Dynamic Instance Credential Assignment for Identity Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing user credentials and application/client credentials becomes laborious and unmanageable in scenarios with a large number of users and applications, particularly with mobile applications where each user can download multiple instances.
Innovation Solution
An identity management and access system (IMAS) dynamically generates and associates application instance-specific credentials with each application instance during the registration process, allowing each instance to transition from a limited functionality template to a fully functional application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application-specific credentials are managed manually for each user instance, then security control is maintained, but management becomes laborious and unmanageable with large numbers of users and applications
Solution Approach 1:
The system enables automatic credential generation and assignment without manual intervention. The identity management system automatically generates unique credentials for each application instance and user combination, and the system self-manages credential distribution and revocation through automated workflows, eliminating the laborious manual management process while maintaining security control
Solution Approach 2:
The system dynamically changes credential parameters based on user and application instance combinations. Instead of static credentials, the system generates unique credential sets for each user-application instance pair, allowing flexible security management where credentials can be selectively activated, deactivated, or revoked based on specific user needs without affecting other users or instances
2Ease of operation
If credentials are pre-assigned to application templates, then credential management is simplified, but security is reduced because all instances share the same credentials
Solution Approach 1:
The system segments credentials at the instance level rather than using shared template-level credentials. Each application instance receives its own unique credential set that is further segmented by user association, allowing individual credential management for each user-instance combination while maintaining simplified overall management through automated processes
Solution Approach 2:
The system applies local quality by providing different credential characteristics to different application instances and user combinations. Each user-instance pair receives credentials with specific properties tailored to their needs, rather than using uniform credentials across all instances, thereby maintaining both security differentiation and management simplicity
3Reliability
If unique credentials are generated for each application instance, then security is improved, but system complexity increases
Solution Approach 1:
The identity management system is designed with multi-functionality to handle credential generation, storage, distribution, and revocation across multiple users and application instances through a single unified system. This universal approach manages the complexity of unique credentials for each instance while maintaining improved security, rather than requiring separate systems for each credential set
Data Source
AI summary
An identity management and authorization system (IMAS) receives a request to download an application to a user device associated with a user. The IMAS downloads, to the user device, a template application instance corresponding to the requested application, the template application instance having a reduced functionality than the requested application. The IMAS receives, from the user device, a request to register to the downloaded template. Responsive to receiving the request to register the application, the IMAS causes the template application instance on the user device to transition to an application instance of the application with full functionality, generates an application instance-specific credential for the application instance, associates the generated application instance-specific credential with the application instance, and stores the application instance-specific credential in association with (1) an application identifier identifying the application instance, (2) a user identifier identifying the user, and (3) a user device identifier identifying the user device.


