Master Password Hashing for Multi-Resource Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple two-factor authentication secrets for various online accounts, leading to frustration and increased vulnerability to hacking, as each account has unique policies and procedures, making it hard to remember and access multiple secrets across different network resources.

Innovation Solution

A device and method that utilize a master password and one-way hash functions to generate secret codes for multiple network resources, allowing users to access accounts with a single remembered password and identifier, reducing the need to remember numerous complex secrets and enhancing security by eliminating susceptibility to brute force attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate secrets are used for different network resources, then security is improved, but user operation complexity increases and time loss occurs

Engineering Contradiction:
ImprovesecurityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple separate secrets into a single master secret that can generate all necessary authentication credentials. The secret management device consolidates the management of secrets for multiple network resources (bank accounts, email, shopping, etc.) into one unified system, allowing users to access all resources using one master secret rather than remembering multiple separate secrets.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The master secret serves multiple functions across different network resources. A single master secret can generate authentication credentials for various types of accounts including banking, email, shopping, and other online resources, making the secret management system universal and applicable to diverse authentication scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate secrets are used for different network resources, then security is improved, but time loss increases due to remembering and accessing multiple secrets

Engineering Contradiction:
ImprovesecurityVSAvoidtime loss
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple separate secrets into a single master secret that can generate all necessary authentication credentials. The secret management device consolidates the management of secrets for multiple network resources (bank accounts, email, shopping, etc.) into one unified system, allowing users to access all resources using one master secret rather than remembering multiple separate secrets.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secret management device performs preliminary actions by automatically generating and storing secrets for multiple network resources in advance. When a user needs to access a resource, the system has already prepared the necessary credentials, eliminating the time needed to manually create or retrieve multiple separate secrets.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If auto population of secrets is used, then ease of operation is improved, but security risks increase

Engineering Contradiction:
Improveease of operationVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted secret management device as an intermediary between the user and network resources. This intermediary securely stores the master secret and generated credentials, managing the auto-population process in a controlled manner. The intermediary protects against security risks by ensuring that secrets are handled through a secure, centralized mechanism rather than vulnerable auto-population features in individual applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11405375B2Device and method for receiving a temporary credit token
Publication Date: 2022.08.02 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US11405375B2 patent drawing
  • US11405375B2 patent drawing
  • US11405375B2 patent drawing

AI summary

A computer implemented method, device and computer program device are provided including one or more processors and an input to collect credential related content including a first network resource identifier related to a first one of multiple network resources, the credential related content further including a master password that is associated with the first network resource identifier and that is associated with network resource identifiers for a remainder of the multiple network resources. Responsive to execution of the program instructions, the processor converts the master password and the first network resource identifier into a first hash code to receive a temporary credential token from the authentication service in connection with the first hash code.