Dynamic Password Update System for Breach Risk Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Inadequate password management leads to security breaches in organizations, as existing encryption and hashing methods are vulnerable to hacking and brute force attacks, with current breach detection systems only reacting after data leaks occur, failing to prevent unauthorized access.

Innovation Solution

A dynamic password update system that classifies breach risk for services based on security practices, breach history, and user data sensitivity, providing users with timely password update notifications and automatic updates at intervals determined by the breach risk classification, using a sandbox environment to assess password management techniques and second factor authentication mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password update notifications are sent frequently to ensure security, then security level improves, but user annoyance and false positives increase

Engineering Contradiction:
Improvepassword securityVSAvoiduser annoyance
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different notification frequencies and security monitoring levels to different services based on their individual breach risk classifications. High-risk services receive frequent notifications and monitoring, while low-risk services receive fewer notifications, thereby improving security where needed without causing universal user annoyance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the notification parameter (frequency/timing) based on the breach risk classification of each service. When a service is classified as high-risk, the system sends notifications at different intervals compared to low-risk services, optimizing the balance between security and user experience.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive security assessment is performed on all services, then breach risk detection accuracy improves, but system complexity and processing time increase

Engineering Contradiction:
Improvebreach risk detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the security assessment process into distinct components: identifying service accounts, assessing security measures, identifying authentication mechanisms, and determining breach risk classification. Each component handles a specific aspect of the assessment, making the overall complex process more manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security assessments and establishes breach risk classifications in advance, before actual breaches occur. This allows the system to proactively notify users of potential risks and take preventive actions, rather than reacting after breaches happen.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual password updates are required for all services, then password security improves, but user time and operational burden increase

Engineering Contradiction:
Improvepassword securityVSAvoiduser time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automatic password updates for services where the breach risk classification and service characteristics indicate that automatic updates are appropriate. This reduces the need for manual user intervention while maintaining security, as the system autonomously handles password updates based on assessed risk levels.

Inventive Principle:
Principle #25Self-service

4Loss of information

If password update notifications are delayed until after breaches occur, then false positive notifications are reduced, but security effectiveness decreases

Engineering Contradiction:
Improvefalse positive notificationsVSAvoidsecurity effectiveness
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system performs preliminary security assessments and sends notifications before breaches actually occur, based on the breach risk classification of services. This proactive approach allows users to take preventive actions against potential threats while minimizing false positives through careful risk assessment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors service security measures and breach risk classifications, providing feedback to users about potential security risks. This ongoing feedback loop allows the system to adjust notification timing and frequency based on changing security conditions, improving both accuracy and effectiveness.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12118074B2Methods and apparatus to generate dynamic password update notifications
Publication Date: 2024.10.15 MCAFEE LLC
  • US12118074B2 patent drawing
  • US12118074B2 patent drawing
  • US12118074B2 patent drawing

AI summary

Methods, apparatus, systems, and articles of manufacture are disclosed that determine a dynamic password update notification interval based on a breach risk classification and an automatic password update mechanism of an online service with which a user has an account. The disclosed methods, apparatus, systems, and articles of manufacture generate a password update suggestion and/or an automatic password update for the user at the dynamic password update notification interval determined by the processor circuitry.