Temporary Password System for Secure SaaS Support Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SaaS systems face security issues due to shared administrator passwords among support personnel, leading to potential misuse and complex password management, as they do not adequately identify support personnel accessing customer servers.

Innovation Solution

Implementing a temporary password system where an access control computer generates a one-time administrator password for support engineers upon request, which is then changed after access is granted or a specified time has passed, ensuring secure access without complex password management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If shared administrator passwords are used among support personnel, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the administrator password into multiple components: a static base password stored securely on the server and dynamic session-specific password portions generated for each support person and each server access. This segmentation allows individual identification and tracking while maintaining ease of use, as support personnel simply need to provide their identifier rather than manage complex passwords.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component (the access control system or module) that automatically generates, distributes, and manages the password components. This intermediary handles the complex password management tasks including generating session-specific password portions, distributing them to authorized support personnel, and automatically expiring them, thereby eliminating manual password management overhead while enhancing security through automatic rotation and expiration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique passwords are provided for each support person and server, then security is improved, but device complexity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service functionality where the access control system automatically performs all password management operations including generation, distribution, rotation, and expiration of password components. The system serves itself by automatically regenerating password portions when support personnel leave or when servers are added, eliminating the need for manual administrative intervention in password management while maintaining strong security through unique, tracked credentials for each support person-server combination.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If administrator access is granted without identification, then ease of operation is improved, but measurement precision deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidaccess identification precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies local quality by making the identification capability specific to each access context. The password structure includes components that are unique to each support person and each server, allowing precise identification of which support person accessed which server. This localized identification precision is embedded in the password itself, enabling the system to track and audit specific access events without requiring additional identification steps from support personnel.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9781102B1Managing support access in software-as-a-service systems
Publication Date: 2017.10.03 EMC IP HLDG CO LLC
  • US9781102B1 patent drawing
  • US9781102B1 patent drawing
  • US9781102B1 patent drawing

AI summary

An improved technique involves setting an administrator password in a server to a temporary password upon receipt of a request for administrator access to the server. Along these lines, when a support engineer receives a support ticket from a customer, the support engineer sends a request to obtain administrator access to the customer's server to an access control computer. The access control computer, upon receipt of the request, generates a temporary password that grants the support engineer a one-time administrator access to the server. The access control computer then changes the administrator password on the server to the temporary password and reveals the temporary password to the support engineer. At some time either after the engineer obtains administrator access to the server or after some specified time has passed, the access control computer invalidates the temporary password by changing the administrator password to a different password.