Credential Management Service for Automated Password Rotation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple usernames and passwords across various web sites, leading to security vulnerabilities and high abandonment rates due to the complexity of remembering and maintaining strong, unique passwords.

Innovation Solution

A system that automatically generates unique, strong passwords for each network site, separates users from password management, and provides secure storage and retrieval of credentials using knowledge-based questions and master passwords, allowing for centralized management and automatic login across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage multiple usernames and passwords manually, then they maintain control over their credentials, but the complexity of remembering and managing tens or hundreds of credentials increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication management service as an intermediary between users and network sites. This service automatically manages credentials, generating strong unique passwords for each site and handling authentication processes. Users interact with a single user account in the authentication service rather than managing multiple credentials directly, thereby reducing management complexity while maintaining security through automated credential generation and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users use the same username and password for multiple web sites, then ease of operation improves, but security vulnerabilities increase

Engineering Contradiction:
Improveease of credential managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the credential management process by creating separate unique credentials for each network site through the authentication management service. Instead of using a single password across multiple sites, the system generates and manages distinct strong passwords for each site, while users only need to remember their single authentication service credentials. This segmentation maintains ease of operation for users while eliminating security vulnerabilities associated with password reuse.

Inventive Principle:
Principle #1Segmentation

3Reliability

If users are required to create new accounts for each service, then security is improved through unique credentials, but abandonment rates increase due to user frustration

Engineering Contradiction:
ImprovesecurityVSAvoidservice adoption rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a universal authentication management service that works across multiple network sites. Users create a single account in the authentication service that automatically manages credentials for numerous different services. This multi-functional approach allows the same authentication mechanism to protect multiple accounts simultaneously, improving security through unique credentials while reducing abandonment rates by eliminating the need for users to manually create and manage separate accounts for each service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If strong unique passwords are generated for each site, then security against brute force attacks improves, but the difficulty of managing these credentials increases

Engineering Contradiction:
Improvesecurity against attacksVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service automation where the authentication management service automatically generates strong unique passwords for each network site, stores them securely, and retrieves them during authentication processes. The system performs all credential management tasks autonomously without requiring user intervention for password creation, storage, or retrieval. This self-service approach maintains high security through strong unique passwords while eliminating the management burden from users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9660982B2Reset and recovery of managed security credentials
Publication Date: 2017.05.23 AMAZON TECH INC
  • US9660982B2 patent drawing
  • US9660982B2 patent drawing
  • US9660982B2 patent drawing

AI summary

Disclosed are various embodiments for management functions relating to security credentials. Account data, which includes multiple security credentials for multiple network sites for a user, is stored in an encrypted form. A request to temporarily change the account data is obtained from a client. The request specifies a master security credential for accessing the account data. In response to the request, the multiple security credentials for the account data are changed to a single temporary security credential, as specified by a user. After an expiration period expires, the multiple security credentials are automatically reset to a plurality of different security credentials.