Automated Credential Recovery Service for Unauthorized Access Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting credential theft, such as by malware, are often reactive and require human intervention, leading to delayed and error-prone protective actions, which increases security risks.

Innovation Solution

A proactive data recovery service that automatically detects compromised credentials by monitoring online repositories and initiates protective actions, such as disabling user accounts, through integration with identity management systems like Active Directory, to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing detection methods are used, then credential theft can be detected, but detection occurs only after unauthorized access has already happened, creating security delays

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection timing
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring online repositories for compromised credentials before they are used for unauthorized access. The data recovery service proactively identifies stolen credentials in data feeds and triggers protective actions ahead of time, preventing the contradiction between detection accuracy and detection timing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where detected compromised credentials immediately trigger automated protective actions. The continuous monitoring of data feeds provides real-time feedback about credential compromise status, enabling the system to respond dynamically and eliminate the time delay between detection and protective action.

Inventive Principle:
Principle #23Feedback

2Reliability

If human users review credential theft information, then protective actions can be initiated, but the process becomes slow and error-prone

Engineering Contradiction:
Improveprotective action accuracyVSAvoidresponse speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs self-service by automatically detecting compromised credentials, making protection decisions, and executing protective actions without human intervention. The automated data recovery service monitors data feeds, identifies compromised credentials, and triggers account disabling or other protective measures autonomously, eliminating both the slowness and error-proneness of manual review processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical human review process with an automated electronic system. Instead of human users manually reviewing credential theft information, the data recovery service uses automated algorithms to analyze data feeds and trigger protective actions, substituting human cognitive processes with machine-based detection and response mechanisms that are both faster and more reliable.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated detection systems are implemented, then response speed improves, but system complexity increases

Engineering Contradiction:
Improvedetection and response speedVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system uses an intermediary approach by integrating with existing identity management systems and data feed providers. Rather than building a complete automated detection system from scratch, the data recovery service leverages existing infrastructure including online repository data feeds, credential monitoring services, and identity management platform APIs, reducing overall system complexity while maintaining high response speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8978150B1Data recovery service with automated identification and response to compromised user credentials
Publication Date: 2015.03.10 EMC IP HLDG CO LLC
  • US8978150B1 patent drawing
  • US8978150B1 patent drawing
  • US8978150B1 patent drawing

AI summary

A data recovery service protects against unauthorized use of a computer system. The service includes a data feed that contains data recovered from online repositories known to be used by malicious software or individuals, the recovered data identifying a compromised credential of an authorized user of the computer system. Based on this data, a protective action is automatically performed to limit or prevent use of the credential of the authorized user to access the computer system. Protective action may include disabling user account access privileges, etc.