Master Password Hashing for Multi-Resource Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing multiple two-factor authentication secrets for various online accounts, leading to frustration and increased vulnerability to hacking, as each account has unique policies and procedures, making it hard to remember and access multiple secrets across different network resources.
Innovation Solution
A device and method that utilize a master password and one-way hash functions to generate secret codes for multiple network resources, allowing users to access accounts with a single remembered password and identifier, reducing the need to remember numerous complex secrets and enhancing security by eliminating susceptibility to brute force attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate secrets are used for different network resources, then security is improved, but user operation complexity increases and time loss occurs
Solution Approach 1:
The patent combines multiple separate secrets into a single master secret that can generate all necessary authentication credentials. The secret management device consolidates the management of secrets for multiple network resources (bank accounts, email, shopping, etc.) into one unified system, allowing users to access all resources using one master secret rather than remembering multiple separate secrets.
Solution Approach 2:
The master secret serves multiple functions across different network resources. A single master secret can generate authentication credentials for various types of accounts including banking, email, shopping, and other online resources, making the secret management system universal and applicable to diverse authentication scenarios.
2Reliability
If multiple separate secrets are used for different network resources, then security is improved, but time loss increases due to remembering and accessing multiple secrets
Solution Approach 1:
The patent combines multiple separate secrets into a single master secret that can generate all necessary authentication credentials. The secret management device consolidates the management of secrets for multiple network resources (bank accounts, email, shopping, etc.) into one unified system, allowing users to access all resources using one master secret rather than remembering multiple separate secrets.
Solution Approach 2:
The secret management device performs preliminary actions by automatically generating and storing secrets for multiple network resources in advance. When a user needs to access a resource, the system has already prepared the necessary credentials, eliminating the time needed to manually create or retrieve multiple separate secrets.
3Ease of operation
If auto population of secrets is used, then ease of operation is improved, but security risks increase
Solution Approach 1:
The patent introduces a trusted secret management device as an intermediary between the user and network resources. This intermediary securely stores the master secret and generated credentials, managing the auto-population process in a controlled manner. The intermediary protects against security risks by ensuring that secrets are handled through a secure, centralized mechanism rather than vulnerable auto-population features in individual applications.
Data Source
AI summary
A computer implemented method, device and computer program device are provided including one or more processors and an input to collect credential related content including a first network resource identifier related to a first one of multiple network resources, the credential related content further including a master password that is associated with the first network resource identifier and that is associated with network resource identifiers for a remainder of the multiple network resources. Responsive to execution of the program instructions, the processor converts the master password and the first network resource identifier into a first hash code to receive a temporary credential token from the authentication service in connection with the first hash code.


