Password Hint Enforcement for BYOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In bring-your-own-device (BYOD) environments, administrators face challenges in managing local passwords on personal devices that are not issued by the enterprise, as they cannot reset or assist with forgotten passwords, differing from network passwords managed in directory services.

Innovation Solution

Implementing a management component on client devices to enforce local security policies, including requiring users to define a password hint for their local passwords, which can be enforced through the management component, ensuring compliance with enterprise password policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators cannot reset local passwords on personal devices, then user autonomy and device security are maintained, but user support burden increases when passwords are forgotten

Engineering Contradiction:
Improvedevice securityVSAvoidpassword recovery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system requires users to pre-configure password hints during device setup or policy enrollment. These hints are stored securely and made available later for password recovery, eliminating the need for administrator intervention while maintaining security. The preliminary action of setting up recovery mechanisms prevents the problem of forgotten passwords without compromising device protection.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If local passwords differ from network passwords, then device access independence is improved, but administrative control and policy enforcement are weakened

Engineering Contradiction:
Improvedevice access independenceVSAvoidpolicy enforcement
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

A management component acts as an intermediary between local device passwords and enterprise policy requirements. This component enforces password policies, monitors compliance, and coordinates with directory services while allowing local password independence. The intermediary maintains both user autonomy and administrative control by bridging the gap between local and network authentication systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If password hints are required by policy, then password recovery ease is improved, but user compliance burden increases

Engineering Contradiction:
Improvepassword recoveryVSAvoidpolicy compliance
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Users independently configure their own password hints through a self-service interface that guides them through the process. The system automatically validates hint quality and stores it securely without requiring administrator approval or complex policy configuration. This self-service approach simplifies compliance by making the process user-friendly while ensuring policy requirements are met.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11443029B2Password hint policies on a user provided device
Publication Date: 2022.09.13 OMNISSA LLC
  • US11443029B2 patent drawing
  • US11443029B2 patent drawing
  • US11443029B2 patent drawing

AI summary

Disclosed are various examples for remotely managing passwords using local security policies. A client device can be enrolled with a management service. The management service then transmits a password policy requiring a password hint to be defined by the user. A management component executed on the client device can then enforce the password policy by requiring a user to define a password hint in order to access enterprise resources.