Self-service Portal for Passwordless Host Access Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key management systems cannot manage cryptographic access control keys for client computers that are not accessible remotely, limiting their use to managed networks where client computers are not under key management system control.
Innovation Solution
A method and apparatus for managing access to hosts in a computerized system, where a user requests an authenticator through a portal, which verifies the user's authorization and sends the request to an authenticator manager only after acceptance by an administration process following predefined rules, enabling access to hosts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a key management system is used to manage cryptographic access control keys, then centralized and controlled key management is achieved, but client computers that are not accessible remotely cannot be managed
Solution Approach 1:
The patent introduces a key backup service as an intermediary component that bridges the gap between the key management system and unmanaged client computers. This service runs locally on client machines (whether managed or unmanaged) and acts as a mediator, allowing the key management system to indirectly access and manage cryptographic keys on clients through standardized interfaces without requiring direct control or remote access capabilities.
Solution Approach 2:
The key backup service is designed with universal functionality to work across different types of client computers regardless of their management status. It provides a standardized interface that can be implemented on any client machine, enabling the key management system to manage keys uniformly across both managed and unmanaged clients, thus achieving multi-functionality and broad applicability.
2Ease of operation
If remote management procedures are implemented on client computers, then centralized control is improved, but personal property computers of employees or freelancers cannot be managed
Solution Approach 1:
The key backup service acts as a local intermediary that enables key management functionality without requiring the client computer to be under remote management control. This service runs autonomously on the client machine and communicates with the key management system through standardized interfaces, allowing personal devices to participate in centralized key management without submitting to remote management procedures.
Solution Approach 2:
The key backup service implements self-service functionality by automatically managing cryptographic keys locally on the client computer. It can generate, store, backup, and manage keys without requiring external intervention or remote management capabilities, while still integrating with the centralized key management system through standardized interfaces.
3Reliability
If direct control over client computers is required for key management, then security control is improved, but the system cannot work with unmanaged clients
Solution Approach 1:
The key backup service serves as a trusted intermediary that enables secure key management without requiring direct control over the client computer. It runs locally on the client machine and maintains security through cryptographic best practices, while acting as a bridge between the unmanaged client and the key management system, thus preserving security control while supporting unmanaged networks.
4Ease of operation
If a portal-based self-service system is implemented, then user autonomy is improved, but additional authorization layers are required
Solution Approach 1:
The system performs preliminary authorization actions by pre-configuring user permissions and policies in the key management system. When users access the portal, their authorization status is already determined based on pre-established rules and policies, allowing them to self-service key management operations without encountering complex real-time authorization decisions.
Data Source
AI summary
Methods and apparatuses for managing access to hosts in a computerized system are disclosed. A request for an authenticator for enabling access to at least one host in the computerized system is communicated from an user to a portal. The portal verifies the right of the user to make the request, and in response to positive verification authorizes the user to make the request and sends the request to an authenticator manager to trigger providing of an authenticator for enabling access to at least one host in accordance with the request. The authenticator manager provides the authenticator for enabling access to the at least one host in accordance with the request. Acceptance of the request by an administration process according a predefined rule is required before said providing of the authenticator.


