RPA Credential Vault with Encrypted Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional robotic process automation (RPA) systems face challenges in managing access controls and protecting sensitive information, particularly as the number of tasks and types of tasks increase, leading to difficulties in ensuring adequate protection and potential security breaches.

Innovation Solution

A centralized credential vault that securely stores and provisions credentials on-demand, using encryption and role-based access control to logically separate credentials from bots, allowing only encrypted references within bots, and employing a control room for credential management and dynamic provisioning, ensuring secure access and compliance with NIST standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are stored in plaintext for easy bot access, then ease of operation improves, but security deteriorates

Engineering Contradiction:
Improveease of bot accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts credentials from the bot execution environment and stores them in a separate secure credential store. The bot can only access credentials through encrypted references, not the actual credential values. This separation eliminates the security risk of plaintext storage while maintaining operational capability through the credential reference mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary credential management system that sits between the bot and the actual credentials. The bot interacts with encrypted credential references rather than plaintext credentials, and the intermediary system handles the secure retrieval and provisioning of credentials during execution, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If multiple bots share the same credentials for simplicity, then device complexity reduces, but reliability deteriorates

Engineering Contradiction:
Improvecredential management complexityVSAvoidsecurity protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments credentials into individual bot-specific credentials stored in a centralized credential store. Each bot has its own credential entry with unique encrypted references, eliminating shared credentials. This segmentation increases security and reliability while the centralized management structure keeps operational complexity manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal credential management system that serves all bots through a common interface and centralized store. While individual credentials are bot-specific for security, the management mechanism is universal and handles all credential operations, maintaining simplicity despite the segmented credential structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If credentials are encrypted and separated from bots, then security improves, but ease of operation worsens

Engineering Contradiction:
Improvecredential protectionVSAvoidcredential access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent performs preliminary encryption of credentials and stores encrypted references in the bot configuration before execution. The actual credential provisioning and decryption happens automatically during bot execution through the credential management system, eliminating manual intervention while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a self-service credential provisioning mechanism where the bot execution system automatically retrieves and provisions credentials from the encrypted store without requiring manual intervention. The system serves itself by handling the entire credential lifecycle automatically, maintaining ease of operation despite encrypted storage.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10733329B1Robotic process automation system and method with secure credential vault
Publication Date: 2020.08.04 AUTOMATION ANYWHERE INC
  • US10733329B1 patent drawing
  • US10733329B1 patent drawing
  • US10733329B1 patent drawing

AI summary

A robotic process automation system with improved security in the form of a credential vault includes data storage for storing bots. The data storage also stores credentials in encrypted form where the credentials are not associated with any of the plurality of bots. The credentials include standard credentials and user specific credentials. A processor is operatively coupled to the data storage and is configured to execute instructions that when executed cause the processor to provide to an administrator a control console. The instructions implement a standard credential generator and a user specific credential generator, to generate a user specific credential template useable by a user to enter credentials specific to the user. The instructions also implement a configurable locker that is stored in encrypted form in the data storage to associate a set of users as a group and to provide selected standard credentials to the group.