Digital Certificate Verification for Shared Account Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Shared logon credentials for Accounts of Last Resort (ALRs) are vulnerable to compromise, putting multiple Information Handling Systems (IHSs) at risk, as they are often used across many users and systems without adequate security measures.
Innovation Solution
The system generates a unique digital certificate using a private encryption key specific to the IHS, which is shared with users, allowing secure logging onto the ALR by verifying a signed digital certificate, thereby reducing credential risk exposure and enhancing security across multiple IHSs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If shared logon credentials are used for ALRs across multiple users and systems, then ease of operation and accessibility are improved, but security and reliability deteriorate due to vulnerability to compromise
Solution Approach 1:
A digital certificate authority (CA) is introduced as an intermediary between users and the shared ALR credentials. The CA issues digital certificates to users that verify their identity before allowing access to the shared credentials, thus mediating the trust relationship and maintaining security while preserving accessibility.
Solution Approach 2:
The patent replaces the mechanical/password-based authentication system with a cryptographic digital certificate system. Instead of relying solely on shared passwords that can be compromised, the system uses asymmetric cryptography and digital certificates to verify user identities, thereby maintaining ease of access while significantly improving security.
2Reliability
If unique credentials are provisioned for each user, then security is improved, but device complexity and management overhead increase
Solution Approach 1:
The shared ALR credentials are designed to be universal, allowing multiple users to access the same account through a common credential set. This multi-functionality is enabled by the digital certificate verification mechanism, which allows the system to distinguish between users based on their certificates while using the same underlying shared credentials, thus reducing management complexity.
Solution Approach 2:
The authentication process is segmented into two distinct parts: (1) digital certificate verification to identify and authenticate the user, and (2) credential validation to verify the shared ALR credentials. This segmentation allows the system to maintain security through unique user identification while using shared credentials, thereby reducing management overhead.
3Reliability
If digital certificate verification is implemented for shared ALR credentials, then security is improved, but device complexity increases due to additional cryptographic operations
Solution Approach 1:
Digital certificates are issued to users in advance before they need to access the shared ALR credentials. This preliminary action of certificate issuance simplifies the authentication process at login time, as the system only needs to verify the pre-issued certificate rather than performing complex cryptographic operations from scratch during authentication.
Solution Approach 2:
The system uses digital certificate copies that contain verified user identity information. Instead of requiring complex real-time cryptographic verification of user identities, the system verifies pre-issued certificate copies that already contain the necessary authentication data, thereby reducing the computational complexity of the authentication process.
Data Source
AI summary
Systems and methods for securing Accounts of Last Resort (ALRs) are described. In an illustrative, non-limiting embodiment, an IHS may include a processor and a memory coupled to the processor, the memory having program instructions that, upon execution, cause the IHS to receive a credential from one of a plurality of users to log onto an ALR, where the credential is shared among the plurality of users, and log the user onto the ALR in response to verification of a signed digital certificate provided by the user.


