Credential Set Locking Mechanism for Unauthorized Access Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current username/password credential validation methods leave systems vulnerable to unauthorized access when credentials are not in use, as they do not provide a mechanism to securely lock or unlock credentials outside of intended usage periods.
Innovation Solution
A system and method that allows users to lock or unlock credential sets, with a remote server managing client and user accounts, providing a token response to service providers indicating the credential set's status, preventing authentication if locked, and allowing it if unlocked, thereby enhancing security by preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If username/password credential validation is continuously available, then ease of operation is improved, but security is worsened due to vulnerability to unauthorized access
Solution Approach 1:
The patent applies dynamics by making the credential validation system stateful rather than static. The credential set can dynamically transition between locked and unlocked states based on user control, allowing the system to adapt its security posture to current needs while maintaining ease of operation when unlocked.
Solution Approach 2:
The patent applies preliminary action by requiring users to proactively unlock credential sets before they can be used. This preliminary unlocking action ensures that credentials are only accessible when intentionally permitted, preventing unauthorized access while maintaining operational ease when properly unlocked.
2Productivity
If credential validation is always available, then productivity is improved, but security is worsened due to exposure to hacking risks
Solution Approach 1:
The system dynamically adjusts between security and productivity modes. When credentials are locked, security is prioritized; when unlocked, productivity is enabled. This dynamic state management allows the system to provide high productivity during legitimate use while maintaining strong security during storage or idle periods.
Solution Approach 2:
The patent introduces an intermediary control mechanism (the lock/unlock state managed by the user) between the credential storage and validation processes. This intermediary layer acts as a gatekeeper that enables productivity when appropriate while blocking security threats, resolving the contradiction between continuous availability and security.
3Object-affected harmful factors
If a lock/unlock mechanism is added to credentials, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent applies universality by designing the credential set structure to serve multiple functions: it stores credentials, maintains lock/unlock state, and provides validation logic all within a single unified object. This multi-functionality reduces overall system complexity despite adding security features, as the credential set itself becomes the centralized control point.
Solution Approach 2:
The patent merges the security control mechanism directly into the credential set structure. Rather than adding separate complex security subsystems, the lock/unlock state and validation logic are combined with the credential storage, creating a streamlined integrated system that improves security without proportionally increasing complexity.
Data Source
AI summary
A system and a method are provided for facilitating the security of sets of credentials. The system and method allow a user to lock or unlock a credential set of at least one user account. The user attempts to access the user account as standard procedure. Before a service provider goes through an authentication process, a third-party server of a service provider requests a token from the system. Based on if the credential set is in a locked status or unlocked status, at least one remote server of the system respectively relays an invalidation token or a validation token to the third-party server. If the invalidation token is relayed to the third-party server, the service provider does not go through the authentication process. If the validation token is relayed to the third-party server, the service provider proceeds with the authentication process as standard procedure.


