Enterprise Credential Management via Hardware Key and Password

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password and key management systems in enterprise computing environments are inefficient due to user password reuse, difficulty in memorizing multiple complex passwords, and challenges in managing transient user access, with existing solutions not effectively leveraging hardware security devices like smart cards and RFID/NFC tags.

Innovation Solution

An enterprise credential management system utilizing a hardware security device, such as a smart card or RFID/NFC tag, combined with a strong password to securely manage user credentials, where a symmetric encryption key is derived from the hardware key and user password, encrypting and decrypting connection data to automate access to network services like RDP, SSH, and VPN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users memorize multiple complex passwords for different secure environments, then security is improved, but user burden and difficulty of operation increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple credentials (smart card, RFID tag, NFC tag, or key file) with a single strong password into one authentication mechanism. This merging allows users to access multiple secure environments using a single stored credential set, eliminating the need to memorize multiple complex passwords while maintaining high security through the combination of hardware-based credentials and password protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary credential storage mechanism that mediates between the user and multiple secure environments. Instead of users directly managing multiple passwords, the stored credential acts as an intermediary that automatically provides appropriate authentication credentials to different services, reducing user burden while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users change passwords frequently to improve security, then security is improved, but password strength decreases due to minimal character changes

Engineering Contradiction:
ImprovesecurityVSAvoidpassword strength
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system performs preliminary authentication using hardware-based credentials (smart card, RFID, NFC, or key file) before requiring password entry. This preliminary action validates the user's identity through the stored credential, allowing the subsequent password to be a single strong password that does not need frequent changes, thereby maintaining both security and password strength.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If enterprise manually manages user access and passwords, then access control is maintained, but management efficiency decreases

Engineering Contradiction:
Improveaccess controlVSAvoidmanagement efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service credential management where users can store and retrieve their own authentication credentials through the encrypted storage mechanism. When users need to access secure environments, the system automatically retrieves the appropriate credentials from stored connection data, eliminating the need for manual enterprise intervention in password distribution and management while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The enterprise performs preliminary setup by providing users with hardware security devices (smart cards, RFID tags, NFC tags, or key files) and initial passwords. This preliminary action establishes the foundation for automated credential management, allowing subsequent access operations to proceed without manual enterprise involvement while maintaining security policies.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If enterprise does not leverage hardware security devices, then system simplicity is maintained, but security is weakened

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system achieves universality by supporting multiple types of hardware security devices (smart cards, RFID tags, NFC tags, and key files) through a common authentication framework. This multi-functionality allows the enterprise to leverage hardware security without creating separate systems for each device type, maintaining relative system simplicity while significantly enhancing security through hardware-based credential storage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10666644B2Enterprise key and password management system
Publication Date: 2020.05.26 REVBITS LLC
  • US10666644B2 patent drawing
  • US10666644B2 patent drawing

AI summary

A hardware, key-file and password assisted enterprise key and password management system. By leveraging hardware and key files, along with public-key cryptography, an extremely efficient and secure key, access and password management system is provided. After configuring an account, the user needs only one hardware key device and need only remember a single strong password.