Credential Provisioning via Intermediate Element for User Attribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user provisioning systems face challenges in ensuring proper authorization and accountability, particularly when shared accounts are used, leading to difficulties in attributing access and operations to specific users due to the lack of individualized credentials and authorization levels.

Innovation Solution

A method and system for credential provisioning that involves an intermediate element receiving a request from a user client to establish a session with a target service, using privileged credentials to create provisioned credentials, and establishing a dual session communication channel, allowing the user client to access the target service without direct access to credentials, while ensuring proper authorization and attribution of actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If shared accounts are used for accessing target services, then ease of operation is improved, but accountability and measurement precision deteriorate due to inability to attribute actions to specific users

Engineering Contradiction:
Improveease of operationVSAvoidattribution precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the shared account access into multiple individualized session credentials, where each user receives a unique credential for their specific session. This allows the system to maintain ease of operation through automated credential distribution while achieving precise attribution of actions to individual users through unique session identifiers and logging mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The provisioning system acts as an intermediary between users and target services, managing credential distribution and session tracking. This intermediary layer enables automated credential provisioning (improving ease of operation) while maintaining detailed logs of which user accessed which service when (improving attribution precision).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If manual provisioning processes are used, then device complexity is reduced, but productivity and time efficiency deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidprovisioning speed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system implements self-service provisioning where users can automatically obtain their own session credentials through the provisioning system without requiring manual administrator intervention. This automation dramatically improves provisioning speed while the system maintains relatively simple architecture by using standardized credential management protocols.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated credential provisioning is implemented, then productivity is improved, but security risks worsen due to potential credential misuse

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic credential management where session credentials are automatically created, distributed, and revoked based on real-time user sessions. Credentials have temporary validity periods and are automatically invalidated when sessions end, reducing security risks while maintaining high provisioning efficiency through automated lifecycle management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms through comprehensive logging and monitoring of credential usage. Each credential transaction is tracked and recorded, enabling the system to detect and respond to potential misuse while maintaining automated provisioning operations. This feedback loop enhances security without significantly impacting provisioning efficiency.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If individualized credentials are provisioned for each user, then accountability and measurement precision are improved, but device complexity and operational overhead worsen

Engineering Contradiction:
Improveattribution precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The provisioning system implements a universal credential management platform that handles multiple functions: credential generation, distribution, tracking, and revocation. This multi-functional approach achieves precise user attribution while avoiding the complexity of multiple separate systems by consolidating all credential management operations into a single standardized platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9680813B2User provisioning
Publication Date: 2017.06.13 CYBER ARK SOFTWARE LTD
  • US9680813B2 patent drawing
  • US9680813B2 patent drawing
  • US9680813B2 patent drawing

AI summary

A method of credential provisioning on a target service utilizes three credential sets: authentication credentials, privileged credentials and provisioned credentials. An intermediate element receives a request from a user client to establish a session with a target service. The request includes authentication credentials. The intermediate element creates provisioned credentials using privileged credentials which are authorized for creating provisioned credentials for accessing the target service. Once provisioned credentials have been created, a dual session communication channel is established between the user client and the target service. The session between the user client and intermediate element is established using the authentication credentials and the session between the intermediate element and the target service is established using the provisioned credentials. Optionally, user authorization to establish a session with the target service is determined prior to creating the provisioned credentials.