Vaulted Credential Release via Encoded Session ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Privileged Account Password Management (PAPM) systems expose vaulted credentials to users, making password sharing easy and handling insecure, as users must manually enter credentials, and require knowledge of machine names or IP addresses for access.
Innovation Solution
A method using a password management server to generate a session ID linked to a login computer and resource, which is encoded into an image displayed on a login computer, allowing a mobile device to decode and transmit the ID to the server for automatic credential release to the login computer, eliminating direct exposure and knowledge of resource identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are exposed to vaulted credentials for manual entry, then ease of operation is improved, but security deteriorates due to password sharing and insecure handling
Solution Approach 1:
The patent extracts the credential information from direct user exposure by using an encoded image displayed on the login computer. The mobile device captures this image and decodes it to obtain the session ID, which then triggers automatic credential release without the user ever seeing or typing the actual credentials. This removes the harmful exposure of credentials while maintaining operational ease.
Solution Approach 2:
The patent introduces a mobile computing device as an intermediary between the user and the credential system. Instead of the user directly interacting with credentials, the mobile device serves as a mediator that captures the encoded image, decodes the session ID, and facilitates automatic credential retrieval. This intermediary layer eliminates direct credential exposure while preserving ease of use.
2Reliability
If users must manually enter credentials, then control over credentials is improved, but time consumption increases and automation is reduced
Solution Approach 1:
The system performs preliminary actions by pre-generating and displaying the encoded image containing the session ID on the login computer before the user needs to access credentials. When the mobile device captures and decodes this pre-prepared image, the system automatically retrieves and releases the credentials without requiring manual entry, thus saving time while maintaining control.
Solution Approach 2:
The system enables self-service by automatically retrieving and releasing credentials based on the session ID obtained from the mobile device. Instead of requiring users to manually enter credentials, the system serves itself by automatically handling the credential retrieval process, reducing time consumption while maintaining security control.
3Adaptability or versatility
If users need to know machine names or IP addresses for access, then adaptability is improved, but complexity increases and user burden increases
Solution Approach 1:
The patent extracts the identification requirements from user knowledge by embedding the session ID in the encoded image that is automatically displayed on the login computer. The mobile device captures this image and decodes the session ID, which automatically associates the user with the correct resource without requiring them to know or input machine names or IP addresses, thus reducing complexity while maintaining adaptability.
4Ease of operation
If credentials are exposed to users, then ease of access is improved, but harmful factors increase due to password sharing and insecure handling
Solution Approach 1:
The patent extracts credential information from direct user exposure by using an encoded image display system. The mobile device captures the encoded image, decodes the session ID, and triggers automatic credential release without the user ever viewing or handling the actual credentials. This removes the harmful exposure while maintaining ease of access.
Solution Approach 2:
The mobile computing device serves as an intermediary that facilitates easy credential access without exposing credentials to the user. The intermediary captures the encoded image, decodes the session ID, and automatically retrieves credentials, thus providing ease of access while eliminating harmful credential exposure and sharing.
Data Source
AI summary
According to an example computer-implemented method, a password management server receives an access request message from a login computer at which a resource requiring vaulted credentials has been requested. The access request message identifies the requested resource and the login computer. A session identifier (ID) is generated for enabling release of the vaulted credentials. The session ID is linked to the login computer and to the requested resource. The session ID is transmitted to the login computer. Responsive to receiving a value indicative of the session ID from a mobile computing device, the password management server transmits the vaulted credentials to the login computer or to the mobile computing device.


