Centralized Password Center Table for Database Rekeying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing database systems face difficulties in efficiently and accurately updating encrypted passwords and encryption keys across various datastores, leading to error-prone and complex rekey logic due to different storage mechanisms and scattered password locations.

Innovation Solution

Implementing a centralized password management system using a password center table that stores password reference identifiers, which are automatically replaced with actual encrypted passwords at runtime, eliminating the need to update each datastore individually and simplifying the rekey process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If passwords are stored in multiple datastores with different storage mechanisms, then password management flexibility is improved, but updating passwords becomes complex and error-prone

Engineering Contradiction:
Improvepassword storage flexibilityVSAvoidpassword update complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a password center table as an intermediary component between the application server and multiple datastores. This central repository stores master encrypted passwords and serves as the single source of truth, eliminating the need to update passwords in multiple scattered datastores simultaneously. The password center table mediates password distribution to child datastores, simplifying the update process while maintaining support for diverse storage mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments password management into two distinct layers: a centralized password center table for master password storage and management, and multiple child datastores for localized password caching. This segmentation allows each layer to have specialized functions - the password center handles updates and master control, while child datastores handle local access - thereby reducing update complexity while preserving storage flexibility.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encrypted passwords are updated periodically for security reasons, then security is improved, but processing overhead increases due to parsing large CLOB columns

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the password management function from the large CLOB column structure and concentrates it in the password center table. By taking out password data from scattered locations and centralizing it, the system eliminates the need to parse large CLOB columns during password updates. Only the compact password center table needs to be updated, significantly reducing processing overhead while maintaining security through periodic encryption key rotation.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If passwords are stored scattered across different datastores, then data distribution flexibility is improved, but accuracy of password updates deteriorates

Engineering Contradiction:
Improvedata distribution flexibilityVSAvoidpassword update accuracy
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The password center table acts as an intermediary that ensures accurate password distribution to all child datastores. It maintains the master copy of encrypted passwords and systematically distributes updates to all connected datastores, ensuring consistency and accuracy across the distributed system while preserving the flexibility of having passwords distributed across multiple storage locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9584324B2Centralized datastore password management
Publication Date: 2017.02.28 SAP SE
  • US9584324B2 patent drawing
  • US9584324B2 patent drawing
  • US9584324B2 patent drawing

AI summary

According to some embodiments, an application server may have a repository to facilitate a transfer of data between data storage elements. A datastore may be stored in the repository for a data storage element, the datastore including a password reference identifier. A password center table may be created in the repository to associate the password reference identifier with an actual encrypted password for the data storage element. At execution time, the password reference identifier in the datastore may be automatically replaced with the actual encrypted password for the data storage element.