Role-Based Login Management for Debugging Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing login information during debugging processes in computing systems fail to adequately secure sensitive information, as IT technicians, including outside contractors, often have access to excessive data, posing security risks.

Innovation Solution

A method and system that manage login information based on designated roles and policies, allowing authorized personnel to access specific content while redacting sensitive information, with the option to upgrade authorization levels temporarily using a token with a limited time stamp for enhanced access when needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If IT technicians are given access to view all system data for debugging purposes, then debugging efficiency is improved, but information security deteriorates

Engineering Contradiction:
Improvedebugging efficiencyVSAvoidinformation security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments system data into multiple categories (sensitive information, general information, debug information) and assigns different access permissions to different technician roles. This allows technicians to access only the specific data categories needed for debugging while preventing access to sensitive information, thus resolving the contradiction between debugging efficiency and information security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different authorization levels to different technicians based on their specific debugging needs and security clearances. Each technician receives customized access permissions tailored to their role, allowing sufficient access for their debugging tasks while maintaining security constraints, thereby balancing debugging efficiency with information protection.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If system managers manually scrub sensitive information before technician login, then information security is improved, but system operation smoothness deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidsystem operation smoothness
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring data masking rules and authorization policies in advance. Sensitive information is automatically masked and filtered before technicians log in, eliminating the need for manual scrubbing operations. This automated preliminary preparation maintains information security while ensuring smooth system operations without manual intervention delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically handling sensitive information masking and filtering without requiring manual intervention from system managers. The system autonomously applies security policies, masks appropriate data fields, and manages technician access permissions, thereby maintaining security while eliminating operational bottlenecks caused by manual scrubbing processes.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If technicians are granted higher authorization levels to view more sensitive information, then debugging capability is improved, but security risk increases

Engineering Contradiction:
Improvedebugging capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamics by enabling temporary elevation of technician authorization levels only when specifically needed for debugging certain issues. The system allows dynamic adjustment of access permissions during the debugging process, granting higher clearance temporarily and then reverting to baseline security levels, thus providing enhanced debugging capability when necessary while maintaining security by limiting exposure time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies periodic action by implementing time-limited access tokens that grant technicians elevated authorization levels for specific debugging tasks. These temporary credentials are automatically revoked after a predetermined period or upon task completion, providing enhanced debugging capability during the authorized window while minimizing security risk through automatic expiration and revocation of elevated permissions.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11983289B2Method and system for managing login information during a debugging process
Publication Date: 2024.05.14 KYOCERA DOCUMENT SOLUTIONS INC
  • US11983289B2 patent drawing
  • US11983289B2 patent drawing
  • US11983289B2 patent drawing

AI summary

A method and a system for managing login information of a computing system during a debugging process are disclosed. The login information is composed according to a number of roles and their associated policies. Some roles have higher authorized levels to view sensitive information. To protect privacy, a technician who access the computing system will not be able to view all content of information. If this restriction prevents the technician to debug the system, the technician can request an upgrade. A new login information with a higher authorized level will be temporarily granted to the technician that allows the technician to view and access more content of information.