Remote Token Password Reset via Third-Party Credential

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password reset mechanisms for tokens, such as smart cards, are cumbersome and insecure, especially in large systems where a single security officer password is shared across multiple tokens, leading to scalability issues and increased security risks if compromised.

Innovation Solution

A remote password reset method using a third-party authentication credential, such as a social security number or secret question, is implemented, allowing for secure communication between a security server and the token to update the password after mutual authentication, reducing the burden on token management systems and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a security officer is provided with a global password to unlock smart cards, then password reset capability is achieved, but security risk increases and scalability is limited

Engineering Contradiction:
Improvepassword reset capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security architecture by separating token management functions between the security officer and the token management system. The TMS maintains a database of token identifiers and associated passwords, allowing the security officer to request password resets for specific tokens without possessing global access credentials. This segmentation eliminates the security risk of global passwords while maintaining password reset capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The token management system acts as an intermediary between the security officer and the tokens. When a security officer needs to reset a password, they submit a request through the TMS, which then communicates with the token to establish a secure communication channel and reset the password. This intermediary approach eliminates the need for security officers to have direct global access to all tokens.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a security officer is provided with a global password to unlock smart cards, then password reset capability is achieved, but system scalability is reduced

Engineering Contradiction:
Improvepassword reset capabilityVSAvoidsystem scalability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The token management system provides universal functionality for managing multiple tokens across the organization. It maintains a centralized database that can store and manage credentials for any number of tokens, allowing the system to scale from small to large deployments without requiring changes to the password reset process. The TMS can handle requests for any token in its database, making the system adaptable to growing organizational needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security officer passwords are managed on a per token basis, then security risk is reduced, but management complexity increases

Engineering Contradiction:
Improvesecurity riskVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The token management system provides self-service functionality by automatically managing the complexity of per-token credential management. When a security officer requests a password reset, the TMS handles the entire process including validating the token identifier, establishing secure communication channels, and resetting the password without requiring the security officer to manually manage individual token credentials. This automation eliminates the management burden while maintaining enhanced security.

Inventive Principle:
Principle #25Self-service

4Reliability

If a list of security officer passwords for each token is maintained, then per-token security is achieved, but maintenance burden increases

Engineering Contradiction:
Improveper-token securityVSAvoidmaintenance burden
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical approach of manually maintaining lists of per-token passwords with an automated electronic system. The token management system stores token identifiers and associated passwords in a database, and automatically retrieves and applies the correct credentials when processing password reset requests. This substitution eliminates the time-consuming manual maintenance of credential lists while maintaining per-token security through automated, accurate credential management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8099765B2Methods and systems for remote password reset using an authentication credential managed by a third party
Publication Date: 2012.01.17 RED HAT INC
  • US8099765B2 patent drawing
  • US8099765B2 patent drawing
  • US8099765B2 patent drawing

AI summary

Embodiments of the present invention provide a secure remote password reset capability. In some embodiments, an exemplary method provides a remote reset of a password associated with a token in a computer system having a security server. A token-based authentication process is activated by connecting the token to the security server. A server-based authentication process is initiated in the security server by activating a password reset process in a security client. The server-based authentication process communicates with the token-based authentication process over a secure channel. An authentication credential is managed by a third party agent that supplies a query and the authentication credential as a correct response to the query to the security server. A prompt provided by the password reset process collects the authentication credential and a new password. After the authentication credential is validated mutually authentication is performed between the security server and the token. The token is updated with the new password based on a successful result of the mutual authentication.