Automated Account Breach Detection and Password Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Individuals often fail to update login information after a data breach, leading to compromised security across multiple accounts, as they may not be aware of breaches affecting other websites using the same login credentials.

Innovation Solution

An account management platform identifies affected accounts by analyzing email content and reporting data breaches, prompting users to update password information across all affected applications to enhance security and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individuals manually monitor and update login information across multiple accounts, then security awareness and response to breaches improve, but time consumption and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service by having the platform automatically monitor data breaches, identify affected accounts, and notify users. This eliminates the need for users to manually track breaches across multiple services, reducing time consumption while maintaining security through automated vigilance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The platform performs multiple functions including breach monitoring, account identification, and user notification through a single integrated system. This multi-functionality consolidates what would otherwise require multiple separate tools or manual processes, reducing overall time consumption while improving security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the platform monitors and notifies users about data breaches across multiple applications, then security protection improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The platform acts as an intermediary between multiple applications and users. It consolidates breach information from various sources, processes it centrally, and delivers notifications to users. This intermediary role simplifies the overall system architecture compared to each application independently implementing its own breach monitoring and notification system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If users are prompted to update passwords across all affected applications, then unauthorized access prevention improves, but user workload and operational steps increase

Engineering Contradiction:
Improveunauthorized access riskVSAvoiduser workload
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system provides targeted feedback to users by notifying them specifically about which accounts are affected by breaches and prompting password updates only for those accounts. This feedback mechanism reduces user workload compared to requiring users to manually update all passwords, while effectively preventing unauthorized access to compromised accounts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11762979B2Management of login information affected by a data breach
Publication Date: 2023.09.19 CAPITAL ONE SERVICES LLC
  • US11762979B2 patent drawing
  • US11762979B2 patent drawing
  • US11762979B2 patent drawing

AI summary

A device determines that a data breach of an application has been reported and determines that an individual has an account with the application based on identifying an association between an application identifier and a username the individual uses to access the application. The device receives, from a user device associated with the individual, password information used to access the application. The device uses the password information and usernames for a group of applications with which the individual has accounts to perform a login procedure for the group of applications to determine that login information for one or more of the applications includes the password information used to access the application affected by the data breach. The device provides, to the user device or another device, a recommendation to change the password information used to access the application and the one or more applications.