Dynamic Instance Credential Assignment for Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing user credentials and application/client credentials becomes laborious and unmanageable in scenarios with a large number of users and applications, particularly with mobile applications where each user can download multiple instances.

Innovation Solution

An identity management and access system (IMAS) dynamically generates and associates application instance-specific credentials with each application instance during the registration process, allowing each instance to transition from a limited functionality template to a fully functional application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application-specific credentials are managed manually for each user instance, then security control is maintained, but management becomes laborious and unmanageable with large numbers of users and applications

Engineering Contradiction:
Improvesecurity controlVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automatic credential generation and assignment without manual intervention. The identity management system automatically generates unique credentials for each application instance and user combination, and the system self-manages credential distribution and revocation through automated workflows, eliminating the laborious manual management process while maintaining security control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes credential parameters based on user and application instance combinations. Instead of static credentials, the system generates unique credential sets for each user-application instance pair, allowing flexible security management where credentials can be selectively activated, deactivated, or revoked based on specific user needs without affecting other users or instances

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If credentials are pre-assigned to application templates, then credential management is simplified, but security is reduced because all instances share the same credentials

Engineering Contradiction:
Improvecredential managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments credentials at the instance level rather than using shared template-level credentials. Each application instance receives its own unique credential set that is further segmented by user association, allowing individual credential management for each user-instance combination while maintaining simplified overall management through automated processes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by providing different credential characteristics to different application instances and user combinations. Each user-instance pair receives credentials with specific properties tailored to their needs, rather than using uniform credentials across all instances, thereby maintaining both security differentiation and management simplicity

Inventive Principle:
Principle #3Local quality

3Reliability

If unique credentials are generated for each application instance, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity management system is designed with multi-functionality to handle credential generation, storage, distribution, and revocation across multiple users and application instances through a single unified system. This universal approach manages the complexity of unique credentials for each instance while maintaining improved security, rather than requiring separate systems for each credential set

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12273343B2Techniques for dynamically assigning client credentials to an application
Publication Date: 2025.04.08 ORACLE INT CORP
  • US12273343B2 patent drawing
  • US12273343B2 patent drawing
  • US12273343B2 patent drawing

AI summary

An identity management and authorization system (IMAS) receives a request to download an application to a user device associated with a user. The IMAS downloads, to the user device, a template application instance corresponding to the requested application, the template application instance having a reduced functionality than the requested application. The IMAS receives, from the user device, a request to register to the downloaded template. Responsive to receiving the request to register the application, the IMAS causes the template application instance on the user device to transition to an application instance of the application with full functionality, generates an application instance-specific credential for the application instance, associates the generated application instance-specific credential with the application instance, and stores the application instance-specific credential in association with (1) an application identifier identifying the application instance, (2) a user identifier identifying the user, and (3) a user device identifier identifying the user device.