Password Manager for Legacy Authentication 2FA Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems that rely on one-factor authentication, such as static passwords, are vulnerable to attacks like phishing and pharming, and implementing two-factor authentication (2FA) is often hindered by cost, system compatibility, and the need for significant upgrades or modifications, especially in legacy systems like Kerberos-based systems.

Innovation Solution

A system and method that transform existing one-factor authentication systems into 2FA by using a token manager to generate dynamic codes and a password manager to replace static passwords with new authentication codes formed by combining static and dynamic passwords, without requiring modifications to the existing system, through operations like 'Change Password' or 'Set/Reset Password', allowing for secure access based on both factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication is implemented using commercial solutions (RSA, VASCO, DS3), then security is improved, but system complexity and deployment cost increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component called the Password Manager that acts as a mediator between the existing authentication system and the 2FA token. This Password Manager transparently handles the dynamic password generation and integration, allowing legacy systems to benefit from 2FA without requiring complex modifications to their core authentication logic or protocol stacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the Password Manager to automatically generate, manage, and rotate dynamic passwords without requiring manual configuration or intervention in the legacy authentication system. The token and Password Manager work autonomously to provide 2FA protection while the existing system continues to operate unchanged.

Inventive Principle:
Principle #25Self-service

2Reliability

If two-factor authentication is integrated into existing systems, then security is improved, but deployment and maintenance difficulty increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the 2FA implementation into independent, modular components: the authentication token and the Password Manager. This segmentation allows the 2FA functionality to be deployed as a separate layer that interfaces with the existing authentication system without requiring integration into the core system architecture, thereby simplifying deployment and maintenance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Password Manager is designed as a universal component that can interface with multiple different legacy authentication systems and protocols. It provides multi-functional capability by handling various authentication methods (Kerberos, NTLM, etc.) through a single implementation, making deployment across diverse systems easier and more maintainable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If Kerberos protocol is used for authentication, then system compatibility is improved, but two-factor authentication compatibility deteriorates

Engineering Contradiction:
Improvesystem compatibilityVSAvoid2FA compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The Password Manager serves as an intermediary layer between the Kerberos protocol and the 2FA token. It translates and adapts the authentication flows, allowing the Kerberos-based legacy system to work with the dynamic password from the token without requiring modifications to the Kerberos protocol itself, thereby maintaining system compatibility while enabling 2FA.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If legacy applications are maintained without modification, then system feasibility is improved, but security protection deteriorates

Engineering Contradiction:
Improvesystem feasibilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements a nested architecture where the 2FA Password Manager and token functionality are nested around the existing legacy authentication system. The outer layer (Password Manager) provides enhanced security through 2FA, while the inner layer (legacy system) remains unchanged and operational. This nesting allows security protection to be added without modifying the core legacy application.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP2394389B1Transforming static password systems to become 2-factor authentication
Publication Date: 2019.12.04 DATA SECURITY SYST SOLUTIONS PTE
  • EP2394389B1 patent drawingFigure 1
  • EP2394389B1 patent drawingFigure 2
  • EP2394389B1 patent drawingFigure 3

AI summary

The present invention provides systems and processes for transforming any system that implements a static password authentication or 1st-factor authentication so as to enforce strong 2-factor authentication, requiring the user to present both a static password and a dynamic password, without having to modify the existing system.