Gradual Credential Expiration System for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rigid password expiration policies in organizations lead to a bad user experience and increased administrative costs due to the all-or-nothing approach, where users either change their passwords before expiration or face complete loss of access, prompting unnecessary password reset requests.

Innovation Solution

Implementing a gradual credential expiration system that allows users to retain access rights with progressive restrictions over a defined grace period, enabling them to change their credentials without complete loss of access, thereby improving user experience and reducing administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a rigid password expiration policy is implemented, then security is improved, but user experience deteriorates and administrative costs increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the credential expiration process into multiple stages: a grace period with progressive access restrictions and a final expiration stage. During the grace period, users experience gradually deteriorating access rights rather than immediate complete loss, making the transition smoother and reducing user frustration while maintaining security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic access control where the level of access rights changes over time based on the credential expiration timeline. Access rights are progressively restricted during the grace period and then completely revoked at final expiration, creating a dynamic rather than static security mechanism that adapts to the user's credential status.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If an all-or-nothing password expiration approach is used, then security enforcement is simplified, but administrative costs increase due to unnecessary password reset requests

Engineering Contradiction:
Improvesecurity enforcementVSAvoidadministrative efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent implements preliminary action by establishing a grace period before complete credential expiration. During this grace period, users are given progressive access restrictions that encourage timely credential renewal. This preliminary warning period reduces the number of users who reach the point of complete access loss and require emergency password resets, thereby improving administrative efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where users receive notifications about their credential expiration status and the progressive restrictions being applied. This feedback loop allows users to understand the situation better and take timely action to renew their credentials, reducing unnecessary helpdesk requests and improving administrative productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10007779B1Methods and systems for gradual expiration of credentials
Publication Date: 2018.06.26 AMAZON TECH INC
  • US10007779B1 patent drawing
  • US10007779B1 patent drawing
  • US10007779B1 patent drawing

AI summary

Methods and systems are provided to enable gradual expiration of credentials. Instead of depriving a user of all his access rights upon expiration of his credential (e.g., password), the user's access rights may be gradually restricted during a grace period after an expected or initial expiration time and/or before a final expiration time. The access right may be determined based on a duration from a time of the access request to the final expiration time or to the initial expiration time.