Password Registry with Resource-Specific Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face cumbersome password management when accessing multiple resources, as they need to remember and enter unique user IDs and passwords for each resource, especially when multiple password management systems are involved.
Innovation Solution
A password registry system that securely stores encrypted passwords and associated identifying information, allowing users to manage multiple resources with varying security requirements by encrypting passwords specific to each resource and decrypting them locally for access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manage passwords for multiple resources using multiple password management systems, then each resource can have its own security requirements, but the complexity of password management increases significantly
Solution Approach 1:
The patent combines multiple password management systems into a single integrated password management system that can handle multiple resources with different security requirements. The system merges the functionality of storing and managing passwords for various resources (file system, database, application server, web server) into one unified platform, eliminating the need for users to manage separate password systems for each resource.
Solution Approach 2:
The password management system is designed with universal functionality to manage passwords for multiple types of resources simultaneously. It provides a single interface and centralized storage that can handle diverse resource types (files, databases, application servers, web servers) with varying security requirements, making the system adaptable to different authentication scenarios without requiring separate specialized systems.
2Reliability
If users remember and enter unique user IDs and passwords for each resource, then each resource maintains its own access control, but the ease of operation decreases
Solution Approach 1:
The system enables users to automatically retrieve and use their passwords for different resources through a single interface without manual intervention. The password management system stores credentials securely and provides them automatically when needed, eliminating the need for users to manually remember and enter passwords for each resource while maintaining proper access control validation.
Solution Approach 2:
The password management system acts as an intermediary between the user and multiple resources. Instead of users directly interacting with each resource's authentication mechanism, the centralized system mediates the authentication process by managing credentials and providing them to resources as needed, simplifying the user experience while maintaining security.
3Ease of operation
If a centralized password storage system is used, then password management becomes simpler, but the security risk increases if the central storage is compromised
Solution Approach 1:
The system implements local quality by allowing different encryption methods and security parameters for different resources stored in the same centralized password management system. Each resource can have its own encryption algorithm and security settings tailored to its specific requirements, so that a compromise in one resource's encryption does not necessarily expose other resources. The system applies different security characteristics to different parts of the stored data based on their specific needs.
Data Source
AI summary
A password management solution which provides a user with convenient access to multiple resources (e.g. systems and services), and also provides the flexibility to establish varying password security requirements for each resource is disclosed. In an embodiment, there is provided a password registry for registering resources and securely storing user ID and encrypted password information. An unencrypted user-provided password may be encrypted by a process associated with each resource, using an encryption algorithm specific to that resource, before storage of the encrypted password in the password registry. An encrypted password retrieved from the password registry may be decrypted by a process associated with each resource using a decryption algorithm specific to that resource.


