Temporary Password System for Secure SaaS Support Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SaaS systems face security issues due to shared administrator passwords among support personnel, leading to potential misuse and complex password management, as they do not adequately identify support personnel accessing customer servers.
Innovation Solution
Implementing a temporary password system where an access control computer generates a one-time administrator password for support engineers upon request, which is then changed after access is granted or a specified time has passed, ensuring secure access without complex password management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If shared administrator passwords are used among support personnel, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent segments the administrator password into multiple components: a static base password stored securely on the server and dynamic session-specific password portions generated for each support person and each server access. This segmentation allows individual identification and tracking while maintaining ease of use, as support personnel simply need to provide their identifier rather than manage complex passwords.
Solution Approach 2:
The patent introduces an intermediary component (the access control system or module) that automatically generates, distributes, and manages the password components. This intermediary handles the complex password management tasks including generating session-specific password portions, distributing them to authorized support personnel, and automatically expiring them, thereby eliminating manual password management overhead while enhancing security through automatic rotation and expiration.
2Reliability
If unique passwords are provided for each support person and server, then security is improved, but device complexity deteriorates
Solution Approach 1:
The system implements self-service functionality where the access control system automatically performs all password management operations including generation, distribution, rotation, and expiration of password components. The system serves itself by automatically regenerating password portions when support personnel leave or when servers are added, eliminating the need for manual administrative intervention in password management while maintaining strong security through unique, tracked credentials for each support person-server combination.
3Ease of operation
If administrator access is granted without identification, then ease of operation is improved, but measurement precision deteriorates
Solution Approach 1:
The patent applies local quality by making the identification capability specific to each access context. The password structure includes components that are unique to each support person and each server, allowing precise identification of which support person accessed which server. This localized identification precision is embedded in the password itself, enabling the system to track and audit specific access events without requiring additional identification steps from support personnel.
Data Source
AI summary
An improved technique involves setting an administrator password in a server to a temporary password upon receipt of a request for administrator access to the server. Along these lines, when a support engineer receives a support ticket from a customer, the support engineer sends a request to obtain administrator access to the customer's server to an access control computer. The access control computer, upon receipt of the request, generates a temporary password that grants the support engineer a one-time administrator access to the server. The access control computer then changes the administrator password on the server to the temporary password and reveals the temporary password to the support engineer. At some time either after the engineer obtains administrator access to the server or after some specified time has passed, the access control computer invalidates the temporary password by changing the administrator password to a different password.


