Identity Manager Shared Account Credential Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems face challenges in managing shared accounts, as they often require manual and costly provisioning and revocation of credentials, lack accountability due to clear text password access, and do not allow for efficient account delegation, especially in distributed computing environments.

Innovation Solution

An identity management solution using an identity manager and enterprise single sign-on (E-SSO) system that designates roles for shared accounts, automatically generates and distributes unique credentials, and restricts password access to the account owner, enabling secure and automated provisioning and delegation of access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If shared account credentials are distributed to all authorized users in clear text, then all users can access the shared account, but auditing becomes difficult and security is compromised

Engineering Contradiction:
Improveaccess to shared accountVSAvoidsecurity and auditing
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the shared account access by creating individual delegated credentials for each authorized user. Instead of one shared credential held by multiple users, each user receives a unique credential that is segmented and specific to their identity, enabling both access and individual auditing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The identity manager acts as an intermediary between the shared account and individual users. It automatically generates and distributes delegated credentials to authorized users, mediating the credential distribution process and eliminating the need for manual sharing of clear text passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual provisioning and revocation of shared credentials is performed, then access control can be managed, but the process becomes costly and problematic

Engineering Contradiction:
Improveaccess controlVSAvoidprovisioning and revocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service through automated credential management. The identity manager automatically provisions delegated credentials to authorized users and revokes them when authorization is removed, eliminating manual intervention and improving efficiency while maintaining reliable access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The identity manager serves as an automated intermediary that handles the provisioning and revocation processes. It receives authorization decisions and automatically generates, distributes, and revokes credentials without manual intervention, resolving the contradiction between reliable control and operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the shared account password is changed, then security is improved, but all users must be re-provisioned with new credentials

Engineering Contradiction:
Improveaccount securityVSAvoidre-provisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

When the shared account password is changed, the identity manager automatically re-provisions all delegated credentials to authorized users without manual intervention. This automated self-service process eliminates the time loss associated with manual re-provisioning while maintaining security through password changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system maintains continuous credential validity for all authorized users. When the shared account password changes, the identity manager continuously re-provisions delegated credentials automatically, ensuring that security is improved without interrupting service or requiring manual re-provisioning actions.

Inventive Principle:
Principle #20Continuity of useful action

4Adaptability or versatility

If a user delegates account access to another user, then temporary access is enabled, but current systems only allow delegation of identity operations not actual account access

Engineering Contradiction:
Improveaccount delegation capabilityVSAvoiddelegation security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent enables delegation by segmenting the shared account credential into individual delegated credentials. Each delegated credential is uniquely assigned to a specific user for a defined period, allowing actual account access delegation while maintaining security through individualized, time-limited credentials that are tracked by the identity manager.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8572709B2Method for managing shared accounts in an identity management system
Publication Date: 2013.10.29 WORKDAY INC
  • US8572709B2 patent drawing
  • US8572709B2 patent drawing
  • US8572709B2 patent drawing

AI summary

This disclosure describes a method of and system for provisioning of shared account credentials to provide authorized access to shared or delegated accounts. Preferably, an enterprise single sign-on (E-SSO) system is used to manage the shared account or control delegation of account access, and preferably the shared or delegated account credential is not exposed to the end user. The described technique enables temporary delegation of account privileges to a member of a shared role. Using the described approach, an information technology (IT) account may be shared so that a user who needs to perform a shared duty can do so in the context of a shared role and without having control over the account itself. The approach facilitates delegating the use of a single account to one of a member of the shared role.