Credential Lock Status Token Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current username/password credential validation methods are inadequate for secure online account protection, especially with the rise of identity theft, as they rely on single-factor authorization and are vulnerable to unauthorized access.
Innovation Solution
A system and method that employs an access control mechanism to lock or unlock sets of credentials, requiring users to perform predefined protocols before accessing accounts, and includes an automatic account protection check to validate the authenticity of requests, using tokens to determine whether to proceed with authentication or invalidate access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single-factor username/password authentication is used, then ease of operation is improved, but account security deteriorates
Solution Approach 1:
The patent segments the authentication process into multiple independent factors (knowledge-based credentials, possession-based tokens, and biometric verification) that must all be satisfied. This multi-factor segmentation ensures that compromise of one factor does not lead to complete system failure, thereby improving account security while maintaining operational ease through automated verification.
Solution Approach 2:
The system performs preliminary account protection checks and credential validation before granting access. Tokens are pre-issued and verified in advance, and the system proactively monitors for compromised credentials. This preliminary action prevents unauthorized access before it can occur, enhancing security without adding significant operational burden during the actual authentication moment.
2Reliability
If credential validation tracking is continuous, then account security is improved, but system complexity increases
Solution Approach 1:
The patent introduces a token-based intermediary system that mediates between the authentication request and the credential validation process. Tokens serve as portable, verifiable credentials that can be checked without requiring continuous tracking of the entire authentication state. This intermediary mechanism simplifies the system architecture while maintaining continuous security monitoring through token verification.
Solution Approach 2:
The system creates verified copies of authentication credentials in the form of tokens that can be transmitted and validated independently. Instead of continuously tracking the original credential state, the system validates these copied token representations, which reduces system complexity while maintaining security through the unforgeable nature of the token copies.
3Reliability
If access control protocols are required before authentication, then account security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements self-service mechanisms where users can proactively lock and unlock their own credentials, manage their token portfolios, and control access permissions without requiring manual intervention from administrators. The system automatically performs protection checks and validates tokens, reducing the operational burden on users while maintaining strong security protocols.
Solution Approach 2:
Users perform preliminary actions to lock their credentials and issue tokens in advance of actual authentication needs. Access control protocols are established beforehand through token issuance and credential locking, so that when authentication is needed, the system can quickly verify pre-established conditions rather than imposing complex protocols at the moment of login.
Data Source
AI summary
A system and a method are provided for facilitating an account protection check for the security of sets of credentials. The system and method enable the use of an access control mechanism to regulate the changes to the lock status of the sets of credentials. A third-party server of a service provider requests a token from the system before the authentication process. The access control mechanism also approves or denies the request before the authentication process. If the credential set is in a locked status or unlocked status, at least one remote server of the system respectively relays an invalidation token or a validation token to the third-party server. If the invalidation token is relayed to the third-party server, the service provider does not go through the authentication process. If the validation token is relayed to the third-party server, the service provider proceeds with the authentication process as standard procedure.


