Automated Password Reset via User Data Challenges
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for password resetting in enterprise environments are costly due to human involvement, as employees often need to contact the help desk for assistance, which accounts for a significant portion of help desk requests.
Innovation Solution
An automated system that authenticates users by generating challenges based on user-specific information such as calendar entries, email, contact lists, and past activities, allowing password reset without human intervention, using an enterprise server that mines user data to create security questions and verify identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated authentication using user-specific information is implemented, then productivity and cost-efficiency improve, but device complexity increases
Solution Approach 1:
The system enables users to reset their own passwords automatically without requiring help desk intervention. The authentication process uses user-specific information (calendar entries, email, contact lists, past activity) that the user themselves can access and verify, making the system self-service oriented and eliminating the need for human operators.
Solution Approach 2:
The patent introduces an intermediary authentication system that mediates between the user and the password reset function. This intermediary layer uses user-specific information as a middle ground for verification, avoiding both simple password-based authentication and complex human intervention, thereby resolving the contradiction between automation and complexity.
2Reliability
If traditional help desk verification is used, then authentication reliability is maintained, but loss of time increases
Solution Approach 1:
The system performs preliminary actions by pre-collecting and storing user-specific information (calendar entries, email data, contact lists, past activity) before authentication is needed. When password reset is required, this pre-prepared information enables immediate verification without requiring real-time human intervention, thus maintaining reliability while reducing time loss.
Solution Approach 2:
The patent replaces the mechanical system of human help desk verification with an automated electronic authentication mechanism. The system uses computer-based analysis of user-specific information to verify identity, substituting human cognitive verification with automated data matching, thereby maintaining reliability while eliminating time delays associated with human interaction.
3Ease of operation
If automated authentication is implemented, then ease of operation improves, but object-generated harmful factors increase
Solution Approach 1:
The system changes authentication parameters by moving from simple password verification to multi-factor analysis of user-specific information (calendar patterns, email communication patterns, contact list relationships, historical activity). This parameter change enhances ease of operation for legitimate users while creating more sophisticated security parameters that detect and prevent automated attacks and fraud.
Solution Approach 2:
The authentication system incorporates feedback mechanisms that analyze user responses against stored user-specific information patterns. The system provides feedback on authentication attempts and adjusts verification requirements based on detected anomalies, creating a dynamic security system that maintains ease of operation for legitimate users while automatically increasing security measures when potential threats are detected.
Data Source
AI summary
One embodiment of the present invention provides a system for automatically authenticating a user. During operation, the system receives a user's request for authentication. The system then extracts information associated with the user from user-specific information stored in an enterprise computer. The extracted user information does not explicitly relate to a password. The system further generates one or more challenges based on the extracted user information, and receives the user's response to the challenges. Subsequently, the system compares the user's response to the extracted user information, and authenticates the user.


