Third-Party Breach Notification Service for Credential Reuse

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often fail to receive warnings about security breaches affecting their accounts, and those using the same credentials across multiple accounts may not realize the risk to other accounts, leading to inadequate protection.

Innovation Solution

A system and method that identify potentially affected user accounts by searching an account management database for accounts associated with a breached service provider, and perform security actions such as notifying users or changing credentials to protect at-risk accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If account providers attempt to contact all users affected by a security breach, then more users receive warnings, but some affected users still may not receive warnings and the process becomes complex

Engineering Contradiction:
Improvewarning delivery reliabilityVSAvoidbreach response system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third-party breach notification service that acts as an intermediary between service providers and users. This service aggregates breach notifications, manages user subscriptions, and handles the complexity of delivering warnings across multiple platforms, thereby improving reliability without increasing individual provider complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The notification service performs multiple functions: receiving breach notifications from various providers, storing user contact information, determining user accounts at risk by analyzing credential reuse patterns, and delivering warnings through multiple channels. This multi-functionality consolidates complexity into a single universal system

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If users receive warnings about security breaches, then users are alerted to potential risks, but users may not respond in a manner that adequately protects their sensitive information

Engineering Contradiction:
Improvesensitive information protectionVSAvoiduser response ease
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of user credentials and account patterns before a breach occurs. By pre-identifying which accounts use reused credentials and which would be affected by potential breaches, the system can immediately notify users of specific risks without requiring them to analyze complex security data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides targeted feedback to users about their specific credential reuse patterns and which accounts are at risk. This personalized feedback helps users understand the concrete risk to their information and guides them toward appropriate protective actions

Inventive Principle:
Principle #23Feedback

3Ease of operation

If users use the same username and password for multiple accounts, then account management becomes easier, but security of multiple accounts is compromised if one credential is exposed

Engineering Contradiction:
Improveaccount management easeVSAvoidaccount security reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables users to self-identify their credential reuse patterns by analyzing their stored account information. Users can see which accounts share credentials and potentially be affected by breaches, allowing them to make informed decisions about password management without external intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The breach notification service acts as an intermediary that analyzes credential patterns across a user's accounts and identifies security risks. This intermediary provides users with actionable intelligence about their security posture without requiring them to manually track their own password usage across multiple platforms

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If the system searches the account management database for all user accounts associated with a breached service provider, then all affected accounts are identified, but the searching and analysis process becomes more complex

Engineering Contradiction:
Improveaffected account identification completenessVSAvoiddatabase searching complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-organizes account data by service provider and credential pattern before breaches occur. By maintaining structured databases that link users to their accounts and analyzing credential reuse patterns in advance, the system can quickly query affected accounts during a breach without performing complex real-time analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual or simple automated searching with sophisticated data analysis that leverages stored credential patterns and account relationships. This substitution enables comprehensive identification of affected accounts through automated pattern recognition rather than brute-force searching

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9077747B1Systems and methods for responding to security breaches
Publication Date: 2015.07.07 CA TECH INC
  • US9077747B1 patent drawing
  • US9077747B1 patent drawing
  • US9077747B1 patent drawing

AI summary

A computer-implemented method for responding to security breaches may include (1) receiving a notification that a service provider has experienced a security breach, (2) identifying a first user account that is potentially affected by the security breach by identifying an account management database that stores users' account information for a plurality of different service providers and searching the account management database for user accounts associated with the service provider that experienced the security breach, and (3) performing, for the first user account that is potentially affected by the security breach, a security action that addresses the security breach. Various other methods, systems, and computer-readable media are also disclosed.