Dynamic Password Lifespan Management for Security-Usability Trade-offs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in remembering and managing multiple complex passwords, leading to either insufficient security due to weak passwords or reduced service appeal due to overly restrictive password requirements, which can compromise customer data.

Innovation Solution

A system that evaluates proposed passwords for compliance with security guidelines, assigns a relative security level, and sets a password lifespan based on this evaluation, allowing for secure access using lower-security passwords while encouraging more secure options through feedback and rewards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password requirements are made more restrictive to improve security, then security level is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidease of password management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts the password lifespan parameter based on the evaluated security level. Stronger passwords receive longer lifespans while weaker passwords receive shorter lifespans, creating a flexible parameter adjustment mechanism that balances security requirements with user convenience without imposing rigid restrictions

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system provides real-time feedback to users by evaluating their password strength and communicating the results along with the assigned lifespan. This feedback loop guides users toward creating stronger passwords while allowing them to understand the consequences of their choices, improving both security and user experience

Inventive Principle:
Principle #23Feedback

2Ease of operation

If password requirements are made less restrictive to improve ease of operation, then ease of operation is improved, but security level deteriorates

Engineering Contradiction:
Improveease of password managementVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic password management where the lifespan is not fixed but adapts based on the actual password strength. This dynamic adjustment allows the system to maintain high security standards while accommodating users who prefer simpler passwords, as the lifespan automatically adjusts to reflect the reduced security level

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

By changing the lifespan parameter based on password strength evaluation, the system allows less secure passwords to have shorter lifespans, effectively compensating for their weaker security through more frequent renewal requirements, thus maintaining overall security without overly restricting user choices

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all users are required to use strong passwords to improve security, then security level is improved, but adaptability deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidadaptability to user capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system adjusts the password lifespan parameter according to the evaluated security level, allowing users with different password strengths to have different expiration periods. This parameter adaptation enables the system to accommodate users with varying security knowledge and capabilities while maintaining appropriate security standards

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The dynamic lifespan assignment creates a flexible system that adapts to individual user situations. Users who create stronger passwords benefit from longer validity periods, while those who use simpler passwords receive shorter periods, making the system adaptable to different user capabilities without imposing uniform restrictions

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8886950B2Apparatus, methods, and computer program products for facilitating secure password creation and management
Publication Date: 2014.11.11 AT&T INTELLECTUAL PROPERTY I L P
  • US8886950B2 patent drawing
  • US8886950B2 patent drawing
  • US8886950B2 patent drawing

AI summary

Apparatus, methods and/or computer program products are provided that facilitate the creation and management of secure passwords. Upon receiving a proposed password from a user for use in a computer system, apparatus or other communication system, the proposed password is evaluated for compliance with security guidelines. If the password complies at least with a minimum level of security, the password is evaluated and a relative level of the password is determined and assigned to the password. A lifespan for the password is selected based on the assigned relative security level of security. The user is notified of the assigned lifespan. Operations for evaluating the password, assigning the lifespan, and notifying the user of the lifespan may be performed in substantially real-time.