Identity Manager Shared Account Credential Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems face challenges in managing shared accounts, as they often require manual and costly provisioning and revocation of credentials, lack accountability due to clear text password access, and do not allow for efficient account delegation, especially in distributed computing environments.
Innovation Solution
An identity management solution using an identity manager and enterprise single sign-on (E-SSO) system that designates roles for shared accounts, automatically generates and distributes unique credentials, and restricts password access to the account owner, enabling secure and automated provisioning and delegation of access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If shared account credentials are distributed to all authorized users in clear text, then all users can access the shared account, but auditing becomes difficult and security is compromised
Solution Approach 1:
The patent segments the shared account access by creating individual delegated credentials for each authorized user. Instead of one shared credential held by multiple users, each user receives a unique credential that is segmented and specific to their identity, enabling both access and individual auditing.
Solution Approach 2:
The identity manager acts as an intermediary between the shared account and individual users. It automatically generates and distributes delegated credentials to authorized users, mediating the credential distribution process and eliminating the need for manual sharing of clear text passwords.
2Reliability
If manual provisioning and revocation of shared credentials is performed, then access control can be managed, but the process becomes costly and problematic
Solution Approach 1:
The system enables self-service through automated credential management. The identity manager automatically provisions delegated credentials to authorized users and revokes them when authorization is removed, eliminating manual intervention and improving efficiency while maintaining reliable access control.
Solution Approach 2:
The identity manager serves as an automated intermediary that handles the provisioning and revocation processes. It receives authorization decisions and automatically generates, distributes, and revokes credentials without manual intervention, resolving the contradiction between reliable control and operational efficiency.
3Reliability
If the shared account password is changed, then security is improved, but all users must be re-provisioned with new credentials
Solution Approach 1:
When the shared account password is changed, the identity manager automatically re-provisions all delegated credentials to authorized users without manual intervention. This automated self-service process eliminates the time loss associated with manual re-provisioning while maintaining security through password changes.
Solution Approach 2:
The system maintains continuous credential validity for all authorized users. When the shared account password changes, the identity manager continuously re-provisions delegated credentials automatically, ensuring that security is improved without interrupting service or requiring manual re-provisioning actions.
4Adaptability or versatility
If a user delegates account access to another user, then temporary access is enabled, but current systems only allow delegation of identity operations not actual account access
Solution Approach 1:
The patent enables delegation by segmenting the shared account credential into individual delegated credentials. Each delegated credential is uniquely assigned to a specific user for a defined period, allowing actual account access delegation while maintaining security through individualized, time-limited credentials that are tracked by the identity manager.
Data Source
AI summary
This disclosure describes a method of and system for provisioning of shared account credentials to provide authorized access to shared or delegated accounts. Preferably, an enterprise single sign-on (E-SSO) system is used to manage the shared account or control delegation of account access, and preferably the shared or delegated account credential is not exposed to the end user. The described technique enables temporary delegation of account privileges to a member of a shared role. Using the described approach, an information technology (IT) account may be shared so that a user who needs to perform a shared duty can do so in the context of a shared role and without having control over the account itself. The approach facilitates delegating the use of a single account to one of a member of the shared role.


