Selective Password Synchronization for Heterogeneous Account Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password synchronization mechanisms lack granularity and fail to address real-world environments where individuals have multiple accounts with different risk levels and conflicting password complexity rules, leading to security risks and synchronization failures.

Innovation Solution

Implementing selective password synchronization mechanisms that group accounts based on policies, rules, and exclusion rules, allowing for granular control over which accounts share passwords, including role-based and resource-type-specific synchronization, to ensure secure and compliant password management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If password synchronization is applied to all accounts, then password management consistency is improved, but security risk increases and synchronization may fail due to conflicting password rules

Engineering Contradiction:
Improvepassword management consistencyVSAvoidsecurity risk
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent segments accounts into different groups based on risk levels, resource types, and password policy requirements. High-risk accounts (e.g., administrator accounts) are separated from low-risk accounts (e.g., user accounts), allowing selective password synchronization only within appropriate groups. This segmentation prevents a single compromised password from affecting all accounts while maintaining consistency within each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different password synchronization policies to different account groups based on their specific characteristics. High-risk accounts have different synchronization rules compared to low-risk accounts. This local quality approach allows the system to tailor password management strategies to the specific security requirements of each account type, rather than applying a uniform policy to all accounts.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If password synchronization is applied to all accounts, then ease of password management is improved, but adaptability to different password policies deteriorates

Engineering Contradiction:
Improveease of password managementVSAvoidadaptability to different password policies
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic password synchronization policies that automatically adjust based on account characteristics, resource types, and organizational requirements. The system can dynamically determine which accounts should receive synchronized passwords and which should maintain unique passwords, adapting to changing security requirements and password policies without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of password synchronization by introducing multiple synchronization policies with different characteristics. Instead of a single binary synchronization decision, the system uses multiple parameters including risk level, resource type, and policy priority to determine synchronization behavior. This allows the system to adapt to different password complexity rules and requirements across various accounts and resources.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If selective password synchronization is implemented, then security and policy compliance are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and policy complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal password synchronization framework that handles multiple account types, risk levels, and password policies through a single integrated system. The selective synchronization mechanism serves multiple functions simultaneously: it maintains security by preventing compromise propagation, ensures policy compliance through configurable rules, and provides ease of management through centralized control. This multi-functionality reduces the need for separate systems for different security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service capabilities where the system automatically determines which accounts should receive password synchronization based on pre-configured policies and rules. The selective synchronization mechanism autonomously evaluates account characteristics, applies appropriate policies, and executes synchronization decisions without requiring manual intervention for each account. This self-service approach reduces operational complexity while maintaining high security and compliance standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9930032B2Selective password synchronization
Publication Date: 2018.03.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9930032B2 patent drawing
  • US9930032B2 patent drawing
  • US9930032B2 patent drawing

AI summary

A mechanism is provided for selective password synchronization. An indication is received that a password is to be changed for an account in a plurality of accounts associated with an individual, where the indication includes a new password. Responsive to receiving the indication of the password change, the account is grouped with one or more other accounts in the plurality of accounts thereby forming a first subset of accounts, where grouping the account with the one or more other accounts in the plurality of accounts excludes at least one account in the plurality of accounts thereby forming a second subset of accounts. The new password is propagated to the first subset of accounts according to a first policy. The new password is propagated to a second subset of accounts of the plurality of accounts according to a second policy, where the second policy is different from the first policy.