Authentication Clearinghouse for Password Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network technologies lack effective mechanisms to detect and respond to compromised authentication information in real-time, leaving users vulnerable to malicious attacks and failing to provide adequate security measures to protect personal and monetary information.

Innovation Solution

Implementing a password fraud detection system that monitors and compares password frequency of use across accounts, flagging potentially compromised accounts and requiring additional authentication measures, such as CAPTCHA or security questions, to prevent unauthorized access, while maintaining separate data stores for frequency and password data to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used to protect consumer information, then basic security is provided, but real-time detection and response to compromised authentication information is lacking

Engineering Contradiction:
Improveaccount securityVSAvoiddetection capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by maintaining a proactive watch list of compromised authentication information and proactively comparing user credentials against this list before allowing account access, rather than waiting for security breaches to occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops by monitoring authentication attempts, updating the watch list with newly compromised credentials, and immediately using this updated information to protect against future attacks, creating a dynamic security response mechanism

Inventive Principle:
Principle #23Feedback

2Reliability

If password frequency monitoring is implemented across accounts, then compromised accounts can be identified, but system complexity increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments authentication security by maintaining separate data stores for password information and frequency-of-use information, allowing independent management and analysis of each data type while reducing the complexity of managing a single monolithic authentication system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication information clearinghouse that acts as a mediator between individual account systems, collecting and analyzing password frequency data from multiple sources without requiring direct integration between the accounts themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If additional authentication measures are required for flagged accounts, then unauthorized access is prevented, but user convenience decreases

Engineering Contradiction:
Improvemalicious accessVSAvoiduser access process
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies partial authentication measures by requiring additional verification steps only for accounts flagged as potentially compromised, while allowing standard authentication for accounts that pass security checks, thus balancing security with user convenience

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10223524B1Compromised authentication information clearing house
Publication Date: 2019.03.05 AMAZON TECH INC
  • US10223524B1 patent drawing
  • US10223524B1 patent drawing
  • US10223524B1 patent drawing

AI summary

Techniques for maintaining potentially compromised authentication information for a plurality of accounts may be provided. An individual piece of authentication information may be associated with one or more tags that indicate access rights with respect to requestors that also provide and maintain other potentially compromised authentication information. A subset of the potentially compromised authentication information may be determined based on the one or more tags in response to a request from a requestor for the potentially compromised authentication information. In an embodiment, the subset of the potentially compromised authentication information may be provided to the requestor.