Dynamic Authentication Mode Switching for Computing Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication management systems face inefficiencies and security risks, particularly when primary passwords are compromised, as they often lack dynamic and secure secondary authentication protocols to protect access to computing devices.

Innovation Solution

Implementing a temporary password authentication mode with a tandem password input and reset method using a delimiter, where the system switches to primary password authentication if temporary passwords are incorrectly entered a threshold number of times, and dynamically reconfigures authentication protocols based on triggering events to enhance security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a temporary password authentication mode is implemented with dynamic switching between primary and temporary passwords, then security is improved by preventing unauthorized access even when primary passwords are compromised, but device complexity increases due to multiple authentication protocols and state management

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically switches between primary password mode and temporary password mode based on detected triggering events. The system transitions from a static authentication protocol to a dynamic one where the active authentication method changes in response to security events, thereby improving security without requiring permanently complex infrastructure

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system is segmented into distinct modes (primary password authentication and temporary password authentication) that can be independently managed. This segmentation allows the system to isolate security incidents to specific modes while maintaining other modes functional, reducing overall system complexity through modular design

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a tandem password input and reset method using a delimiter is implemented, then ease of operation is improved by allowing users to authenticate and reset passwords in a single interaction, but measurement precision deteriorates due to potential delimiter ambiguity in password inputs

Engineering Contradiction:
Improvepassword reset convenienceVSAvoidauthentication input accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

A delimiter character serves as an intermediary between the temporary password and reset password inputs in the tandem authentication method. This intermediary allows the system to parse and distinguish between two passwords entered in sequence, enabling convenient single-interaction password reset while maintaining input accuracy through structured delimiter-based separation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system deactivates temporary password authentication after a threshold number of incorrect entries, then reliability is improved by preventing brute force attacks, but ease of operation worsens due to potential lockout of legitimate users

Engineering Contradiction:
Improveattack resistanceVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system implements feedback mechanisms that monitor incorrect password entry patterns and provide responses through the graphical user interface. The system adjusts its behavior based on feedback from authentication attempts, dynamically deactivating temporary password mode when attack patterns are detected while allowing legitimate users to recover through alternative authentication methods

Inventive Principle:
Principle #23Feedback

4Reliability

If authentication inputs are disguised to prevent unauthorized access, then security is improved by obscuring authentication requirements, but difficulty of detecting and measuring increases due to obscured authentication prompts

Engineering Contradiction:
Improveaccess protectionVSAvoidauthentication prompt visibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The graphical user interface employs visual changes including color modifications to indicate when temporary password authentication is active. These visual cues allow the system to disguise the specific authentication requirements from potential attackers while maintaining visibility for legitimate users who need to know what type of authentication is expected

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS10007780B1Authentication management
Publication Date: 2018.06.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10007780B1 patent drawing
  • US10007780B1 patent drawing
  • US10007780B1 patent drawing

AI summary

Disclosed aspects relate to authentication management. A first valid authentication input may be established with respect to access enablement to a computing asset. A second valid authentication input may be established with respect to access enablement to the computing asset. A triggering event may be detected. The first valid authentication input may be deactivated based on the triggering event. The second valid authentication input may be activated based on the triggering event. The graphical user interface may be presented which may appear to prompt for the first valid authentication input. The second valid authentication input may be received via the graphical user interface. Access enablement with respect to the computing asset may be authenticated in response to receiving the second valid authentication input.