Password Security Risk Detection via Personal Data Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The widespread use of passwords for secure access to computing and network resources often relies on personal information for creation, management, and recovery, which can create vulnerabilities as this information can be exploited by unauthorized users, leading to potential security breaches.

Innovation Solution

A system that includes a content inspector, password inspector, and comparator to detect and compare provided personal information with password-related information, determining a risk level and notifying users if the publication of personal information poses a risk to password security, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal information is used for password creation and management, then password memorability and user convenience are improved, but security vulnerability increases due to potential exposure of personal information on networks

Engineering Contradiction:
Improvepassword memorabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection and comparison of personal information against password-related information before the user publishes content. By proactively identifying potential security risks before they materialize, the system prevents vulnerable password practices without requiring users to change their behavior patterns or memorability strategies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides immediate feedback to users when their published personal information matches password-related data. This feedback loop allows users to understand the security risk and take corrective action (such as changing the password or removing the published information) while the vulnerability still exists, rather than waiting for a security breach to occur.

Inventive Principle:
Principle #23Feedback

2Reliability

If password security measures are strengthened by avoiding personal information, then security risk is reduced, but user convenience and password memorability deteriorate

Engineering Contradiction:
Improvepassword securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables users to maintain their preferred password practices (using personal information for memorability) while the automated inspection system handles the security verification. Users continue to create and manage passwords using personally meaningful information, but the system independently performs the security check against published personal information, eliminating the need for users to manually verify security implications.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If users publish personal information on networks, then information sharing and communication are improved, but password security is compromised due to potential unauthorized access

Engineering Contradiction:
Improveinformation sharingVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by detecting and alerting users to potential security compromises before unauthorized access can occur. By comparing published personal information against stored password-related information in advance, the system prevents the security breach from happening rather than responding after the fact.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The inspection system acts as an intermediary between the user's information sharing activities and their password security. It monitors the interaction between published personal information and stored password data, mediating the potential conflict by alerting users to risks and enabling them to make informed decisions about what information to publish.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8539599B2Password protection using personal information
Publication Date: 2013.09.17 SAP SE
  • US8539599B2 patent drawing
  • US8539599B2 patent drawing
  • US8539599B2 patent drawing

AI summary

Provided personal information from a user may be determined, the provided personal information being associated with network publication thereof. A comparison of the provided personal information with password-related information may be performed. Based on the comparison, it may be determined that a risk level associated with the network publication relative to password security of at least one password associated with the password-related information exceeds a predetermined risk level. The user may be notified that the network publication of the provided personal information is associated with potential compromise of the password security of the at least one password.