Temporary Credential Provisioning for Secure Remote Support
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in securely granting access to their software systems to support resources for error reproduction and analysis, due to privacy concerns and lack of knowledge about the identity of the support resource requesting credentials.
Innovation Solution
A system and method where support resources can request and obtain login credentials for customer software instances through a help desk application, with automatic or manual approval processes, ensuring secure communication via VPN or encryption, and logging of all activities to maintain accountability and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If support resources are granted existing user credentials to access the software system, then access efficiency is improved, but organizational privacy and security are compromised
Solution Approach 1:
The patent segments the credential access process into distinct components: credential generation, secure transmission, and controlled usage. Temporary credentials are generated specifically for the support resource's incident-related access needs, transmitted securely through the application, and automatically invalidated after use or timeout, thus providing efficient access while limiting security exposure through temporal and functional segmentation
Solution Approach 2:
The application acts as an intermediary between the support resource and the software system. Instead of directly sharing credentials, the application generates temporary credentials, transmits them securely to the support resource, and can revoke them. This intermediary role enables efficient access while maintaining security controls, as the application mediates the credential lifecycle without exposing permanent access
2Reliability
If the organization requests credentials from support resources, then security control is improved, but access time and efficiency deteriorate
Solution Approach 1:
The application performs preliminary actions by automatically generating temporary credentials and transmitting them to the support resource before the support resource needs to access the software system. This preliminary credential provision eliminates the need for back-and-forth credential requests, maintaining security control through automated generation and transmission while significantly reducing access time
Solution Approach 2:
The system implements self-service credential provisioning where the application automatically generates, transmits, and manages temporary credentials without requiring manual organization approval for each access request. The support resource receives credentials automatically through the application, enabling quick access while the application maintains security control through automated credential lifecycle management
3Reliability
If the organization restricts credential access to known identities, then security is improved, but the complexity of credential management increases
Solution Approach 1:
The application implements feedback mechanisms by tracking credential usage, monitoring when temporary credentials are generated and transmitted to which support resource for which incident, and automatically revoking credentials after use or timeout. This automated feedback and monitoring system maintains security by ensuring credentials are used appropriately while reducing management complexity through automatic tracking and revocation rather than manual credential management
Data Source
AI summary
Various embodiments herein include at least one of systems, methods, and software to receive and process credential requests for remote support of computer applications. One embodiment includes receiving a credentials request in a first environment from a second environment in response to an incident in the first environment. This embodiment further includes processing the received credentials request within the first environment by approving the request, activating credentials, and sending the credentials to the second environment. This embodiment may further include receiving, within the first environment, a message indicating the incident is resolved and deactivating the credentials.


