Vaulted Credential Access via Encoded Image and Approval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Privileged account password management systems expose credentials to users, making them vulnerable to sharing and insecure, and require users to know specific machine names or IP addresses for access, which can be problematic in dynamic environments.

Innovation Solution

A method involving a password management server that generates a session ID linked to a login computer and a requested resource, using encoded images displayed on a login computer for mobile devices to obtain vaulted credentials without exposing them to the user, and an approval process for authorization when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are exposed to users for manual entry, then ease of operation is improved, but security deteriorates due to vulnerability of sharing and exposure

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential information from the user's direct view and stores it in a secure vault on the server. The user interacts with the system through a mobile device that displays an encoded image containing the credentials, but the actual credential data remains protected in the vault, preventing direct exposure and sharing while maintaining ease of access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a mobile computing device as an intermediary between the user and the credential vault. The mobile device displays an encoded image that serves as a mediator to convey credential information without exposing the raw credentials. This intermediary layer maintains security by preventing direct credential exposure while enabling user access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If users must know specific machine names or IP addresses for access, then access control precision is improved, but ease of operation deteriorates in dynamic environments

Engineering Contradiction:
Improveaccess control precisionVSAvoidease of operation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements a universal access mechanism where the mobile computing device serves multiple functions: displaying the encoded image, capturing user input, and communicating with the server. This multi-functional approach eliminates the need for users to manually enter machine names or IP addresses, as the system automatically handles the authentication process across different devices and environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-service by automatically generating and displaying the encoded image on the mobile device, automatically capturing user input through the mobile device's interface, and automatically processing the authentication with the server. This eliminates manual configuration requirements and simplifies operation in dynamic environments where machine identifiers may change.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8997195B1Access to vaulted credentials using login computer, mobile computing device, and manager computing device
Publication Date: 2015.03.31 CA TECH INC
  • US8997195B1 patent drawing
  • US8997195B1 patent drawing
  • US8997195B1 patent drawing

AI summary

In an example computer-implemented method, a password management (PM) server receives an access request message from a login computer at which a resource requiring vaulted credentials has been requested. The access request message identifies the requested resource and the login computer. A session identifier (ID) is generated that is linked to the login computer and to the requested resource, and is transmitted to the login computer. The PM server receives, from a mobile computing device, a user ID and a value indicative of the session ID. If the user ID is not authorized to access the requested resource, the PM server transmits the vaulted credentials to the login computer or the mobile computing device only if an approval message indicative of a confirmation code is received from a manager computing device authorizing release of the vaulted credentials for the user ID.