Security Continuity System with Alternate Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During security events, existing continuity systems fail to effectively manage user access, leading to chaos and potential further compromise of sensitive systems, with lost productivity being a significant cost, and they provide little protection during attacks beyond continuing to process requests or using cloud passwords.

Innovation Solution

A security continuity system that automatically provisions and manages alternate user logon identity credentials, securing primary credentials, and provides selective access through these alternate credentials, allowing continued access to user accounts while blocking unauthorized access, and can be invoked manually or automatically upon detecting security events such as account lockouts or compromises.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all users are temporarily blocked from services during a security event, then security is improved by preventing further compromise, but productivity is lost and user access is disrupted

Engineering Contradiction:
ImprovesecurityVSAvoidemployee productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments user access by creating separate credential sets: primary credentials for normal operations and alternate credentials for security events. This allows selective access control where compromised accounts can be blocked while unaffected accounts continue operating normally, preventing blanket service interruptions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary credential management layer that sits between users and services. This intermediary automatically provisions and manages alternate credentials, acting as a mediator that maintains access continuity while enforcing security policies during incidents without requiring direct user intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If primary user logon identity credentials are secured by blocking access during security events, then security is improved by preventing attacker access, but user access to essential accounts is disrupted

Engineering Contradiction:
ImprovesecurityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-provisioning alternate credentials before security events occur and automatically activating them when needed. This eliminates the need for users to manually create or request alternative access methods during critical security incidents, maintaining ease of operation while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The credential management system operates autonomously by automatically detecting security events, provisioning alternate credentials, and switching access without requiring user intervention. This self-service capability ensures that security measures are enforced while maintaining seamless user access to essential accounts.

Inventive Principle:
Principle #25Self-service

3Reliability

If alternate credentials are made difficult to guess for security, then security is improved by preventing attacker guessing, but credential complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcredential complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates alternate credentials that are functional copies of primary credentials but with enhanced security properties. These alternate credentials maintain the same user identity and access rights while using different credential values that are harder to guess, providing security improvement without requiring users to manage multiple complex credential sets manually.

Inventive Principle:
Principle #26Copying

4Reliability

If selective access is provided through alternate credentials, then security is improved by controlling what information can be accessed, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic access control where credential validity and access permissions change automatically based on security event status. During normal operations, primary credentials provide full access; during security events, the system dynamically switches to alternate credentials with selective access permissions, providing enhanced security control without requiring complex manual configuration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12255888B2Security continuity systems and methods
Publication Date: 2025.03.18 MIMECAST SERVICES LTD
  • US12255888B2 patent drawing
  • US12255888B2 patent drawing
  • US12255888B2 patent drawing

AI summary

In various exemplary embodiments, a security continuity system allows users to continue accessing certain user accounts (e.g., email, calendar, contacts, documents, instant messaging, cloud storage, etc.) through alternate logon identity credentials that are automatically provisioned such as when a security event is detected or suspected. The alternate logon identity credentials may be temporary (e.g., just used during security continuity until the original user logon identity credentials can be secured such as by establishing a new password or by having the user select a new logon identity) or permanent (e.g., the alternate logon identity can become the user's new logon identity). Security continuity may be invoked manually (e.g., by the user or by an administrator) or automatically when certain conditions are detected (e.g., through detection of suspicious activities such as repeated user lockouts due to multiple failed logon attempts or upon detection of a successful breach by an attacker).