Single Sign-On Credential Management System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Employees in businesses face difficulties managing multiple passwords for various computer applications, leading to increased complexity and customer service delays when passwords expire or need to be reset.
Innovation Solution
A single sign-on (SSO) system, referred to as the call center dashboard, securely accesses and manages passwords for multiple applications, allowing users to log in once and automatically updating passwords as needed without user intervention, while maintaining seamless interaction with the applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each application requires separate login credentials, then application security is maintained, but user operation complexity increases and productivity decreases
Solution Approach 1:
The patent introduces a credential management service as an intermediary between users and multiple applications. This service stores application credentials securely and provides them to users who have been authenticated through a single login, thereby maintaining application security while reducing user operation complexity.
Solution Approach 2:
The credential management service performs multiple functions: it acts as an authentication gateway, a secure credential repository, and a credential distribution system. This universal service replaces the need for separate login mechanisms for each application, improving ease of operation while maintaining security through centralized control.
2Reliability
If passwords are changed periodically with strict criteria, then security is improved, but time loss increases due to frequent password changes and resets
Solution Approach 1:
The system enables users to manage their own credentials through the credential management service. When credentials need to be updated or reset, the service handles the process automatically based on predefined security policies, reducing the time users spend on password management while maintaining security requirements.
Solution Approach 2:
The credential management service pre-configures credential rotation policies and security criteria before they are needed. This allows the system to automatically enforce password change schedules and complexity requirements without requiring user intervention at the moment of change, thereby reducing time loss while maintaining security.
3Adaptability or versatility
If multiple applications are accessed separately, then application functionality is preserved, but productivity decreases due to repeated authentication
Solution Approach 1:
The patent merges the authentication processes of multiple applications into a single unified login experience. The credential management service combines credential verification for multiple applications into one authentication event, allowing users to access multiple applications without repeated authentication, thereby improving productivity while preserving application functionality.
4Device complexity
If users manage multiple passwords manually, then no additional system complexity is introduced, but ease of operation deteriorates and errors increase
Solution Approach 1:
The credential management service acts as an intermediary that users interact with through a simple interface, while the complex tasks of credential storage, retrieval, and management are handled automatically by the service. This approach improves ease of operation without requiring users to understand or manage the underlying system complexity.
Data Source
AI summary
A password management system is provided. The password management system includes a plurality of enterprise applications accessible by local and remote desktop computers by providing single sign-on security information. Each of the plurality of enterprise applications require separate login information which is stored in a secure back-end system along with the single sign-on security information. Scripts located, for example, on remotely accessible servers and/or on the local desktop computer, allow a user to logon with a single sign-on and have access to the plurality of enterprise applications. The script uses the single sign-on security information, and perhaps other information, to authenticate the user and access the login information for each of the enterprise applications. The script is further operable to automatically interface with the enterprise applications through user input windows, such as by scripting login information automatically into the enterprise application login windows.


