Password Strength Feedback via Community Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional password strength feedback mechanisms do not consider the user community context, limiting their effectiveness in encouraging users to choose stronger passwords.

Innovation Solution

A system that detects password events, assesses password strength against community-based metrics, and provides feedback to users, comparing their password strength to that of their peers without revealing actual password data, to encourage stronger password choices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password strength feedback mechanisms are used, then users receive feedback on their password strength, but the feedback does not include context of the user community limiting effectiveness

Engineering Contradiction:
Improvepassword strengthVSAvoidfeedback context
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system provides feedback to users about their password strength relative to their peer group. The feedback mechanism compares individual password strength metrics (entropy, complexity, length) against aggregated community metrics and presents this comparison to users, motivating them to choose stronger passwords by showing how their choices compare to others in their community.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the parameters of password strength evaluation by introducing community-based metrics alongside traditional strength metrics. Instead of evaluating passwords in isolation using fixed algorithms, the system dynamically adjusts evaluation parameters to include relative performance against peer groups, thereby adapting the feedback to contextualize strength within the user community.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If community-based password strength comparison is implemented, then users are motivated to choose stronger passwords, but system complexity increases

Engineering Contradiction:
Improvepassword strengthVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary computation of password strength metrics and community aggregates in advance. Strength metrics for individual passwords (entropy, complexity scores) and aggregated community metrics are pre-calculated and stored, enabling rapid comparison when users need feedback without requiring complex real-time computation during the actual feedback delivery moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary layer that aggregates and processes community password data separately from the core authentication system. This intermediary component handles the complex tasks of collecting, normalizing, and comparing password metrics across the community, thereby isolating complexity from the main user authentication flow and making the system more manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If password strength metrics are collected and compared, then feedback accuracy improves, but data processing requirements increase

Engineering Contradiction:
Improvefeedback accuracyVSAvoiddata processing
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts and focuses on specific, high-impact password strength metrics rather than processing all possible password characteristics. By identifying and measuring only the most relevant metrics (entropy, complexity, length) and their relative distributions within the community, the system achieves accurate feedback while minimizing the quantity of data that needs to be collected, stored, and processed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9009815B2Increasing chosen password strength
Publication Date: 2015.04.14 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9009815B2 patent drawing
  • US9009815B2 patent drawing
  • US9009815B2 patent drawing

AI summary

An approach is provided to increase password strength in a group of users. The approach detects a password event corresponding to one of the users. In response to the detected password event, the approach identifies a strength of the user's password and compares it to one or more password strength metrics that correspond to the group of users. The password strength comparison data is then transmitted as feedback back to the user.