Transparent Credential Generation for Self-Managed Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many computer systems rely on weak security credentials due to user difficulty in managing complex passwords, making them susceptible to attacks, and existing self-managed authentication mechanisms are often overlooked or inadequately utilized.

Innovation Solution

A computer security system that automatically generates and manages strong device credential data transparently to the user, using a security module integrated with the BIOS to authenticate users and control access to self-managed devices, enabling secure operations without relying on external authentication services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users provide security credentials for access control, then authentication security is improved, but user convenience deteriorates due to the need to remember and input complex passwords

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication where the authentication mechanism on the resource device automatically verifies credentials without requiring user intervention. The self-managed authentication mechanism on the resource device handles verification independently, eliminating the need for users to manually input complex passwords while maintaining strong security credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that bridges the gap between security requirements and user convenience. The self-managed authentication system acts as an intermediary that automatically handles credential verification, transparently managing the authentication process without requiring users to directly interact with complex security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users use simple familiar passwords, then ease of operation is improved, but authentication security deteriorates making the system susceptible to attacks

Engineering Contradiction:
Improveease of password inputVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The resource device incorporates a self-managed authentication mechanism that independently verifies credentials without requiring external authentication services. This self-service approach allows the system to enforce strong credential policies while automatically handling verification, preventing users from being forced to use weak passwords for convenience.

Inventive Principle:
Principle #25Self-service

3Reliability

If complex security credentials are required, then authentication security is improved, but user awareness and utilization of the authentication system deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser awareness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The self-managed authentication mechanism serves as an intermediary that transparently handles complex security credentials. By automating the verification process and making it invisible to users, the system maintains strong security requirements while improving user awareness through seamless operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system operates autonomously on the resource device, automatically verifying credentials without requiring user awareness of the underlying complexity. This self-service mechanism ensures that strong security credentials are enforced while users experience a simplified interaction model.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7581111B2System, method and apparatus for transparently granting access to a selected device using an automatically generated credential
Publication Date: 2009.08.25 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US7581111B2 patent drawing
  • US7581111B2 patent drawing
  • US7581111B2 patent drawing

AI summary

A computer security system comprises a self-managed device having an authentication system for controlling access to the self-managed device by a user. The system also comprises a security module adapted to authenticate an identity of the user and, in response to user authentication, automatically generate, transparently to the user, device credential data verifiable by the authentication system to enable user access to the self-managed device.