Dynamic Password Authentication via Dynamic Text Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional password authentication methods are vulnerable to guessing and theft, especially in high-risk situations, as they rely on static passwords that can be easily compromised by malware and other attacks.
Innovation Solution
The method enhances password protection by converting static user passwords into semi-dynamic passwords through the intermixing of dynamic text suggestions, utilizing the concept of 'something you know and something you have,' which are sent via out-of-band mechanisms, such as email or CAPTCHA, to strengthen the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static passwords are used for authentication, then the system is simple and easy to operate, but the security is weak and vulnerable to guessing and theft
Solution Approach 1:
The patent transforms static passwords into dynamic authentication mechanisms by introducing time-varying elements. Dynamic passwords change over time or in response to specific events, making them resistant to replay attacks and guessing. The system incorporates dynamic challenge-response pairs, session-based tokens, and adaptive authentication flows that evolve based on risk assessment, thereby resolving the contradiction between security strength and system simplicity.
Solution Approach 2:
The patent employs parameter changes by modifying authentication parameters dynamically based on risk context. The system adjusts password policies, authentication methods, and security parameters according to user behavior patterns, device trust levels, and threat detection results. This adaptive parameter adjustment strengthens security without requiring complete system redesign, addressing the contradiction between reliability and complexity.
2Reliability
If dynamic text is added to passwords to enhance security, then password protection is improved, but the ease of operation decreases
Solution Approach 1:
The patent implements feedback mechanisms where the system provides real-time guidance to users during the authentication process. Dynamic challenges are presented with clear instructions, and the system validates user input with immediate feedback. This feedback loop simplifies the user experience by guiding them through complex authentication flows, resolving the contradiction between enhanced protection and operational ease.
Solution Approach 2:
The system performs self-service by automatically managing the dynamic authentication process without requiring manual configuration or complex user intervention. The authentication mechanism autonomously generates challenges, validates responses, and adjusts parameters based on risk assessment, freeing users from manual security management while maintaining strong protection.
3Reliability
If multi-factor authentication is implemented, then security against malware and theft is improved, but the device complexity and authentication time increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing authentication contexts, trust relationships, and security parameters before the actual authentication event. The system performs risk assessment, device verification, and policy determination in advance, so that during the authentication process itself, the system can quickly execute pre-planned verification flows without time-consuming real-time analysis, thus reducing authentication time while maintaining security.
Solution Approach 2:
The system implements partial action by selectively applying authentication measures based on risk level. For low-risk scenarios, the system uses simplified authentication flows, while reserving complex multi-factor verification for high-risk situations. This risk-based partial application of security measures reduces overall authentication time while maintaining strong protection when needed most.
Data Source
AI summary
A mechanism is provided for enhancing password protection. a combination password that comprises dynamic text interspersed within a static user password is received from a user. A determination is made as to whether the combination password is to be verified without the dynamic text. Responsive to identifying that the combination password is to be verified without the dynamic text, the dynamic text is filtered from the combination password based on an identified dynamic suggestion issued to the user prior to the combination password being received thereby forming a filtered password. The filtered password is then authenticated using information stored for the user. Responsive to validating the filtered password, access is granted by the user to a secured system.


