Transient Event Data Authentication for Password Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing password recovery methods rely on static user-provided information that is often shared across multiple platforms, making it vulnerable to unauthorized access, as the information used for recovery is not secret and can be easily obtained from social networking sites.
Innovation Solution
The use of transient event data to generate authentication questions specific to each computing resource, based on the user's previous interactions, providing a dynamic and resource-specific authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static user-provided information (e.g., mother's maiden name, city of birth) is used for password recovery, then the recovery process is simple and easy to implement, but the security is weak because this information is often shared across multiple platforms and can be easily obtained from social networking sites
Solution Approach 1:
The patent transforms the static password recovery mechanism into a dynamic one by using transient event data that changes over time. Instead of relying on fixed personal information, the system uses time-varying data from user interactions with the computing resource, making the recovery process both secure and adaptive to current user behavior patterns
Solution Approach 2:
The patent changes the fundamental parameter used for authentication from static personal information to dynamic interaction-based data. By shifting from fixed attributes (birth city, pet names) to variable attributes (recent file accesses, application usage patterns, login times), the system achieves both security and operational simplicity
2Adaptability or versatility
If the same password recovery information is collected for all websites, then the user experience is consistent across platforms, but the security risk increases because unauthorized persons can access multiple accounts using the same recovery data
Solution Approach 1:
The patent applies local quality by making each computing resource have its own unique authentication characteristics. Instead of using universal personal information, the system generates recovery questions based on local interaction data specific to each resource (e.g., files accessed on this specific device, applications used on this specific platform), ensuring that compromise of one system does not affect others
Solution Approach 2:
The patent segments the authentication process by creating resource-specific recovery mechanisms. Each computing resource maintains its own transient event data and generates independent authentication questions, dividing the previously unified recovery process into isolated, resource-specific segments that prevent cross-contamination of security risks
3Ease of operation
If personal information about pets, jobs, and sports teams is used for password recovery, then the questions are easy for users to answer, but the information becomes public through social networking and is no longer secret
Solution Approach 1:
The patent creates a copy of user knowledge that exists only within the computing resource environment. Instead of using real-world personal information that users have publicly shared, the system captures and uses copies of interaction data (file access patterns, application usage) that are specific to the digital environment and not exposed elsewhere
Solution Approach 2:
The patent introduces transient event data as an intermediary between the user and the authentication system. This intermediary layer translates user interactions with the computing resource into authentication questions, preventing direct exposure of personal information while maintaining the ease of answering through familiar interaction patterns
Data Source
AI summary
Some embodiments provide a method for authenticating a user to access computing resources that uses transient event data regarding previous interactions of the user with the computing resources. The method receives a notification that a user is unable to provide a correct user identifier and password. The method generates authentication questions for the remote user using the transient event data. The authentication questions are presented to the user. The method authenticates the user based on answers to the password recovery questions. The user may be a remote user and the computing resources are a set of application servers to which the user has forgotten a password. The computing resources may be a portable device that the user wishes to access remotely in order to delete data from the portable device.


