Automated Account Recovery Using Trusted Device Cookies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in restoring access to compromised accounts due to shared passwords and lack of secure verification methods, leading to time-consuming manual processes and security challenges for both users and service providers.

Innovation Solution

Implementing a system where service providers assess account risk and use verification cookies associated with trusted devices to grant or deny access, automatically resetting passwords upon breach detection, ensuring only valid, trusted devices can access accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual account restoration processes are used, then security verification can be performed, but the process becomes time-consuming and complex for users

Engineering Contradiction:
Improveaccount securityVSAvoidaccount restoration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing trusted device relationships and storing verification cookies before account compromise occurs. When account restoration is needed, the system can immediately verify the user's identity through the pre-stored trusted device information, eliminating the need for time-consuming manual verification processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service account restoration by allowing users to automatically verify their identity through trusted device recognition. The verification cookie stored on the user's device automatically proves ownership without requiring user intervention or customer service involvement, making the restoration process both secure and rapid.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If communication with compromised email accounts is used for verification, then account restoration can be attempted, but security is compromised since the email account may also be hacked

Engineering Contradiction:
Improveaccount restoration processVSAvoidverification security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary verification mechanism using trusted device information and verification cookies, which mediate between the user and the account restoration process. This intermediary approach bypasses compromised communication channels like email by using the device itself as the verification medium, ensuring that even if email is hacked, the verification process remains secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If verification cookies are required for all account access, then security is improved, but user convenience decreases due to additional verification steps

Engineering Contradiction:
Improveaccount access securityVSAvoidaccount access process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies partial verification by requiring full cookie validation only when necessary (e.g., during account restoration or suspicious activity), while allowing streamlined access during normal operations. This selective application of verification maintains security when needed while preserving user convenience during routine account access.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11936651B2Automated account recovery using trusted devices
Publication Date: 2024.03.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11936651B2 patent drawing
  • US11936651B2 patent drawing
  • US11936651B2 patent drawing

AI summary

Embodiments of the invention are directed to an automated account restoration system. In some embodiments, the system determines a state of an account based on a likelihood that the account has been compromised. If the account is determined to be in a low-risk state, then upon an successful login to that account, a verification cookie may be generated which is unique to a user device used to access the account. If the account is determined to be in a high-risk state, then system may prevent access to the account except by user devices that include a valid verification cookie.