Weak-Password Account Migration Through Verified Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on services do not efficiently convert accounts associated with applications to use a single set of credentials across multiple authorization domains, leading to the need for multiple sets of credentials and potential exposure of private information.

Innovation Solution

A method and apparatus that convert an account associated with an application to use a single sign-on service by receiving an indication of a weak password, verifying account credentials, requesting and receiving single sign-on credentials, and performing local or third-party authorization to enable seamless access across authorization domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users use separate credentials for each service, then security is improved, but user convenience deteriorates due to needing to remember multiple passwords

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into distinct phases: initial weak password authentication, verification phase, and single sign-on credential issuance. This allows the system to handle different security requirements at different stages, maintaining security while enabling convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification process that acts as a mediator between the weak password and the strong single sign-on credentials. The verification server validates the weak password without exposing it, then issues secure single sign-on credentials that can be used across multiple services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users convert to single sign-on service, then ease of operation is improved, but security risk increases due to potential exposure of private information

Engineering Contradiction:
Improveease of operationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary verification of the weak password through a secure verification server before issuing single sign-on credentials. This preliminary action ensures that only valid accounts can convert to single sign-on, and the verification process itself is designed to protect the weak password from exposure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potentially harmful weak password into a beneficial verification mechanism. The weak password, which would normally be a security liability, becomes a secure gateway that can be verified without exposure, enabling the issuance of stronger single sign-on credentials.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If multiple sets of credentials are maintained, then security is improved, but loss of information increases due to potential exposure of private information

Engineering Contradiction:
ImprovesecurityVSAvoidexposure of private information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the weak password from the authentication process after verification, removing it from the system entirely. The single sign-on credentials are issued without storing or exposing the original weak password, effectively taking out the source of potential information exposure while maintaining security through the verified identity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4158871B1Systems and methods of account verification upgrade
Publication Date: 2025.10.29 APPLE INC
  • EP4158871B1 patent drawingFigure 1
  • EP4158871B1 patent drawingFigure 2
  • EP4158871B1 patent drawingFigure 3

AI summary

A method and apparatus of a device that converts an account associated with an application to use a single sign-on service is described. In an exemplary embodiment, the device receives an indication of a weak password associated with the account. The device further sends a request to verify an account credential for a user associated with the device. In addition, the device receives the verification of the account credential. The device additionally requests a single sign-on credential for the account and receives the single sign-on credential. Furthermore, the device sends a message to a server associated with a service for the application that the application is registered for the single sign-on service.