Dynamic Password Authentication via Dynamic Text Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional password authentication methods are vulnerable to guessing and theft, especially in high-risk situations, as they rely on static passwords that can be easily compromised by malware and other attacks.

Innovation Solution

The method enhances password protection by converting static user passwords into semi-dynamic passwords through the intermixing of dynamic text suggestions, utilizing the concept of 'something you know and something you have,' which are sent via out-of-band mechanisms, such as email or CAPTCHA, to strengthen the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static passwords are used for authentication, then the system is simple and easy to operate, but the security is weak and vulnerable to guessing and theft

Engineering Contradiction:
Improvepassword securityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static passwords into dynamic authentication mechanisms by introducing time-varying elements. Dynamic passwords change over time or in response to specific events, making them resistant to replay attacks and guessing. The system incorporates dynamic challenge-response pairs, session-based tokens, and adaptive authentication flows that evolve based on risk assessment, thereby resolving the contradiction between security strength and system simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs parameter changes by modifying authentication parameters dynamically based on risk context. The system adjusts password policies, authentication methods, and security parameters according to user behavior patterns, device trust levels, and threat detection results. This adaptive parameter adjustment strengthens security without requiring complete system redesign, addressing the contradiction between reliability and complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic text is added to passwords to enhance security, then password protection is improved, but the ease of operation decreases

Engineering Contradiction:
Improvepassword protectionVSAvoidpassword entry process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the system provides real-time guidance to users during the authentication process. Dynamic challenges are presented with clear instructions, and the system validates user input with immediate feedback. This feedback loop simplifies the user experience by guiding them through complex authentication flows, resolving the contradiction between enhanced protection and operational ease.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically managing the dynamic authentication process without requiring manual configuration or complex user intervention. The authentication mechanism autonomously generates challenges, validates responses, and adjusts parameters based on risk assessment, freeing users from manual security management while maintaining strong protection.

Inventive Principle:
Principle #25Self-service

3Reliability

If multi-factor authentication is implemented, then security against malware and theft is improved, but the device complexity and authentication time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing authentication contexts, trust relationships, and security parameters before the actual authentication event. The system performs risk assessment, device verification, and policy determination in advance, so that during the authentication process itself, the system can quickly execute pre-planned verification flows without time-consuming real-time analysis, thus reducing authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements partial action by selectively applying authentication measures based on risk level. For low-risk scenarios, the system uses simplified authentication flows, while reserving complex multi-factor verification for high-risk situations. This risk-based partial application of security measures reduces overall authentication time while maintaining strong protection when needed most.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8856904B2Enhancing password protection
Publication Date: 2014.10.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8856904B2 patent drawing
  • US8856904B2 patent drawing
  • US8856904B2 patent drawing

AI summary

A mechanism is provided for enhancing password protection. a combination password that comprises dynamic text interspersed within a static user password is received from a user. A determination is made as to whether the combination password is to be verified without the dynamic text. Responsive to identifying that the combination password is to be verified without the dynamic text, the dynamic text is filtered from the combination password based on an identified dynamic suggestion issued to the user prior to the combination password being received thereby forming a filtered password. The filtered password is then authenticated using information stored for the user. Responsive to validating the filtered password, access is granted by the user to a secured system.