Vaulted Credential Access via Encoded Image and Approval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Privileged account password management systems expose credentials to users, making them vulnerable to sharing and insecure, and require users to know specific machine names or IP addresses for access, which can be problematic in dynamic environments.
Innovation Solution
A method involving a password management server that generates a session ID linked to a login computer and a requested resource, using encoded images displayed on a login computer for mobile devices to obtain vaulted credentials without exposing them to the user, and an approval process for authorization when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are exposed to users for manual entry, then ease of operation is improved, but security deteriorates due to vulnerability of sharing and exposure
Solution Approach 1:
The patent extracts the credential information from the user's direct view and stores it in a secure vault on the server. The user interacts with the system through a mobile device that displays an encoded image containing the credentials, but the actual credential data remains protected in the vault, preventing direct exposure and sharing while maintaining ease of access.
Solution Approach 2:
The patent introduces a mobile computing device as an intermediary between the user and the credential vault. The mobile device displays an encoded image that serves as a mediator to convey credential information without exposing the raw credentials. This intermediary layer maintains security by preventing direct credential exposure while enabling user access.
2Measurement precision
If users must know specific machine names or IP addresses for access, then access control precision is improved, but ease of operation deteriorates in dynamic environments
Solution Approach 1:
The patent implements a universal access mechanism where the mobile computing device serves multiple functions: displaying the encoded image, capturing user input, and communicating with the server. This multi-functional approach eliminates the need for users to manually enter machine names or IP addresses, as the system automatically handles the authentication process across different devices and environments.
Solution Approach 2:
The system performs self-service by automatically generating and displaying the encoded image on the mobile device, automatically capturing user input through the mobile device's interface, and automatically processing the authentication with the server. This eliminates manual configuration requirements and simplifies operation in dynamic environments where machine identifiers may change.
Data Source
AI summary
In an example computer-implemented method, a password management (PM) server receives an access request message from a login computer at which a resource requiring vaulted credentials has been requested. The access request message identifies the requested resource and the login computer. A session identifier (ID) is generated that is linked to the login computer and to the requested resource, and is transmitted to the login computer. The PM server receives, from a mobile computing device, a user ID and a value indicative of the session ID. If the user ID is not authorized to access the requested resource, the PM server transmits the vaulted credentials to the login computer or the mobile computing device only if an approval message indicative of a confirmation code is received from a manager computing device authorizing release of the vaulted credentials for the user ID.


