Strong Proof Authentication for Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

User accounts are vulnerable to attacks due to weak authentication methods like passwords, which can be compromised, allowing malicious users to change security settings and lock out legitimate users.

Innovation Solution

Implementing a system that uses multiple strong proofs associated with a user account, requiring confirmation via these proofs to change security settings, ensuring that changes are only permitted if confirmed by the account holder through stronger verification methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple strong proofs are required for confirmation, then account security is improved, but the complexity of the authentication system increases

Engineering Contradiction:
Improveaccount securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent proof methods (password, email confirmation, SMS code, security questions). Each proof method operates as a separate module that can be individually evaluated, allowing the system to maintain high security through multiple layers while keeping each individual component relatively simple and manageable.

Inventive Principle:
Principle #1Segmentation

2Reliability

If strong proofs with higher strength than the proof being changed are required, then the security setting change is protected, but the difficulty of detecting and measuring proof strength increases

Engineering Contradiction:
Improvesecurity setting protectionVSAvoidproof strength verification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary classification and strength assignment of different proof methods during system setup and configuration. Each proof method (email, SMS, security questions) is pre-evaluated and assigned a strength level. When a security setting change is requested, the system automatically compares the strength of available proofs against the required threshold, eliminating the need for complex real-time analysis of proof strength.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2540028B1Protecting account security settings using strong proofs
Publication Date: 2017.08.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2540028B1 patent drawingFigure 1
  • EP2540028B1 patent drawingFigure 2
  • EP2540028B1 patent drawingFigure 3

AI summary

One or more strong proofs are maintained as associated with an account of a user. In response to a request to change a security setting of the account, an attempt is made to confirm the request by using one of the one or more strong proofs to notify the user. The change is permitted if the request is confirmed via one or more of the strong proofs, and otherwise the change to the security setting of the account is kept unchanged.