Password Management System Using Knowledge-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing numerous usernames and passwords across multiple websites, often resulting in weak password choices and security vulnerabilities due to human limitations in remembering complex, unique passwords.

Innovation Solution

A system that automatically generates unique, strong passwords for each network site, separates users from password management, and stores passwords centrally, accessible across devices via knowledge-based questions or master passwords, while providing secure authentication and account creation processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually manage their own usernames and passwords, then they maintain control over their accounts, but they face difficulties remembering complex passwords and tend to use weak or reused passwords

Engineering Contradiction:
Improvepassword strengthVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a password management service as an intermediary between users and network sites. This service automatically generates, stores, and manages strong unique passwords for each user's accounts across multiple websites, eliminating the need for users to manually remember complex passwords while maintaining account security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users create unique strong passwords for each website, then security is improved, but the complexity of managing multiple passwords increases significantly

Engineering Contradiction:
Improveaccount securityVSAvoidcredential management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the password management function from the user's direct control and transfers it to a dedicated password management service. The service handles password generation, storage, and retrieval automatically, allowing users to focus on account security without being burdened by the complexity of managing multiple unique passwords.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The password management service creates and manages copied versions of user credentials across multiple network sites. Instead of users directly handling each unique password, the service generates and stores copies of strong unique passwords for each account, simplifying the overall management complexity while maintaining security.

Inventive Principle:
Principle #26Copying

3Ease of operation

If users reuse the same password across multiple websites, then password management becomes simpler, but security vulnerabilities increase

Engineering Contradiction:
Improvepassword managementVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent enables the password management service to automatically generate and manage unique strong passwords for each user's accounts across multiple websites. The service autonomously handles password creation, storage, and updates without requiring user intervention, thereby eliminating security vulnerabilities associated with password reuse while keeping management simple for users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11444936B2Managing security credentials
Publication Date: 2022.09.13 AMAZON TECH INC
  • US11444936B2 patent drawing
  • US11444936B2 patent drawing
  • US11444936B2 patent drawing

AI summary

Disclosed are various embodiments for managing security credentials. In one embodiment, knowledge-based questions are selected in response to failing to receive a valid master security credential in a request to authenticate a user account for access to account data. In response to receiving the request, the plurality of knowledge-based questions are provided to an application. Answers to the knowledge-based questions are received and scored. Access is granted to establish a new master security credential based at least in part on the score meeting or exceeding a predetermined threshold.