Vaulted Credential Release via Encoded Session ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Privileged Account Password Management (PAPM) systems expose vaulted credentials to users, making password sharing easy and handling insecure, as users must manually enter credentials, and require knowledge of machine names or IP addresses for access.

Innovation Solution

A method using a password management server to generate a session ID linked to a login computer and resource, which is encoded into an image displayed on a login computer, allowing a mobile device to decode and transmit the ID to the server for automatic credential release to the login computer, eliminating direct exposure and knowledge of resource identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are exposed to vaulted credentials for manual entry, then ease of operation is improved, but security deteriorates due to password sharing and insecure handling

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential information from direct user exposure by using an encoded image displayed on the login computer. The mobile device captures this image and decodes it to obtain the session ID, which then triggers automatic credential release without the user ever seeing or typing the actual credentials. This removes the harmful exposure of credentials while maintaining operational ease.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a mobile computing device as an intermediary between the user and the credential system. Instead of the user directly interacting with credentials, the mobile device serves as a mediator that captures the encoded image, decodes the session ID, and facilitates automatic credential retrieval. This intermediary layer eliminates direct credential exposure while preserving ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users must manually enter credentials, then control over credentials is improved, but time consumption increases and automation is reduced

Engineering Contradiction:
Improvecontrol over credentialsVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-generating and displaying the encoded image containing the session ID on the login computer before the user needs to access credentials. When the mobile device captures and decodes this pre-prepared image, the system automatically retrieves and releases the credentials without requiring manual entry, thus saving time while maintaining control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically retrieving and releasing credentials based on the session ID obtained from the mobile device. Instead of requiring users to manually enter credentials, the system serves itself by automatically handling the credential retrieval process, reducing time consumption while maintaining security control.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If users need to know machine names or IP addresses for access, then adaptability is improved, but complexity increases and user burden increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the identification requirements from user knowledge by embedding the session ID in the encoded image that is automatically displayed on the login computer. The mobile device captures this image and decodes the session ID, which automatically associates the user with the correct resource without requiring them to know or input machine names or IP addresses, thus reducing complexity while maintaining adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If credentials are exposed to users, then ease of access is improved, but harmful factors increase due to password sharing and insecure handling

Engineering Contradiction:
Improveease of accessVSAvoidharmful factors
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts credential information from direct user exposure by using an encoded image display system. The mobile device captures the encoded image, decodes the session ID, and triggers automatic credential release without the user ever viewing or handling the actual credentials. This removes the harmful exposure while maintaining ease of access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile computing device serves as an intermediary that facilitates easy credential access without exposing credentials to the user. The intermediary captures the encoded image, decodes the session ID, and automatically retrieves credentials, thus providing ease of access while eliminating harmful credential exposure and sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8959583B2Access to vaulted credentials using login computer and mobile computing device
Publication Date: 2015.02.17 CA TECH INC
  • US8959583B2 patent drawing
  • US8959583B2 patent drawing
  • US8959583B2 patent drawing

AI summary

According to an example computer-implemented method, a password management server receives an access request message from a login computer at which a resource requiring vaulted credentials has been requested. The access request message identifies the requested resource and the login computer. A session identifier (ID) is generated for enabling release of the vaulted credentials. The session ID is linked to the login computer and to the requested resource. The session ID is transmitted to the login computer. Responsive to receiving a value indicative of the session ID from a mobile computing device, the password management server transmits the vaulted credentials to the login computer or to the mobile computing device.