Cross-Enterprise Security Exchange for Password Reuse Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a centralized framework to detect and prevent password reuse across different computer systems, leading to increased risk and liability for organizations due to cybercriminals exploiting reused credentials, while data privacy laws restrict the sharing of user information.

Innovation Solution

A cross-enterprise computer security exchange that allows organizations to share anonymized user account information and authentication data with a trusted third party for comparison and analysis, enabling detection of password reuse while maintaining data privacy and compliance with regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If organizations share user account information and authentication data to detect password reuse, then detection capability is improved, but data privacy is compromised

Engineering Contradiction:
Improvedetection capabilityVSAvoiddata privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

A trusted third-party intermediary system is introduced to receive, anonymize, and compare authentication data from multiple organizations. The intermediary performs the detection function while ensuring that individual user data remains protected through anonymization techniques, thus resolving the conflict between detection capability and data privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of sharing actual user authentication data, the system uses anonymized copies of the data. The anonymization process creates surrogate representations that retain the ability to detect password reuse while removing personally identifiable information, thereby maintaining detection capability without compromising user privacy.

Inventive Principle:
Principle #26Copying

2Reliability

If a centralized security exchange is implemented to detect password reuse, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized security exchange is designed as a universal platform that serves multiple organizations simultaneously. By consolidating the detection functionality into a single multi-functional system, the patent achieves improved security reliability across all participating organizations while avoiding the complexity of implementing separate detection systems at each organization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The centralized exchange acts as an intermediary that simplifies the overall system architecture by providing a single point of coordination for password reuse detection. Instead of complex peer-to-peer communication between multiple organizations, the intermediary handles all comparisons and notifications, reducing system complexity while maintaining high security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10320775B2Eliminating abuse caused by password reuse in different systems
Publication Date: 2019.06.11 PAYPAL INC
  • US10320775B2 patent drawing
  • US10320775B2 patent drawing
  • US10320775B2 patent drawing

AI summary

Methods, systems, and computer program products for eliminating abuse caused by password reuse in different computer systems are disclosed. For example, a computer-implemented method may include receiving a security request comprising an anonymized version of authentication data from a first computer system of a first organization, analyzing the security request to determine a second computer system of a second organization to contact for detecting reuse of the authentication data, generating a second security request comprising the anonymized authentication data for the second computer system, sending the second security request to the second computer system of the second organization, analyzing a response to the second security request from the second computer system to determine whether the anonymized authentication data associated was detected, and providing a response to the first security request indicating whether the second computer system detected reuse of the authentication data.