RPA Credential Vault with Encrypted Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional robotic process automation (RPA) systems face challenges in managing access controls and protecting sensitive information, particularly as the number of tasks and types of tasks increase, leading to difficulties in ensuring adequate protection and potential security breaches.
Innovation Solution
A centralized credential vault that securely stores and provisions credentials on-demand, using encryption and role-based access control to logically separate credentials from bots, allowing only encrypted references within bots, and employing a control room for credential management and dynamic provisioning, ensuring secure access and compliance with NIST standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are stored in plaintext for easy bot access, then ease of operation improves, but security deteriorates
Solution Approach 1:
The patent extracts credentials from the bot execution environment and stores them in a separate secure credential store. The bot can only access credentials through encrypted references, not the actual credential values. This separation eliminates the security risk of plaintext storage while maintaining operational capability through the credential reference mechanism.
Solution Approach 2:
The patent introduces an intermediary credential management system that sits between the bot and the actual credentials. The bot interacts with encrypted credential references rather than plaintext credentials, and the intermediary system handles the secure retrieval and provisioning of credentials during execution, resolving the contradiction between accessibility and security.
2Device complexity
If multiple bots share the same credentials for simplicity, then device complexity reduces, but reliability deteriorates
Solution Approach 1:
The patent segments credentials into individual bot-specific credentials stored in a centralized credential store. Each bot has its own credential entry with unique encrypted references, eliminating shared credentials. This segmentation increases security and reliability while the centralized management structure keeps operational complexity manageable.
Solution Approach 2:
The patent creates a universal credential management system that serves all bots through a common interface and centralized store. While individual credentials are bot-specific for security, the management mechanism is universal and handles all credential operations, maintaining simplicity despite the segmented credential structure.
3Object-affected harmful factors
If credentials are encrypted and separated from bots, then security improves, but ease of operation worsens
Solution Approach 1:
The patent performs preliminary encryption of credentials and stores encrypted references in the bot configuration before execution. The actual credential provisioning and decryption happens automatically during bot execution through the credential management system, eliminating manual intervention while maintaining security.
Solution Approach 2:
The patent implements a self-service credential provisioning mechanism where the bot execution system automatically retrieves and provisions credentials from the encrypted store without requiring manual intervention. The system serves itself by handling the entire credential lifecycle automatically, maintaining ease of operation despite encrypted storage.
Data Source
AI summary
A robotic process automation system with improved security in the form of a credential vault includes data storage for storing bots. The data storage also stores credentials in encrypted form where the credentials are not associated with any of the plurality of bots. The credentials include standard credentials and user specific credentials. A processor is operatively coupled to the data storage and is configured to execute instructions that when executed cause the processor to provide to an administrator a control console. The instructions implement a standard credential generator and a user specific credential generator, to generate a user specific credential template useable by a user to enter credentials specific to the user. The instructions also implement a configurable locker that is stored in encrypted form in the data storage to associate a set of users as a group and to provide selected standard credentials to the group.


