Account Administration System with Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing account administration systems are vulnerable to hacker intrusion as user passwords and accounts are permanently stored, leading to security risks and inconvenience for users when changing credentials.

Innovation Solution

An account administration system and method where user passwords are generated by a separate issue unit and sent to a portable communication device, which then inputs the password and account into an identification unit for authentication, ensuring that hackers must access both units to gain access, and the password is temporary and coded to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user passwords and accounts are permanently stored in the identification unit, then user authentication can be performed, but the system becomes vulnerable to hacker intrusion and data breaches

Engineering Contradiction:
Improveauthentication functionalityVSAvoidhacker intrusion risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the authentication credentials into two separate components: the account information is stored in the identification unit, while the password is generated by a separate issue unit and transmitted to a portable communication device. This segmentation ensures that hackers must compromise both the identification unit and the issue unit to obtain both credentials, significantly reducing the security risk associated with storing passwords permanently in one location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A portable communication device is introduced as an intermediary between the issue unit and the identification unit. The issue unit generates the password and sends it through this intermediary to the user's portable device, which then transmits it to the identification unit. This intermediary layer adds an additional security barrier and prevents direct access to the password storage system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If users are required to change their passwords regularly to prevent data loss, then security is improved, but user convenience deteriorates due to the troublesome nature of frequent changes

Engineering Contradiction:
Improvedata loss preventionVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The issue unit automatically generates passwords and sends them to users' portable communication devices without requiring users to manually create or change passwords. This self-service mechanism eliminates the burden of password management from users while maintaining strong security through automated, frequent password rotation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual password change process is replaced with an automated electronic system where the issue unit generates and distributes passwords through portable communication devices. This substitution transforms the mechanical process of users typing new passwords into an automated digital delivery system, greatly improving ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If a separate issue unit is introduced to generate passwords, then security against hacker intrusion is improved, but device complexity increases

Engineering Contradiction:
Improvehacker intrusion resistanceVSAvoidsystem structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The issue unit serves multiple functions: it generates passwords, transmits them securely to portable communication devices, and manages password distribution for multiple users. By consolidating these functions into a single multi-functional component, the system reduces overall complexity compared to having separate dedicated systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The password generation, transmission, and management functions are merged into a single issue unit that communicates through existing portable communication devices. This merging approach avoids the need for additional complex hardware infrastructure, as the system leverages widely available mobile devices as part of its security architecture.

Inventive Principle:
Principle #5Merging (Combining)

4Object-affected harmful factors

If user passwords are generated at real time, then hackers cannot obtain the password even if they invade the issue unit, but the system requires more complex real-time generation and transmission mechanisms

Engineering Contradiction:
Improvepassword interception riskVSAvoidreal-time generation mechanism
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements periodic password generation where the issue unit creates new passwords at regular intervals or for each authentication session. This periodic regeneration ensures that even if hackers gain access to the issue unit, they can only obtain the current password, which becomes invalid after the next generation cycle, effectively neutralizing long-term security breaches.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8582734B2Account administration system and method with security function
Publication Date: 2013.11.12 SHOOTER DIGITAL
  • US8582734B2 patent drawing
  • US8582734B2 patent drawing
  • US8582734B2 patent drawing

AI summary

An account administration system and method with security function are provided. The system comprises an identification unit, an issue unit, a portable communication device, and a identification device, wherein after the issue unit receiving the request massage from the portable communication device, a user password will be generated from the issue unit, and the user password will be sent to the portable communication device and the identification unit, thus, user can input the user password to the identification device received from the portable communication device, furthermore, according to the user account used, the identification procedure of the identification unit will exam to be passed for the identification device, such that the online access with the identification unit will be achieved.