Dynamic Password Criteria Generation for Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password change requirements are static, providing hackers with consistent guidelines, increasing the likelihood of successful guessing or brute-force attempts as users tend to reuse passwords or create similar new ones, thus compromising account security.

Innovation Solution

A computer-implemented method that dynamically generates unique password criteria combinations for each password change, randomly selecting from a list of rules to ensure each new password satisfies different requirements, thereby reducing the predictability of valid combinations and forcing hackers to re-tool their approaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static password criteria are used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of password creationVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static password criteria to dynamic criteria that automatically change over time. The system generates new password requirements periodically or based on security events, ensuring that password policies evolve without requiring manual intervention. This resolves the contradiction by maintaining ease of operation (automatic changes) while improving security (changing criteria prevent reuse of old passwords).

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of password criteria over time, including minimum length, character complexity requirements, and allowed patterns. By dynamically adjusting these parameters based on security needs and user behavior, the system maintains operational simplicity while enhancing security through evolving requirements that adapt to emerging threats.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If static password criteria are used, then device complexity is reduced, but security is worsened

Engineering Contradiction:
Improvepassword policy complexityVSAvoidaccount security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system implements self-service by automatically generating and updating password criteria without requiring manual configuration. The automated system monitors security events, determines when criteria changes are needed, and applies new requirements autonomously. This reduces device complexity (no manual policy management) while improving security (consistent, timely updates based on actual security needs).

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system monitors password usage patterns, security incidents, and user behavior to dynamically adjust criteria. This feedback loop allows the system to automatically refine password requirements based on real-world performance data, reducing the need for complex manual policy configuration while maintaining high security standards.

Inventive Principle:
Principle #23Feedback

3Reliability

If password criteria change dynamically, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidpassword policy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

While dynamics inherently increase complexity, the patent manages this by implementing automated dynamic criteria generation. The system uses algorithms to automatically create and update password requirements based on security events and user behavior, rather than requiring manual policy configuration. This approach improves security through frequent criteria changes while controlling complexity through automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The self-service automation of dynamic criteria generation significantly reduces the operational complexity burden. The system autonomously handles the complexity of generating, validating, and enforcing changing password requirements without requiring manual intervention or complex administrative overhead. This allows the organization to benefit from improved security while avoiding the complexity management burden.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If password criteria change dynamically, then predictability for hackers is reduced, but ease of operation is worsened

Engineering Contradiction:
Improvehackers ability to guess passwordsVSAvoiduser experience during password change
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent changes password criteria parameters dynamically based on security needs and user context. By adjusting requirements such as minimum length, character types, and complexity levels in response to security events rather than using fixed rules, the system reduces predictability for attackers. The automated nature of these changes maintains ease of operation by eliminating manual policy updates while presenting users with adaptive, context-aware requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240419778A1Computer generated password criteria combinations
Publication Date: 2024.12.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20240419778A1 patent drawing
  • US20240419778A1 patent drawing
  • US20240419778A1 patent drawing

AI summary

Computer generated password criteria generated in response to a required password change can include detecting a request for a new password for a program. A password criteria for the new password is generated, which is different than a previous password criteria. A submitted new password is received and a determination is made when the submitted new password meets each of the password criteria for the new password. Responsive to determining the submitted new password meets each of the password criteria for the new password, access is allowed to the program.