Auto-generated Application Passwords for Third-Party Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in allowing third-party applications to access user accounts securely, particularly when two-factor authentication or on-demand passwords are enabled, leading to login failures and user confusion, as these applications are not compatible with modern authentication mechanisms.

Innovation Solution

A server-generated application password is automatically created and stored for trusted client devices, enabling third-party applications to log in to user accounts without satisfying traditional authentication processes, by determining the device's trust status based on historical login data and user authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication or on-demand passwords are enabled for user accounts, then security is improved, but third-party applications cannot log in successfully

Engineering Contradiction:
ImprovesecurityVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication mechanism by creating a dedicated application password separate from the main user password and two-factor authentication flow. This allows third-party applications to use a specialized authentication path (application password) while the user account maintains strong security through the primary password and two-factor authentication for human users.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If traditional password authentication is used, then third-party applications can log in easily, but security is compromised when modern authentication mechanisms are implemented

Engineering Contradiction:
Improveapplication compatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The application password serves as an intermediary authentication mechanism between third-party applications and the user account. It mediates the authentication process by providing a dedicated password format that applications can use without interfering with the security-enhancing two-factor authentication and on-demand password features.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual password entry is required for applications, then user control is maintained, but user experience deteriorates due to complexity and confusion

Engineering Contradiction:
Improveuser experienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables self-service by automatically generating and managing application passwords without requiring manual user intervention. The server autonomously creates, distributes, and rotates application passwords, freeing users from the burden of manually managing multiple passwords while maintaining security through automated credential management.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If application passwords are automatically generated and managed, then ease of operation is improved, but system complexity increases

Engineering Contradiction:
Improveautomated password managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of password generation and management from the user side and relocates it to the server side. Users experience simplicity because all password operations are handled automatically by the server, which manages the generation, distribution, rotation, and revocation of application passwords without user involvement.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10447692B2Auto-creation of application passwords
Publication Date: 2019.10.15 VERIZON PATENT & LICENSING INC
  • US10447692B2 patent drawing
  • US10447692B2 patent drawing
  • US10447692B2 patent drawing

AI summary

In one embodiment, an attempt to log in to a user account, by an application on a client device, is detected. It is determined whether the client device is a trusted device. An application password is generated and stored, by a server, in association with the client device and the user account based, at least in part, upon whether the client device is a trusted device.