Unified Credential Processing for Disparate Security Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and access control systems face complexity when interacting with resources across disparate security domains, requiring different credentials and protocols, which hinders single sign-on convenience and efficient resource management.

Innovation Solution

A method and system for unified credential processing, involving a discovery profile that specifies resource types and authentication protocols, and a credential transformation service (CTS) to map and transform authentication credentials across security domains, enabling secure access to resources without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different authentication credentials are used for each security domain, then security requirements for each domain are met, but system complexity and user authentication burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a credential transformation service as an intermediary component that sits between the user and multiple security domains. This service automatically transforms credentials from one security domain to another, eliminating the need for users to manually manage multiple credentials while maintaining the security requirements of each domain. The transformation service acts as a mediator that handles the complexity of credential mapping and transformation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal credential transformation service that can handle multiple security domains and various credential types through a single interface. This multi-functional service can transform credentials across different security domains, protocols, and formats, providing a universal solution that replaces multiple domain-specific authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication credentials are required for different security domains, then domain-specific security protocols are satisfied, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The credential transformation service operates autonomously to transform credentials without requiring user intervention. The service automatically detects the source and target security domains, retrieves appropriate credentials, performs the transformation, and delivers the transformed credentials back to the user or system, all without manual input from the end user.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The transformation service mediates between the user's single credential set and the multiple domain-specific credential requirements, automatically handling the translation and transformation processes in the background while the user experiences a simplified single-sign-on interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If credential transformation services are implemented across multiple security domains, then single sign-on capability is achieved, but device complexity increases

Engineering Contradiction:
Improvesingle sign-on capabilityVSAvoidcredential transformation infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple credential transformation functions into a single unified service that handles credential transformation across all security domains. By combining what would otherwise be multiple separate transformation services into one centralized component, the system achieves single sign-on capability while consolidating rather than multiplying the complexity infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9131008B2Discovery profile based unified credential processing for disparate security domains
Publication Date: 2015.09.08 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9131008B2 patent drawing
  • US9131008B2 patent drawing
  • US9131008B2 patent drawing

AI summary

A method for discovery profile based unified credential processing for disparate security domains can include loading a discovery profile specifying types of manageable resources to be discovered during discovery of manageable resources and authentication protocols for use in accessing each type of the resources. The method also can include discovering the resources across disparate security domains and selecting a discovered one of the resources in a particular one of the security domains for a systems management task. The method further can include transforming an authentication credential not specific to the particular one of the security domains to a mapped authentication credential specific to the particular one of the security domains and authenticating into the particular one of the security domains with the mapped authentication credential utilizing an authentication protocol specified by the profile in order to perform the systems management task on the selected discovered one of the resources.