Adaptive Password Authentication via Context Substring Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital user authentication methods, such as password managers, are prone to subscription costs, manual inputs, security breaches, and the risk of password reuse due to uniform policies that lock accounts after a predetermined number of invalid attempts, leading to legitimate users being locked out.
Innovation Solution
A method that compares context substrings of incorrect password inputs with correct password database entries to generate a user legitimacy score, allowing for a variable incorrect password input protocol that adjusts the number of attempts before lockout or implements additional security measures based on the score.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a uniform password policy locks accounts after a predetermined number of invalid attempts, then security is improved by preventing brute-force attacks, but legitimate users are locked out due to temporary memory failures or typos
Solution Approach 1:
The patent applies dynamics by transitioning from a static, uniform password policy to a dynamic, adaptive policy. The system continuously monitors password attempt patterns and adjusts the lockout threshold based on user behavior. Legitimate users who make occasional mistakes are given additional attempts, while suspicious patterns trigger earlier lockout, thus adapting the security mechanism to individual user needs and eliminating the contradiction between security and ease of operation.
Solution Approach 2:
The patent implements feedback by introducing a monitoring mechanism that tracks password attempt patterns and uses this information to adjust the lockout policy. The system provides feedback to administrators about user behavior patterns, enabling data-driven decisions to optimize the balance between security and user accessibility. This feedback loop allows the system to learn from actual usage and refine its response accordingly.
2Ease of operation
If password managers are used to store login credentials, then ease of operation is improved by eliminating the need to memorize multiple passwords, but security is worsened due to subscription costs, manual inputs, and potential security breaches
Solution Approach 1:
The patent applies self-service by enabling users to manage their own password security through intuitive patterns recognition. Instead of relying on external password managers that require subscriptions and manual maintenance, the system automatically detects and learns user typing patterns, capitalizing on their natural behavior to provide secure authentication without additional software dependencies or manual inputs.
Solution Approach 2:
The patent replaces the mechanical system of password managers with a pattern recognition system. Instead of storing credentials in a database requiring manual access and management, the system uses computational pattern analysis to verify user identity based on their typing behavior, eliminating the need for external management tools and their associated security risks.
3Reliability
If a predetermined number of invalid password attempts triggers lockout, then security is improved by preventing unauthorized access, but productivity is worsened due to legitimate users being locked out and requiring password resets
Solution Approach 1:
The patent applies dynamics by making the lockout threshold adaptive rather than fixed. The system dynamically adjusts the number of allowed attempts based on real-time analysis of user behavior patterns. Legitimate users with occasional typos maintain full access, while accounts showing suspicious patterns are locked out sooner, thus optimizing both security and productivity without the need for manual password resets.
Solution Approach 2:
The patent implements feedback by continuously monitoring password attempt patterns and using this information to adjust the lockout policy in real-time. This feedback mechanism ensures that legitimate users are not unnecessarily locked out, maintaining productivity while still protecting against unauthorized access through pattern-based detection of malicious behavior.
Data Source
AI summary
The present inventive concept provides for a method of digital user authentication using password context substrings. The method includes comparing corresponding context substrings of an incorrect password input and a correct password database entry. A user legitimacy score is generated based, at least in part, on the compared corresponding context substrings, and a variable incorrect password input protocol is implemented based on the generated user legitimacy score.


