Software Product Credential Management for Secure Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing security credentials for access to resources in a distributed computing environment is time-consuming and difficult, especially when customers purchase or cancel software products, requiring frequent updates to ensure only authorized access.
Innovation Solution
Implementing a system where software providers authorize software products to access resources based on subscriptions, using access policies and temporary security credentials that expire automatically, eliminating the need for individual customer credential management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual security credentials are assigned to each customer, then access control security is improved, but credential management complexity and time consumption increase
Solution Approach 1:
The patent merges individual customer credentials with software product credentials. Instead of managing separate credentials for each customer, the system combines them into a unified credential structure where the software product credential serves as the access authority for all customers subscribed to that product.
Solution Approach 2:
The software product credential is designed to serve multiple functions: it acts as both the software product's own credential and as the authorization basis for all customers who purchase or subscribe to the software product. This universal credential eliminates the need for individual customer credentials.
2Reliability
If access control lists are updated frequently when customers purchase or cancel products, then access authorization accuracy is improved, but administrative time consumption increases
Solution Approach 1:
The system performs preliminary configuration by associating software product credentials with resource access permissions in advance. When customers purchase or cancel products, the credential service automatically updates access control lists based on these pre-configured associations, eliminating the need for manual administrative updates.
Solution Approach 2:
The credential service implements automated feedback loops that monitor customer purchase and cancellation events, then automatically update access control lists accordingly. This closed-loop system ensures access authorization remains accurate without requiring manual administrative intervention.
3Reliability
If temporary security credentials with automatic expiration are used, then security is improved, but credential validity management complexity increases
Solution Approach 1:
The credential service implements self-service functionality where temporary security credentials automatically expire based on predefined conditions such as software product cancellation or subscription expiration. The system autonomously manages credential validity periods without requiring manual intervention, and automatically revokes access when expiration conditions are met.
4Measurement precision
If manual credential updates are performed for each customer, then access control precision is improved, but productivity decreases
Solution Approach 1:
The credential service acts as an intermediary between customer purchase/cancellation events and access control list updates. It automatically processes credential issuance, renewal, and revocation based on software product licensing status, maintaining precise access control while eliminating manual administrative work.
Data Source
AI summary
Functionality is disclosed herein for providing temporary access to a resource. A software product that is executing in response to a request from a customer may access one or more resources of a software provider. The resources that may be accessed by a software product may be identified within an access policy. The customer is prevented from accessing the resource when the software product is not executing.


