Recovery Token System for Secure Account Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user account recovery methods are inadequate due to difficulties in choosing secure and memorable recovery questions, vulnerabilities in email-based password recovery, and limitations in federated systems, which can be inconvenient and ineffective.
Innovation Solution
A recovery provider system is utilized to facilitate user account recovery by generating and validating a recovery token, allowing users to create new login credentials, and interacting with the account provider system to restore access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If email-based password recovery is used, then users can recover their accounts, but the system becomes vulnerable to email security breaches and phishing attacks
Solution Approach 1:
The patent introduces a recovery provider system as an intermediary between the user and the account provider. This mediator generates and manages recovery tokens independently of the email system, eliminating direct dependency on email security while maintaining account recovery functionality. The recovery provider acts as a trusted third party that handles credential recovery without exposing the account provider's systems to email-based attacks.
Solution Approach 2:
The patent replaces the mechanical email-based recovery mechanism with a cryptographic token-based system. Instead of relying on email delivery and parsing, the system uses signed recovery tokens that are validated through public key infrastructure. This substitution eliminates vulnerabilities associated with email security while maintaining the account recovery function.
2Reliability
If recovery questions are used for account recovery, then users can regain access, but it becomes difficult to choose secure and memorable questions
Solution Approach 1:
The patent extracts the recovery question mechanism entirely and replaces it with a token-based system. Instead of relying on users to remember and answer security questions, the system uses pre-generated recovery tokens that are automatically handled by the recovery provider. This extraction eliminates the difficulty of choosing secure questions while maintaining recovery functionality.
Solution Approach 2:
The recovery provider system performs the recovery process automatically without requiring user intervention in the complex decision-making about security questions. The system self-manages token generation, validation, and credential restoration, freeing the user from the burden of selecting and remembering secure recovery questions.
3Adaptability or versatility
If federated systems are used for account recovery, then account provider systems can delegate recovery, but the system becomes less flexible and more complex
Solution Approach 1:
The recovery provider system is designed as a universal solution that can work with multiple account provider systems through standardized protocols. Instead of requiring complex federated integrations for each provider, the system provides a unified interface that handles recovery across different platforms, simplifying the overall architecture while maintaining flexibility.
Solution Approach 2:
The patent segments the account recovery function into a separate, independent recovery provider system rather than embedding it within the account provider's federated infrastructure. This segmentation isolates the complexity of recovery logic from the account provider systems, allowing each to operate independently while maintaining flexibility through standardized communication protocols.
Data Source
AI summary
Systems, methods, and non-transitory computer-readable media can determine a user request to recover control of an account for accessing an account provider system. A recovery token that is associated with the account can be obtained. A signature for at least a portion of the recovery token can be generated. Metadata information associated with the account provider system can be obtained. The signed recovery token can be provided to the account provider system based at least in part on the metadata information, wherein the account provider system is configured to provide control of the account to the user upon validating the signed recovery token.


