Credential Management System for Secure Password Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple usernames and passwords across various web sites, leading to security vulnerabilities and high abandonment rates due to the complexity of remembering strong, unique passwords.

Innovation Solution

A system that automatically generates unique, strong passwords for each network site, separates users from password management, and provides secure storage and retrieval of credentials using knowledge-based questions and master passwords, allowing for automatic account creation, upgrade, and logout across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage multiple usernames and passwords manually, then security credentials can be stored locally, but users face difficulties remembering passwords and security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a centralized account management service as an intermediary between users and multiple network sites. This service stores credentials securely on remote servers and automatically retrieves them during authentication, eliminating the need for users to manually manage multiple passwords while maintaining security through centralized control and encrypted storage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically generating, storing, and retrieving security credentials without user intervention. The account management service handles password generation, secure storage, and automatic retrieval during login processes, freeing users from the burden of manual password management while maintaining strong security practices

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users use the same username and password for multiple web sites, then password management becomes easier, but security vulnerabilities increase

Engineering Contradiction:
Improvepassword managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the credential management system by creating separate, unique security credentials for each network site while maintaining a centralized management structure. Each account in the account data structure is associated with specific network sites and has its own unique credentials, preventing the security vulnerabilities of password reuse while keeping management simple through centralization

Inventive Principle:
Principle #1Segmentation

3Reliability

If strong, unique passwords are required for each network site, then security is improved, but user abandonment rates increase due to complexity

Engineering Contradiction:
ImprovesecurityVSAvoiduser sign-up rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary action by automatically generating and storing strong, unique passwords for each network site before the user needs them. The account management service pre-configures all security credentials in advance, so when users want to sign up for new services, the passwords are already generated and stored securely, eliminating the complexity barrier to sign-up while maintaining strong security requirements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12177201B2Managing security credentials
Publication Date: 2024.12.24 AMAZON TECH INC
  • US12177201B2 patent drawing
  • US12177201B2 patent drawing
  • US12177201B2 patent drawing

AI summary

Disclosed are various embodiments for managing security credentials for an authentication management client on a client device. In one non-limiting example, a computing device is configured to receive an authentication request from an authentication management client of a client and determine an affinity of the authentication management client based at least in part on the authentication request. The computing device is configured to determine that the authentication management client is supported based at least in part on the affinity. The computing device is configured to generate a session for the authentication management client based at least in part on a security credential being received from the authentication management client.