Transient Event Data Authentication for Password Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing password recovery methods rely on static user-provided information that is often shared across multiple platforms, making it vulnerable to unauthorized access, as the information used for recovery is not secret and can be easily obtained from social networking sites.

Innovation Solution

The use of transient event data to generate authentication questions specific to each computing resource, based on the user's previous interactions, providing a dynamic and resource-specific authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static user-provided information (e.g., mother's maiden name, city of birth) is used for password recovery, then the recovery process is simple and easy to implement, but the security is weak because this information is often shared across multiple platforms and can be easily obtained from social networking sites

Engineering Contradiction:
Improvepassword recovery process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms the static password recovery mechanism into a dynamic one by using transient event data that changes over time. Instead of relying on fixed personal information, the system uses time-varying data from user interactions with the computing resource, making the recovery process both secure and adaptive to current user behavior patterns

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter used for authentication from static personal information to dynamic interaction-based data. By shifting from fixed attributes (birth city, pet names) to variable attributes (recent file accesses, application usage patterns, login times), the system achieves both security and operational simplicity

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the same password recovery information is collected for all websites, then the user experience is consistent across platforms, but the security risk increases because unauthorized persons can access multiple accounts using the same recovery data

Engineering Contradiction:
Improvecross-platform consistencyVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making each computing resource have its own unique authentication characteristics. Instead of using universal personal information, the system generates recovery questions based on local interaction data specific to each resource (e.g., files accessed on this specific device, applications used on this specific platform), ensuring that compromise of one system does not affect others

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the authentication process by creating resource-specific recovery mechanisms. Each computing resource maintains its own transient event data and generates independent authentication questions, dividing the previously unified recovery process into isolated, resource-specific segments that prevent cross-contamination of security risks

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If personal information about pets, jobs, and sports teams is used for password recovery, then the questions are easy for users to answer, but the information becomes public through social networking and is no longer secret

Engineering Contradiction:
Improveuser ability to answer questionsVSAvoidsecrecy of recovery information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent creates a copy of user knowledge that exists only within the computing resource environment. Instead of using real-world personal information that users have publicly shared, the system captures and uses copies of interaction data (file access patterns, application usage) that are specific to the digital environment and not exposed elsewhere

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces transient event data as an intermediary between the user and the authentication system. This intermediary layer translates user interactions with the computing resource into authentication questions, preventing direct exposure of personal information while maintaining the ease of answering through familiar interaction patterns

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8973154B2Authentication using transient event data
Publication Date: 2015.03.03 APPLE INC
  • US8973154B2 patent drawing
  • US8973154B2 patent drawing
  • US8973154B2 patent drawing

AI summary

Some embodiments provide a method for authenticating a user to access computing resources that uses transient event data regarding previous interactions of the user with the computing resources. The method receives a notification that a user is unable to provide a correct user identifier and password. The method generates authentication questions for the remote user using the transient event data. The authentication questions are presented to the user. The method authenticates the user based on answers to the password recovery questions. The user may be a remote user and the computing resources are a set of application servers to which the user has forgotten a password. The computing resources may be a portable device that the user wishes to access remotely in order to delete data from the portable device.