Universal Reset Credential System for Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators have unrestricted access to user accounts, allowing potential misuse and unauthorized access, which threatens user privacy and security across various types of accounts, including email, financial, and retail accounts.

Innovation Solution

Implementing a universal reset credential system that separates access permissions, preventing system administrators from accessing the original user password and allowing them to reset access only to a universal reset credential, while restricting changes back to the original password, thus enhancing security and user control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If system administrators are given unrestricted access to user credentials, then system administrators can manage and reset user passwords, but user privacy and security are compromised due to potential misuse and unauthorized access

Engineering Contradiction:
ImproveSystem administrator ability to manage user passwordsVSAvoidUser privacy and security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The credential system is segmented into two distinct parts: the original user credential (first credential) and the universal reset credential. System administrators are granted access only to the universal reset credential, while the original user credential remains inaccessible to administrators. This segmentation allows administrators to reset passwords without being able to view or misuse original user credentials, thereby resolving the contradiction between operational ease and security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The universal reset credential acts as an intermediary mechanism between the system administrator and the user account. Instead of directly accessing original user credentials, administrators interact through the universal reset credential, which serves as a controlled interface. This intermediary structure enables password management functionality while preventing direct exposure to sensitive user credentials, thus maintaining both administrative capability and user security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If system administrators can directly access and modify user credentials, then password reset operations are simple and fast, but the risk of unauthorized access and credential misuse increases

Engineering Contradiction:
ImprovePassword reset efficiencyVSAvoidCredential security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

By dividing credential access into two separate pathways - one for original credentials (user-only access) and one for reset credentials (administrator access) - the system maintains efficient password reset operations through the universal reset credential while protecting original credentials from unauthorized access, thus achieving both productivity and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of allowing administrators direct access to original credentials and requiring users to protect against administrator misuse, the system inverts the approach by giving administrators access only to a universal reset credential while the original credentials remain exclusively under user control. This inversion fundamentally changes the security model to protect user credentials from administrator access while maintaining reset functionality.

Inventive Principle:
Principle #13The other way round (Inversion)

3Ease of operation

If original user passwords are kept accessible to administrators for support purposes, then user account recovery is easier, but the threat of unauthorized access and credential theft increases

Engineering Contradiction:
ImproveAccount recovery accessibilityVSAvoidUnauthorized access threats
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The credential system is divided into original credentials (first credential) and reset credentials (universal reset credential), with distinct access permissions for each. This segmentation enables account recovery through the universal reset credential pathway while keeping original credentials secure from administrator access, thus resolving the contradiction between recovery ease and unauthorized access prevention.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The universal reset credential serves as an intermediary that enables account recovery operations without requiring administrators to access original user passwords. This intermediary mechanism provides the necessary support functionality while maintaining a security barrier that prevents unauthorized access to original credentials, thus achieving both accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11836261B2Secure credentials control method
Publication Date: 2023.12.05 BAIMMT LLC
  • US11836261B2 patent drawing
  • US11836261B2 patent drawing
  • US11836261B2 patent drawing

AI summary

Methods, apparatus, and systems are provided to secure access to an account of a user. The account may have a system administrator. The user may have a credential for accessing the secure data on the account. The methods, apparatus, and systems involve setting a universal reset credential associated with the account, denying the system administrator of the account permission to change the first credential of the access feature, and permitting the system administrator to reset the access feature from the first credential to the universal reset credential.