamically, replacing the direct hard-coded authentication approach and providing enhanced security controls without requiring application code changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If passwords are changed frequently according to security policies, then security posture improves, but application maintenance complexity and costs increase

Engineering Contradiction:
Improvesecurity postureVSAvoidmaintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service credential management where the credential manager automatically handles password changes, rotations, and updates without requiring application redeployment or manual intervention. The system autonomously manages credential lifecycle events, eliminating the maintenance burden associated with frequent password changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes preliminary credential management infrastructure that proactively handles future credential changes. By setting up the credential manager in advance with automated rotation policies and event-driven updates, the system prepares for security policy requirements without requiring reactive maintenance when passwords need to be changed.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If User Identity Management systems are used for authentication, then individual user authentication is enabled, but unattended application authentication fails due to lack of automated credential management

Engineering Contradiction:
Improveuser authentication capabilityVSAvoidapplication automation capability
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent creates a universal credential manager that serves multiple authentication scenarios: both interactive user authentication and automated unattended application authentication. The system provides a unified interface that adapts to different authentication contexts, enabling both user-driven and machine-driven access without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authentication functionality into distinct operational modes within the credential manager: interactive user authentication flows and automated application credential retrieval flows. This segmentation allows the system to handle different authentication types appropriately while maintaining a unified underlying infrastructure.

Inventive Principle:
Principle #1Segmentation

4Reliability

If Public Key Infrastructures are implemented for authentication, then comprehensive authentication and authorization is achieved, but integration complexity and deployment costs increase dramatically

Engineering Contradiction:
Improveauthentication comprehensivenessVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified credential management model that copies the essential functionality needed for secure authentication without implementing the full complexity of PKI. The credential manager provides certificate-based, token-based, and password-based authentication mechanisms in a unified, simplified interface that achieves comprehensive security without PKI-level integration complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8839414B2Authenticated database connectivity for unattended applications
Publication Date: 2014.09.16 IRDETO BV
  • US8839414B2 patent drawing
  • US8839414B2 patent drawing
  • US8839414B2 patent drawing

AI summary

A custom database connectivity component is deployed in conjunction with a native database connectivity component and a credential manager. The custom connectivity component has a requestor interface for communicating with a requestor application, a credential service interface for communicating with the credential manager, a native database connectivity interface for communicating with native connectivity components, and a decision engine for determining how to convert a request from a requestor to an appropriate API call to the credential manager. The custom connectivity component provides an authenticated and authorized database connection for a requestor application. The component transparently serves retrieves database, or other target resource, credentials on a real time basis, without requiring code changes to the requestor application.