Enterprise Credential Management via Hardware Key and Password
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current password and key management systems in enterprise computing environments are inefficient due to user password reuse, difficulty in memorizing multiple complex passwords, and challenges in managing transient user access, with existing solutions not effectively leveraging hardware security devices like smart cards and RFID/NFC tags.
Innovation Solution
An enterprise credential management system utilizing a hardware security device, such as a smart card or RFID/NFC tag, combined with a strong password to securely manage user credentials, where a symmetric encryption key is derived from the hardware key and user password, encrypting and decrypting connection data to automate access to network services like RDP, SSH, and VPN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users memorize multiple complex passwords for different secure environments, then security is improved, but user burden and difficulty of operation increase
Solution Approach 1:
The patent combines multiple credentials (smart card, RFID tag, NFC tag, or key file) with a single strong password into one authentication mechanism. This merging allows users to access multiple secure environments using a single stored credential set, eliminating the need to memorize multiple complex passwords while maintaining high security through the combination of hardware-based credentials and password protection.
Solution Approach 2:
The system introduces an intermediary credential storage mechanism that mediates between the user and multiple secure environments. Instead of users directly managing multiple passwords, the stored credential acts as an intermediary that automatically provides appropriate authentication credentials to different services, reducing user burden while maintaining security.
2Reliability
If users change passwords frequently to improve security, then security is improved, but password strength decreases due to minimal character changes
Solution Approach 1:
The system performs preliminary authentication using hardware-based credentials (smart card, RFID, NFC, or key file) before requiring password entry. This preliminary action validates the user's identity through the stored credential, allowing the subsequent password to be a single strong password that does not need frequent changes, thereby maintaining both security and password strength.
3Reliability
If enterprise manually manages user access and passwords, then access control is maintained, but management efficiency decreases
Solution Approach 1:
The system enables self-service credential management where users can store and retrieve their own authentication credentials through the encrypted storage mechanism. When users need to access secure environments, the system automatically retrieves the appropriate credentials from stored connection data, eliminating the need for manual enterprise intervention in password distribution and management while maintaining secure access control.
Solution Approach 2:
The enterprise performs preliminary setup by providing users with hardware security devices (smart cards, RFID tags, NFC tags, or key files) and initial passwords. This preliminary action establishes the foundation for automated credential management, allowing subsequent access operations to proceed without manual enterprise involvement while maintaining security policies.
4Device complexity
If enterprise does not leverage hardware security devices, then system simplicity is maintained, but security is weakened
Solution Approach 1:
The system achieves universality by supporting multiple types of hardware security devices (smart cards, RFID tags, NFC tags, and key files) through a common authentication framework. This multi-functionality allows the enterprise to leverage hardware security without creating separate systems for each device type, maintaining relative system simplicity while significantly enhancing security through hardware-based credential storage.
Data Source
AI summary
A hardware, key-file and password assisted enterprise key and password management system. By leveraging hardware and key files, along with public-key cryptography, an extremely efficient and secure key, access and password management system is provided. After configuring an account, the user needs only one hardware key device and need only remember a single strong password.

