Identity Verification Device Preventing Account Enumeration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password reset mechanisms are vulnerable to attacks, allowing hackers to reset user passwords even if they fail to crack the original password, compromising system security and user experience.

Innovation Solution

A method that involves the verifier sending consistent confirmation information for both valid and invalid accounts, preventing hackers from determining account validity and reducing the risk of password reset vulnerabilities, while allowing users to identify incorrect accounts and improve user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the verifier returns different confirmation information for valid and invalid accounts, then users can identify incorrect accounts, but hackers can enumerate valid accounts using the confirmation information

Engineering Contradiction:
Improveuser ability to identify incorrect accountsVSAvoidaccount enumeration attacks by hackers
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making the confirmation information form consistent (to prevent enumeration) while allowing local differentiation through binding information content (to enable user identification). The form homogeneity masks account validity, but the binding information embedded within can still help users verify if they own the account through selective information matching.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses homogeneity by making the confirmation information form identical for both valid and invalid accounts. This prevents hackers from determining account validity by analyzing differences in confirmation information structure, while users can still identify incorrect accounts by checking if the binding information within matches their known account details.

Inventive Principle:
Principle #33Homogeneity

2Reliability

If the verifier generates binding information for invalid accounts, then the confirmation information form remains consistent, but system resources are consumed generating fake information

Engineering Contradiction:
Improveconsistency of confirmation information formVSAvoidsystem resources for generating fake binding information
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies copying by creating a fake confirmation information structure that mirrors the valid account format. Instead of generating entirely new fake binding information, the system copies the form structure and populates it with generated or placeholder binding information, reducing computational overhead while maintaining form consistency.

Inventive Principle:
Principle #26Copying

3Ease of operation

If the verifier sends verification information to invalid accounts, then the user experience is improved with consistent responses, but network congestion increases

Engineering Contradiction:
Improveconsistent user experienceVSAvoidnetwork congestion from verification information
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the essential function of providing consistent confirmation information while removing the harmful effect of sending actual verification information to invalid accounts. The system sends confirmation information with binding data for display purposes but excludes the actual verification codes or sensitive authentication data that would cause network congestion and security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11388194B2Identity verification and verifying device
Publication Date: 2022.07.12 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US11388194B2 patent drawing
  • US11388194B2 patent drawing
  • US11388194B2 patent drawing

AI summary

An identity verification method and a verifying device, where the verifying device receives an account for requesting password reset. When the account is invalid, the verifying device sends a fake identification and a first verification request to a requesting device. The verification request mentioned requests a user to determine whether to send verification information to a first communication address. The fake identification and the first communication address are associated with the first account.