Application Authentication via Program Factors for A2A Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems often grant excessive privileges to network users, leading to exploitation by insiders and hackers, and application-to-application or application-to-database communication using hard-coded passwords is vulnerable to unauthorized access, lacking adequate security and accountability.

Innovation Solution

A security appliance manages password access by requiring registration and using program factors for authentication, generating and expiring passwords, and providing secure access control, ensuring only authorized users and applications access sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If full unrestricted superuser privileges are granted to network users, then ease of operation is improved, but security and accountability deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments superuser privileges into multiple distinct credentials (superuser password, root password, administrator password) that can be independently controlled and assigned. This allows different users to receive only the specific level of access needed for their duties rather than universal full access, resolving the contradiction between ease of operation and security by providing convenient targeted access while maintaining strong security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different privilege levels and credential types to different users based on their specific operational needs. Each user receives customized access rights appropriate to their role, allowing ease of operation for authorized tasks while preventing unauthorized access to sensitive functions, thus balancing operational convenience with security.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If privileged accounts and embedded passwords are shared among administrators, then ease of operation is improved, but accountability and security deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidaccountability
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent segments shared administrative access into individually assigned credentials, creating distinct authentication identities for each administrator. This eliminates the accountability problem of shared accounts while maintaining ease of operation through automated credential distribution and management, as each administrator has their own secure access without manual account sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service by enabling automated credential distribution and management systems that can independently generate, distribute, and revoke passwords without manual administrator intervention. This maintains ease of operation through automation while ensuring accountability by tracking which specific credential was used for each action, eliminating the need for shared accounts.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If passwords are hard-coded or embedded in calling applications, then ease of operation is improved, but security deteriorates due to vulnerability to exploitation

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts embedded passwords from application code and relocates them to a separate secure credential management system. Applications request credentials dynamically rather than having them hard-coded, which maintains ease of operation through automated retrieval while dramatically improving security by removing the vulnerability of static embedded passwords that can be viewed by anyone with source code access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary action by pre-configuring credential distribution policies and security parameters before applications need access. The security system is established in advance with defined rules for credential issuance, expiration, and revocation, allowing applications to operate conveniently with automated access while security controls are already in place to prevent exploitation.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If more scrutiny and control are implemented for privileged accounts, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing automated credential management systems that handle security scrutiny and control without requiring complex manual processes. The system automatically generates, distributes, tracks, and revokes credentials based on pre-configured policies, improving security through consistent automated enforcement while minimizing the operational complexity that would result from manual security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary credential management system that sits between users/applications and privileged resources. This intermediary handles all security scrutiny, authentication, and authorization automatically, improving security through centralized control while reducing the complexity burden on individual applications and users by abstracting away the complex security protocols into a single managed interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9160545B2Systems and methods for A2A and A2DB security using program authentication factors
Publication Date: 2015.10.13 BEYONDTRUST CORP
  • US9160545B2 patent drawing
  • US9160545B2 patent drawing
  • US9160545B2 patent drawing

AI summary

In various embodiments, security may be provided for application to application (A2A) and application to database (A2DB) implementations. In some embodiments, a method comprises receiving a registration request at a first digital device for a first application, receiving a first program factor associated with the first application, confirming the first program factor, generating a first password for a second application based, at least, on the confirmation of the first program factor, and providing the first password to a second digital.