Rules-Driven Multiple Password Stack for Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password authentication systems are cumbersome for users due to strict rules governing password creation and reuse, leading to the use of weak passwords across multiple accounts, and are vulnerable to attacks.

Innovation Solution

A rules-driven multiple password system where a stack of passwords is created based on user-defined conditions, allowing automatic rotation and expiration of passwords to avoid reuse restrictions, with notifications to the user when passwords change.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single password is used for user accounts with strict reuse rules, then system security is maintained according to rules, but user convenience deteriorates and weak passwords are forced

Engineering Contradiction:
Improvepassword securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the single password into multiple passwords organized in a stack structure. Each password in the stack can be used independently, allowing the system to rotate through multiple passwords rather than reusing a single password. This segmentation resolves the contradiction by maintaining security through password variety while improving user convenience through automated rotation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-generating a stack of passwords in advance. When a password needs to be changed, the system automatically selects the next password from the pre-prepared stack, eliminating the need for users to manually create new passwords that comply with complex rules. This resolves the contradiction by maintaining security through pre-planned password rotation while improving convenience through automation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple passwords are manually managed by users, then password rotation security is improved, but time consumption and complexity increase

Engineering Contradiction:
Improvepassword rotation securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by automatically managing the password stack without requiring user intervention. The system monitors password usage, detects when rotation is needed, and automatically selects and applies the next password from the stack. This resolves the contradiction by maintaining security through automated password rotation while eliminating the time consumption associated with manual password management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs periodic action by rotating passwords at predetermined intervals or based on usage criteria. The password stack is designed to automatically cycle through passwords according to established rules, providing periodic security updates without requiring user time investment. This resolves the contradiction by maintaining security through regular password rotation while eliminating manual time consumption.

Inventive Principle:
Principle #19Periodic action

3Reliability

If password stack depth is increased to overcome reuse rules, then password variety and security are improved, but system complexity increases

Engineering Contradiction:
Improvepassword varietyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a password stack as an intermediary structure between the user and the authentication system. This stack manages multiple passwords and handles the complexity of rotation internally, presenting a simplified interface to users. The intermediary resolves the contradiction by providing password variety through the stack structure while hiding the system complexity from users through automated management.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If automatic password change is implemented, then user burden is reduced, but notification and monitoring requirements increase

Engineering Contradiction:
Improveuser burdenVSAvoidmonitoring requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms to notify users when passwords change automatically. The monitoring component tracks password usage and triggers notifications to inform users of rotations, providing transparency without requiring continuous user attention. This resolves the contradiction by reducing user burden through automation while managing monitoring complexity through structured feedback loops.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9231981B2Rules driven multiple passwords
Publication Date: 2016.01.05 AIRBNB INC
  • US9231981B2 patent drawing
  • US9231981B2 patent drawing
  • US9231981B2 patent drawing

AI summary

A rules driven multiple passwords system is provided wherein a list of stored passwords are used in rotation over time in accordance with a set of rules or conditions managed by the system. With such an arrangement, the currently active password of a system User may automatically be changed, in accordance with the rules or conditions, to the next password in the list. The User is notified as to the newly assigned password.