Password Changing via Temporary Credential Rotation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When logging into user accounts from untrusted computing devices, there is a risk of password capture by malicious hardware or software, compromising account security.

Innovation Solution

A temporary password is generated and automatically negotiated with the remote computing system to change the existing password, allowing secure access from untrusted devices while ensuring the captured password is not valid for future logins, using a trusted device or host computer application that can operate over various networks, including those with limited compute power and no live internet connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user logs in to a user account from an untrusted computing device, then the user can access the on-line service, but the password may be captured by malicious hardware or software compromising account security

Engineering Contradiction:
Improveaccess to on-line serviceVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by automatically changing the password to a temporary value before the user logs in from an untrusted device, and then reverting it after the session. This preemptive password rotation ensures that even if malware captures the password during login, it becomes invalid for future use, thus resolving the security risk while maintaining ease of access

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The password protection application acts as an intermediary between the user and the on-line service. It automatically negotiates password changes with the service provider's account management system, shielding the user from manual password changes while ensuring security. This intermediary function allows seamless access protection without requiring user intervention or modifications to the remote service

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If an automated routine negotiates password change with the on-line service, then account security is improved, but device complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidautomation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The password protection application implements self-service by automatically performing password rotation without requiring user intervention. The system monitors login sessions, automatically negotiates password changes with the on-line service through integrated account management interfaces, and manages the entire security protocol independently, reducing the perceived complexity for users while maintaining robust security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The application provides multi-functionality by combining password management, automated negotiation with multiple on-line services, session monitoring, and security enforcement in a single unified system. This universal approach allows the same mechanism to protect accounts across different services without requiring separate complex systems for each, thereby reducing overall device complexity while maintaining high security standards

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8826398B2Password changing
Publication Date: 2014.09.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8826398B2 patent drawing
  • US8826398B2 patent drawing
  • US8826398B2 patent drawing

AI summary

In one example, a computing device generates a new password for accessing a user account and/or computing system and inspires a change of an existing password for the user account and/or computing system to the new password. Thereafter, the computing device detects occurrence of a condition to trigger another change of the password for the user account and/or computing system and, responsively, inspires another change of the password for the user account and/or computing system.