Dynamic Credential Rotation via Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current credential rotation practices do not account for the sensitivity of customer accounts to potential leakage, making it difficult for service providers to quickly and efficiently adjust rotation schedules, as they treat all credentials equally and require manual adjustments which are time and resource intensive.

Innovation Solution

Implementing a dynamic risk-based scheduling system that evaluates the strength of credentials and customer profiles to determine a tailored credential rotation schedule, using algorithms to calculate a composite risk score based on password complexity, user activity, and system configuration, allowing for automatic adjustments to rotation periods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed credential rotation schedule is implemented for all credentials, then the scheduling process is simple and consistent, but it cannot account for varying sensitivity of customer accounts to credential leakage

Engineering Contradiction:
Improveadaptability to account sensitivityVSAvoidscheduling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic credential rotation scheduling where the rotation period is not fixed but is determined by risk scores calculated from multiple factors including password complexity, user behavior patterns, and system configuration. The scheduling system automatically adjusts rotation requirements based on real-time risk assessment, transitioning from static to dynamic management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of rotation period based on risk score calculations. Different risk levels result in different rotation schedules, allowing the system to adapt the timing parameter according to the specific security posture of each customer account without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If manual adjustment of credential rotation schedules is performed to account for account sensitivity, then the scheduling can be customized, but it is time and resource intensive

Engineering Contradiction:
Improvecustomization capabilityVSAvoidadjustment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically calculating risk scores based on predefined criteria and autonomously determining rotation schedules without requiring manual intervention from service providers. The authentication service evaluates password complexity, user activity patterns, and system configuration to automatically generate customized rotation schedules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where user authentication behavior and system events are monitored, risk scores are recalculated, and rotation schedules are automatically adjusted accordingly. This closed-loop feedback mechanism ensures the scheduling remains optimized without manual intervention.

Inventive Principle:
Principle #23Feedback

3Productivity

If all credentials are treated equally in rotation scheduling, then the management process is simple, but it does not prioritize credentials with higher leakage risk

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsecurity effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by treating different credentials differently based on their individual risk profiles. Instead of uniform treatment, the system assigns specific rotation requirements to specific credentials based on factors like password strength, usage patterns, and associated user behavior, ensuring high-risk credentials receive enhanced attention.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments credentials into different risk categories based on calculated risk scores and applies distinct rotation policies to each segment. This segmentation allows the system to manage credentials efficiently by grouping them according to their security characteristics rather than treating them uniformly.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11537706B1Risk-based scheduling for credential rotation
Publication Date: 2022.12.27 AMAZON TECH INC
  • US11537706B1 patent drawing
  • US11537706B1 patent drawing
  • US11537706B1 patent drawing

AI summary

A service provider receives a set of credentials from a customer and a request to access one or more services provided by the service provider. An authentication service of the service provider receives the set of credentials and, based at least in part on the received set of credentials, one or more activities performed by the customer, the customer's user profile, and the system configuration of the customer's computing device, calculates a risk score. The authentication service subsequently utilizes the calculated risk score to determine a credential rotation schedule for the set of credentials. The authentication service updates one or more servers to enforce the new credential rotation schedule and enables the customer to utilize the set of credentials to access the one or more services.