Dual-Password Authentication System for Conditional Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password management systems in computer systems often require a single password for initial and ongoing access, which may not provide adequate security differentiation between initial and subsequent access levels, potentially compromising security.

Innovation Solution

Implementing a dual-password system where a first password with stronger security is used for initial access, and a second, easier-to-enter password is used for subsequent access, with conditions set by a policy engine determining when each password is required based on factors like time, location, and device type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single strong password is used for both initial and ongoing access, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into two distinct phases: initial access requiring a strong first password, and ongoing access requiring a simpler second password. This segmentation allows the system to maintain high security for critical initial authentication while providing convenience for routine access operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic password requirements that change based on the access context. The system transitions from requiring a strong first password for initial access to accepting a simpler second password for ongoing access, making the authentication requirements adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If a single weak password is used for both initial and ongoing access, then user convenience is improved, but security deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the password system into two distinct password types: a strong first password for initial access and a simpler second password for ongoing access. This segmentation ensures that security is not compromised in the initial authentication phase while still providing convenience for ongoing operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different access scenarios. The first password scenario uses strong security characteristics, while the second password scenario uses weaker but more convenient security characteristics, matching the security requirements of each specific access context.

Inventive Principle:
Principle #3Local quality

3Reliability

If different password strengths are used for initial and ongoing access, then security differentiation is improved, but system complexity deteriorates

Engineering Contradiction:
Improvesecurity differentiationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into two distinct password pathways: a first password for initial access and a second password for ongoing access. This clear segmentation, managed by a policy engine, provides security differentiation while maintaining manageable system complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8474013B2Securely managing password access to a computer system
Publication Date: 2013.06.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8474013B2 patent drawing
  • US8474013B2 patent drawing
  • US8474013B2 patent drawing

AI summary

A method, system or computer usable program product for providing initial access Lo the computer system in response to a user providing a first password, and upon detecting a condition meeting a predetermined criteria, providing subsequent access to the computer system in response to the user providing a second password wherein the first password has stronger security than the second password.