Network Configuration Password Encryption and Temporary Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current configuration management systems face challenges in securely managing and synchronizing passwords for multiple configuration items across a network, requiring stringent security measures and significant administrative effort.
Innovation Solution
A computer system and method that encrypts passwords within the configuration information collection system only during temporary access, using an ID management system to encrypt and decrypt passwords with a decryption system, ensuring secure storage and reduced administrative burden by not storing unencrypted passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords are stored in unencrypted form for easy access, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent applies parameter changes by transforming passwords from plain text form to encrypted form, changing the state of the password data. The system encrypts passwords before storage and only decrypts them temporarily when access is required, then re-encrypts them. This parameter transformation resolves the contradiction by maintaining security while enabling operational access.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism that acts as a mediator between password storage and password access. The encryption/decryption process serves as an intermediary layer that allows the system to maintain secure storage while providing controlled access when needed, thus resolving the contradiction between security and ease of operation.
2Reliability
If stringent security protocols are implemented for password management, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent applies self-service by implementing automatic encryption and decryption processes that occur without manual intervention. The system automatically encrypts passwords when storing them, decrypts them only when necessary for access, and then re-encrypts them. This automation reduces the complexity of security management while maintaining high security standards.
Solution Approach 2:
The patent applies preliminary action by pre-encrypting passwords before they are stored in the system. This preliminary encryption step ensures that passwords are secured before any potential security threats can occur, and the system only temporarily decrypts them when absolutely necessary, minimizing exposure time and reducing overall security management complexity.
3Productivity
If passwords are continuously stored in decrypted state for quick access, then productivity is improved, but security is worsened
Solution Approach 1:
The patent applies periodic action by implementing a rhythm of encryption and decryption that occurs only when necessary. Passwords are encrypted continuously during storage, then periodically decrypted only when access is required, and immediately re-encrypted afterward. This periodic decryption approach maintains security while providing productivity when needed.
Solution Approach 2:
The patent applies skipping by rapidly decrypting passwords only for the minimum necessary time to perform the required access operation, then immediately re-encrypting them. This rushing through the decrypted state minimizes the time passwords are vulnerable while still allowing productive access when needed, thus resolving the contradiction between productivity and security.
Data Source
AI summary
Disclosed embodiments include a method for receiving, at a configuration information server, an encrypted password associated with a configuration item, where the encrypted password is encrypted using an encryption key. The method further includes encrypting a decrypted password to generate a reencrypted password, where the decrypted password is derived from the encrypted password. The method further includes transmitting the reencrypted password to the configuration item and removing the decrypted password from the configuration information collection server.


