Intermediary System for Secure Credential Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securely migrating security credentials between systems that use different encoding technologies, requiring a solution to ensure seamless authentication and compliance with varying regulatory requirements.

Innovation Solution

An intermediary system is introduced that securely migrates security credentials by providing digitally signed secure login interface program code to devices, establishing trust relationships, and facilitating the migration of authenticated credentials between systems with different cryptographic encoders, ensuring secure authentication and updating credential repositories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If different encoding technologies are used in different authentication systems, then each system can maintain its own security standards and compliance requirements, but secure migration of credentials between systems becomes complex and difficult

Engineering Contradiction:
Improvecompatibility with different encoding technologiesVSAvoidcomplexity of credential migration process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between source and target authentication systems with different encoding technologies. This intermediary captures credentials from the source system, re-encodes them using the target system's encoding technology, and forwards them to the target system, thereby enabling seamless credential migration without direct interaction between incompatible systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The credential migration process is segmented into distinct stages: credential capture at the source system, intermediary processing and re-encoding, and credential delivery to the target system. This segmentation allows each component to be optimized independently for its specific encoding technology while maintaining overall system compatibility

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic encoding is applied to store passwords securely, then security is improved, but the ability to migrate credentials between different encoding systems deteriorates

Engineering Contradiction:
Improvesecurity of stored credentialsVSAvoidportability across different encoding systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The intermediary system dynamically changes the encoding parameters (algorithm, salt, iteration count) based on the requirements of the target authentication system. It captures credentials encoded with one set of parameters from the source system and re-encodes them with different parameters suitable for the target system, maintaining security while ensuring compatibility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The intermediary system pre-configures multiple encoding technology profiles and algorithms in advance. When a migration is needed, it selects the appropriate pre-configured encoding profile for the target system, eliminating the need for real-time encoding development and ensuring secure transformation

Inventive Principle:
Principle #10Preliminary action

3Reliability

If trust relationships are established between authentication systems for credential migration, then secure migration is enabled, but the setup and management of trust relationships becomes complex

Engineering Contradiction:
Improvesecurity of credential migrationVSAvoidease of establishing trust relationships
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Trust relationships are established in advance between the intermediary system and both source and target authentication systems through pre-shared secrets, digital certificates, or API credentials. This preliminary setup allows the intermediary to automatically authenticate and migrate credentials without requiring complex real-time trust negotiations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The intermediary system acts as a trusted mediator that centralizes trust relationship management. Instead of establishing direct trust relationships between multiple authentication systems, all trust is funneled through the intermediary, which has pre-established credentials with each system, simplifying the overall trust architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10412077B2Identity authentication migration between different authentication systems
Publication Date: 2019.09.10 CA TECH INC
  • US10412077B2 patent drawing
  • US10412077B2 patent drawing
  • US10412077B2 patent drawing

AI summary

An intermediary can securely migrate a security credential between systems despite different underlying encoding technologies used for authentication by the system. This intermediary can also securely migrate an identity between different authentication technologies. A secure login interface program code that is digitally signed by the intermediary is provided in advance to devices that will source authentication requests. The interface program code is at least secure because it has been digitally signed by the intermediary. An instance of the secure interface program code directs authentication requests entered into the interface instance to the intermediary, which is at least identified by the digital signature. After a successful authentication by a destination system identified by the authentication request, the intermediary can migrate the authenticated security credential to a migration target.