Temporary Credential Provisioning for Secure Remote Support

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in securely granting access to their software systems to support resources for error reproduction and analysis, due to privacy concerns and lack of knowledge about the identity of the support resource requesting credentials.

Innovation Solution

A system and method where support resources can request and obtain login credentials for customer software instances through a help desk application, with automatic or manual approval processes, ensuring secure communication via VPN or encryption, and logging of all activities to maintain accountability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If support resources are granted existing user credentials to access the software system, then access efficiency is improved, but organizational privacy and security are compromised

Engineering Contradiction:
Improveaccess efficiencyVSAvoidprivacy concerns and security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the credential access process into distinct components: credential generation, secure transmission, and controlled usage. Temporary credentials are generated specifically for the support resource's incident-related access needs, transmitted securely through the application, and automatically invalidated after use or timeout, thus providing efficient access while limiting security exposure through temporal and functional segmentation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application acts as an intermediary between the support resource and the software system. Instead of directly sharing credentials, the application generates temporary credentials, transmits them securely to the support resource, and can revoke them. This intermediary role enables efficient access while maintaining security controls, as the application mediates the credential lifecycle without exposing permanent access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the organization requests credentials from support resources, then security control is improved, but access time and efficiency deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The application performs preliminary actions by automatically generating temporary credentials and transmitting them to the support resource before the support resource needs to access the software system. This preliminary credential provision eliminates the need for back-and-forth credential requests, maintaining security control through automated generation and transmission while significantly reducing access time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service credential provisioning where the application automatically generates, transmits, and manages temporary credentials without requiring manual organization approval for each access request. The support resource receives credentials automatically through the application, enabling quick access while the application maintains security control through automated credential lifecycle management

Inventive Principle:
Principle #25Self-service

3Reliability

If the organization restricts credential access to known identities, then security is improved, but the complexity of credential management increases

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The application implements feedback mechanisms by tracking credential usage, monitoring when temporary credentials are generated and transmitted to which support resource for which incident, and automatically revoking credentials after use or timeout. This automated feedback and monitoring system maintains security by ensuring credentials are used appropriately while reducing management complexity through automatic tracking and revocation rather than manual credential management

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8844004B2Automatic user credentials for remote support
Publication Date: 2014.09.23 SAP SE
  • US8844004B2 patent drawing
  • US8844004B2 patent drawing
  • US8844004B2 patent drawing

AI summary

Various embodiments herein include at least one of systems, methods, and software to receive and process credential requests for remote support of computer applications. One embodiment includes receiving a credentials request in a first environment from a second environment in response to an incident in the first environment. This embodiment further includes processing the received credentials request within the first environment by approving the request, activating credentials, and sending the credentials to the second environment. This embodiment may further include receiving, within the first environment, a message indicating the incident is resolved and deactivating the credentials.