Password Changing via Temporary Credential Rotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
When logging into user accounts from untrusted computing devices, there is a risk of password capture by malicious hardware or software, compromising account security.
Innovation Solution
A temporary password is generated and automatically negotiated with the remote computing system to change the existing password, allowing secure access from untrusted devices while ensuring the captured password is not valid for future logins, using a trusted device or host computer application that can operate over various networks, including those with limited compute power and no live internet connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user logs in to a user account from an untrusted computing device, then the user can access the on-line service, but the password may be captured by malicious hardware or software compromising account security
Solution Approach 1:
The system performs preliminary actions by automatically changing the password to a temporary value before the user logs in from an untrusted device, and then reverting it after the session. This preemptive password rotation ensures that even if malware captures the password during login, it becomes invalid for future use, thus resolving the security risk while maintaining ease of access
Solution Approach 2:
The password protection application acts as an intermediary between the user and the on-line service. It automatically negotiates password changes with the service provider's account management system, shielding the user from manual password changes while ensuring security. This intermediary function allows seamless access protection without requiring user intervention or modifications to the remote service
2Reliability
If an automated routine negotiates password change with the on-line service, then account security is improved, but device complexity increases
Solution Approach 1:
The password protection application implements self-service by automatically performing password rotation without requiring user intervention. The system monitors login sessions, automatically negotiates password changes with the on-line service through integrated account management interfaces, and manages the entire security protocol independently, reducing the perceived complexity for users while maintaining robust security
Solution Approach 2:
The application provides multi-functionality by combining password management, automated negotiation with multiple on-line services, session monitoring, and security enforcement in a single unified system. This universal approach allows the same mechanism to protect accounts across different services without requiring separate complex systems for each, thereby reducing overall device complexity while maintaining high security standards
Data Source
AI summary
In one example, a computing device generates a new password for accessing a user account and/or computing system and inspires a change of an existing password for the user account and/or computing system to the new password. Thereafter, the computing device detects occurrence of a condition to trigger another change of the password for the user account and/or computing system and, responsively, inspires another change of the password for the user account and/or computing system.


