Adaptive Password Authentication via Context Substring Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital user authentication methods, such as password managers, are prone to subscription costs, manual inputs, security breaches, and the risk of password reuse due to uniform policies that lock accounts after a predetermined number of invalid attempts, leading to legitimate users being locked out.

Innovation Solution

A method that compares context substrings of incorrect password inputs with correct password database entries to generate a user legitimacy score, allowing for a variable incorrect password input protocol that adjusts the number of attempts before lockout or implements additional security measures based on the score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a uniform password policy locks accounts after a predetermined number of invalid attempts, then security is improved by preventing brute-force attacks, but legitimate users are locked out due to temporary memory failures or typos

Engineering Contradiction:
ImprovesecurityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies dynamics by transitioning from a static, uniform password policy to a dynamic, adaptive policy. The system continuously monitors password attempt patterns and adjusts the lockout threshold based on user behavior. Legitimate users who make occasional mistakes are given additional attempts, while suspicious patterns trigger earlier lockout, thus adapting the security mechanism to individual user needs and eliminating the contradiction between security and ease of operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback by introducing a monitoring mechanism that tracks password attempt patterns and uses this information to adjust the lockout policy. The system provides feedback to administrators about user behavior patterns, enabling data-driven decisions to optimize the balance between security and user accessibility. This feedback loop allows the system to learn from actual usage and refine its response accordingly.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If password managers are used to store login credentials, then ease of operation is improved by eliminating the need to memorize multiple passwords, but security is worsened due to subscription costs, manual inputs, and potential security breaches

Engineering Contradiction:
Improvecredential managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies self-service by enabling users to manage their own password security through intuitive patterns recognition. Instead of relying on external password managers that require subscriptions and manual maintenance, the system automatically detects and learns user typing patterns, capitalizing on their natural behavior to provide secure authentication without additional software dependencies or manual inputs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of password managers with a pattern recognition system. Instead of storing credentials in a database requiring manual access and management, the system uses computational pattern analysis to verify user identity based on their typing behavior, eliminating the need for external management tools and their associated security risks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a predetermined number of invalid password attempts triggers lockout, then security is improved by preventing unauthorized access, but productivity is worsened due to legitimate users being locked out and requiring password resets

Engineering Contradiction:
ImprovesecurityVSAvoiduser access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making the lockout threshold adaptive rather than fixed. The system dynamically adjusts the number of allowed attempts based on real-time analysis of user behavior patterns. Legitimate users with occasional typos maintain full access, while accounts showing suspicious patterns are locked out sooner, thus optimizing both security and productivity without the need for manual password resets.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback by continuously monitoring password attempt patterns and using this information to adjust the lockout policy in real-time. This feedback mechanism ensures that legitimate users are not unnecessarily locked out, maintaining productivity while still protecting against unauthorized access through pattern-based detection of malicious behavior.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250016150A1Digital user authentication using password context substrings
Publication Date: 2025.01.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250016150A1 patent drawing
  • US20250016150A1 patent drawing
  • US20250016150A1 patent drawing

AI summary

The present inventive concept provides for a method of digital user authentication using password context substrings. The method includes comparing corresponding context substrings of an incorrect password input and a correct password database entry. A user legitimacy score is generated based, at least in part, on the compared corresponding context substrings, and a variable incorrect password input protocol is implemented based on the generated user legitimacy score.