Rules-Driven Multiple Password Stack for Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current password authentication systems are cumbersome for users due to strict rules governing password creation and reuse, leading to the use of weak passwords across multiple accounts, and are vulnerable to attacks.
Innovation Solution
A rules-driven multiple password system where a stack of passwords is created based on user-defined conditions, allowing automatic rotation and expiration of passwords to avoid reuse restrictions, with notifications to the user when passwords change.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single password is used for user accounts with strict reuse rules, then system security is maintained according to rules, but user convenience deteriorates and weak passwords are forced
Solution Approach 1:
The patent segments the single password into multiple passwords organized in a stack structure. Each password in the stack can be used independently, allowing the system to rotate through multiple passwords rather than reusing a single password. This segmentation resolves the contradiction by maintaining security through password variety while improving user convenience through automated rotation.
Solution Approach 2:
The system performs preliminary action by pre-generating a stack of passwords in advance. When a password needs to be changed, the system automatically selects the next password from the pre-prepared stack, eliminating the need for users to manually create new passwords that comply with complex rules. This resolves the contradiction by maintaining security through pre-planned password rotation while improving convenience through automation.
2Reliability
If multiple passwords are manually managed by users, then password rotation security is improved, but time consumption and complexity increase
Solution Approach 1:
The system implements self-service by automatically managing the password stack without requiring user intervention. The system monitors password usage, detects when rotation is needed, and automatically selects and applies the next password from the stack. This resolves the contradiction by maintaining security through automated password rotation while eliminating the time consumption associated with manual password management.
Solution Approach 2:
The system employs periodic action by rotating passwords at predetermined intervals or based on usage criteria. The password stack is designed to automatically cycle through passwords according to established rules, providing periodic security updates without requiring user time investment. This resolves the contradiction by maintaining security through regular password rotation while eliminating manual time consumption.
3Reliability
If password stack depth is increased to overcome reuse rules, then password variety and security are improved, but system complexity increases
Solution Approach 1:
The patent introduces a password stack as an intermediary structure between the user and the authentication system. This stack manages multiple passwords and handles the complexity of rotation internally, presenting a simplified interface to users. The intermediary resolves the contradiction by providing password variety through the stack structure while hiding the system complexity from users through automated management.
4Ease of operation
If automatic password change is implemented, then user burden is reduced, but notification and monitoring requirements increase
Solution Approach 1:
The system implements feedback mechanisms to notify users when passwords change automatically. The monitoring component tracks password usage and triggers notifications to inform users of rotations, providing transparency without requiring continuous user attention. This resolves the contradiction by reducing user burden through automation while managing monitoring complexity through structured feedback loops.
Data Source
AI summary
A rules driven multiple passwords system is provided wherein a list of stored passwords are used in rotation over time in accordance with a set of rules or conditions managed by the system. With such an arrangement, the currently active password of a system User may automatically be changed, in accordance with the rules or conditions, to the next password in the list. The User is notified as to the newly assigned password.


