Multi-Password Authentication for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing username/password systems are insecure when used on shared or public computers, as users are unaware of potential malware or security holes, leading to concerns about unauthorized access and data protection.

Innovation Solution

Implementing a system where a single username is associated with multiple passwords, each granting different levels of access, allowing users to choose passwords based on comfort level and security needs, with one password providing full privileges and others offering restricted access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single password is used for a username, then ease of operation is improved, but security is worsened because password theft leads to complete account compromise

Engineering Contradiction:
Improvepassword managementVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single password into multiple distinct passwords (first password, second password, third password, etc.), each associated with the same username but granting different permission levels. This segmentation allows the system to maintain ease of operation (users still use simple password entry) while improving security (compromise of one password does not lead to total account compromise).

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If full access permissions are granted to all passwords, then ease of operation is improved, but security is worsened because any password provides complete access

Engineering Contradiction:
Improveaccess managementVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different permission characteristics to different passwords. The first password provides full access permissions, the second password provides limited access permissions, and the third password provides read-only permissions. This allows the system to grant appropriate access levels based on the specific context or user needs, reducing unauthorized access risk while maintaining operational ease.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple passwords with different permissions are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a multi-functional authentication system where a single username can utilize multiple passwords with different permission levels. This universal approach allows the same authentication mechanism to serve multiple security needs (full access, limited access, read-only access) without requiring separate authentication systems, thereby improving security while managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7865950B2System of assigning permissions to a user by password
Publication Date: 2011.01.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7865950B2 patent drawing
  • US7865950B2 patent drawing
  • US7865950B2 patent drawing

AI summary

A data processing system includes a data storage unit for storing data sets accessible to a user upon receipt of permission. The data processing system restricts access to data sets by requiring a username and then requiring a password to obtain permission for access to a data set stored in a data storage unit. The system is adapted to support use of more than one said password associated with a username; and each of those passwords associated with that username permits a distinct level of access to a particular data set, whereas other passwords can provide different levels of access to any data set assigned thereto.