Intermediary Component Credential Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are hesitant to access resources or services from untrusted computers due to concerns about their user credentials being compromised by malicious programs, leading to frustration and delays.

Innovation Solution

Implementing an intermediary component that obtains and manages user credentials, sends requests to access services on behalf of the user, and returns session state information, allowing the user to access services without revealing their credentials to the less trusted access component.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access services directly from untrusted computers, then ease of operation is improved, but security and reliability deteriorate due to credential exposure risks

Engineering Contradiction:
Improveease of accessVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary component that acts as a mediator between the user's access component and the service. This intermediary obtains user credentials, sends authenticated requests to services, and returns session state information without exposing credentials to the access component. This resolves the contradiction by enabling easy access through the intermediary while maintaining credential security through its mediation role.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If an intermediary component is introduced to protect credentials, then reliability and security are improved, but device complexity increases

Engineering Contradiction:
Improvecredential securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediary component consolidates multiple functions (credential management, authentication, session state handling) into a single trusted entity. This approach improves reliability by centralizing security functions while managing complexity through functional consolidation rather than distribution across multiple components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If users enter credentials on untrusted computers, then ease of operation is improved, but loss of information increases due to potential credential theft

Engineering Contradiction:
Improveease of accessVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The intermediary component extracts the credential entry and authentication functions from the untrusted access component. Users interact with the access component for ease of operation, but credentials are obtained and managed exclusively by the intermediary, preventing exposure to the untrusted environment while maintaining user-friendly access.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If session state information is used instead of credentials, then reliability is improved by preventing credential exposure, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improvecredential protectionVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a session state information copy that represents authenticated user identity without containing actual credentials. This copy enables subsequent authenticated interactions while preventing credential exposure. The copying mechanism simplifies the authentication flow after initial credential verification by the intermediary.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8984597B2Protecting user credentials using an intermediary component
Publication Date: 2015.03.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8984597B2 patent drawing
  • US8984597B2 patent drawing
  • US8984597B2 patent drawing

AI summary

An access component sends an access request to an intermediary component, the access request being a request to access a service or resource without credentials of a current user of the intermediary component being revealed to the access component. The intermediary component obtains user credentials, for the current user, that are associated with the service or resource. The access request and the user credentials are sent to the service or resource, and in response session state information is received from the service or resource. The session state information is returned to the access component, which allows the access component and the service or resource to communicate with one another based on the session state information and independently of the first component.