Role Account Credential Management for Secure Remote Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In managed networks, remote product update operations are often hindered by the requirement for administrative credentials and secure tokens, which are not always accessible, leading to vulnerabilities and outdated software due to limited access and centralized control via Mobile Device Management (MDM) services.
Innovation Solution
A method that initiates and implements product updates by scanning endpoints for relevant updates, checking for existing role accounts, obtaining user credentials if necessary, generating new role accounts with administrative privileges, and decrypting credentials to execute remediation operations, ensuring secure and remote management of credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrative credentials and secure tokens are required for product updates, then security is improved, but remote update capability deteriorates
Solution Approach 1:
The patent introduces an intermediary role account that acts as a mediator between the administrative credentials and the product update operation. The role account stores credentials securely and provides controlled access without requiring direct credential exposure, enabling remote updates while maintaining security through the intermediary layer.
Solution Approach 2:
The patent segments the authentication process by separating the credential storage (role account) from the update execution. The role account is created as a distinct entity that holds the necessary credentials, allowing the update operation to proceed without direct access to the original administrative credentials, thus resolving the contradiction between security and remote capability.
2Reliability
If MDM service is used for centralized control, then security is improved, but update coverage deteriorates
Solution Approach 1:
The role account mechanism serves multiple functions: it works within MDM-managed endpoints and also on non-MDM endpoints. This universal approach allows the same credential management system to function across diverse endpoint types, improving update coverage while maintaining the security benefits of centralized credential control where applicable.
Solution Approach 2:
The system enables self-service credential management through role accounts that can be automatically created and configured. The endpoint can locally manage its own credential access through the role account without requiring continuous MDM intervention, allowing updates to proceed on both MDM-managed and non-MDM-managed endpoints.
3Reliability
If direct user intervention is required for updates, then security is improved, but update efficiency deteriorates
Solution Approach 1:
The role account is created in advance with the necessary credentials and permissions stored securely. This preliminary action eliminates the need for direct user intervention during the actual update process, as the pre-configured role account can automatically authenticate and execute updates, maintaining security while improving efficiency.
Solution Approach 2:
The update system uses self-service automation through the role account mechanism, where credentials are automatically provided to the update process without requiring direct user input or intervention. The role account autonomously handles authentication and authorization, enabling unattended updates while preserving security controls.
Data Source
AI summary
A method of product update management in systems having product access restrictions associated with administrative credentials includes detecting that an operating system (OS) update is outstanding at an endpoint. The method includes communicating a request for an OS update to the endpoint and determining whether it is enrolled in a mobile device management (MDM) environment. If the endpoint is enrolled in the MDM environment, the method includes communicating a request for an MDM call to an MDM module of a management device. The MDM module includes authority to initiate the OS update. The method includes queuing and scheduling an OS update command with an MDM requester. The method includes communicating, by the MDM requester, an update command to a vendor agent of the endpoint. The method includes interfacing with a third party update service to retrieve an OS update and communicating with the OS to initiate installation the OS update.


