Systems, computers and recording media for creating, verifying and entering security information

A system generates and securely prints high-entropy security information in human- and machine-readable forms, facilitating quick and accurate entry into secure systems, addressing the challenges of typing and remembering complex passwords.

JP7756217B2Active Publication Date: 2025-10-17INTEGRITY SECURITY SERVICES LLC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024162267
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-10-25
Filing Date
2024-09-19
Publication Date
2025-10-17
Estimated Expiration
2040-10-22

AI Technical Summary

Technical Problem

High-entropy security information, such as passwords and PINs, are difficult for users to type correctly and remember, especially for those with reading or dexterity impairments, leading to errors and time-consuming manual entry procedures.

Method used

A system comprising a generator computer, display device, and printer generates high-entropy character sets in both human-readable and machine-readable forms, which are printed on paper, allowing users to visually review and input the information using a barcode scanner or digital camera, while ensuring secure deletion of electronic records.

Benefits of technology

Enables fast and error-free entry of high-entropy security information into secure systems, reducing the need for password managers and eliminating the tendency to create non-random passwords for ease of usability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007756217000001
    Figure 0007756217000001
  • Figure 0007756217000002
    Figure 0007756217000002
  • Figure 0007756217000003
    Figure 0007756217000003
Patent Text Reader

Abstract

To provide a system for securely creating and using high-entropy security information such as a password.SOLUTION: A system includes a printer, a display device, and a generator computer that is connected to the printer and the display device. The generator computer causes the printer to print a high-entropy set of characters and a machine-readable representation on paper, and deletes the high-entropy set of characters and the machine-readable representation from the system. The high-entropy set of characters is entered into a target computer by scanning a barcode on the paper using a barcode scanner connected to the target computer, which is significantly faster than and eliminates a human error associated with typing input in a high-entropy set of characters.SELECTED DRAWING: Figure 1A
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims the benefit of and priority to U.S. Provisional Application No. 62 / 925,985, filed October 25, 2019, which is incorporated herein by reference in its entirety.

[0002] The present invention relates to systems, devices, manufactures, and methods for creating, verifying, maintaining, and securely entering security information, such as passwords, PINs, and cryptographic keys. The security information may be created or generated by a dedicated computing system and may be automatically entered into another computing device, for example, to log into a highly secure server. [Background technology]

[0003] Security information such as passwords, PINs, and encryption keys are best and most secure when they are in the form of high-entropy strings or character sets. For example, the best passwords use both a large number of randomly selected characters (e.g., 12 or more) and a large and varied set of characters from which they are selected (e.g., not only letters of the alphabet or only numbers).

[0004] However, a significant drawback is that the higher the entropy of a security information character set, such as a password, the more difficult it is for a user to type correctly on a keyboard and remember. Conventional systems and methods typically address this drawback by using a physical paper form on which a user manually writes a high-entropy password. The form is physically stored securely (e.g., locked in a safe) until needed (e.g., to log in to a highly secure computing system). To log in, the user must obtain the physical form, read the password, and then attempt to type the password from the form into the keyboard of the secure target computer system. This procedure is very time-consuming and extremely difficult to perform without error, especially for users with reading, physical, or dexterity impairments. This is in part because high-entropy passwords are, by their very nature, difficult to type and remember.

[0005] Various embodiments described herein address these and other shortcomings associated with high-entropy security information. Summary of the Invention

[0006] Systems, methods, and apparatuses for generating, verifying, inputting, and / or using high-entropy security information, such as passwords, are disclosed. In various embodiments, the system may include a printer, a display device, and a generator computer operably connected to the printer and the display device. The generator computer may include a processor and a storage device operably connected to the processor and containing instructions. The processor may execute the instructions to perform operations including generating a high-entropy character set, generating a machine-readable representation representing the high-entropy character set, providing the high-entropy character set and the machine-readable representation to a printer for printing on paper, and then deleting the original electronic form of the high-entropy character set and the machine-readable representation. In some embodiments, the electronic form may be erased, for example, from all of the generator computer's volatile storage (e.g., DRAM) and non-volatile storage. good.

[0007] In some embodiments, the printer is storage-free. In some embodiments, removing the high-entropy character set and the machine-readable representation includes instructing the printer to remove the high-entropy character set and the machine-readable representation after printing.

[0008] In some embodiments, the storage device is a removable storage device, and generating the high-entropy character set includes storing the high-entropy character set on the removable storage device, and generating the machine-readable representation includes storing the machine-readable representation on the removable storage device. In some such embodiments, deleting the high-entropy character set and the machine-readable representation further includes erasing the high-entropy character set and the machine-readable representation from the removable storage device. In some other such embodiments, the removable storage device is configured to render the high-entropy character set and the machine-readable representation unrecoverable upon detecting tampering with the removable storage device.

[0009] In various embodiments, the processor may also perform the operation of determining a number of characters for the high-entropy security information. Generating a high-entropy character set includes generating a high-entropy character set according to the number of characters.

[0010] In various embodiments, the processor may also perform the operations of displaying the high-entropy character set on a display device and allowing a user to visually review and / or edit the high-entropy character set using the display device. In some such embodiments, removing the high-entropy character set and the machine-readable representation includes clearing the high-entropy character set from the display device.

[0011] In various embodiments, the high-entropy character set is input to the target computer using a printed machine-readable representation. In various embodiments, the high-entropy character set is at least one of a password, a personal identification number (PIN), or a key used in a cryptography. In various embodiments, the machine-readable representation is a barcode. In various embodiments, the machine-readable representation is a Quick Response (QR) Code.

[0012] In some embodiments, the system further includes a target system, the target system including a reading device operably connected to the target computer, the reading device reading the machine-readable representation from the paper and providing the high-entropy character set represented by the machine-readable representation to the target computer. In some such embodiments, the reading device is a barcode scanner and the machine-readable representation is a barcode. In some other such embodiments, the reading device is a digital camera and the machine-readable representation is a barcode.

[0013] In some embodiments, the operations further include calculating a key check value (KCV) from the high entropy character set and providing the key check value to a printer for printing on paper.

[0014] Another embodiment is a system for producing high entropy security information that includes a printer, a display device, and a generator computer operably connected to the printer and the display device. The generator computer includes a processor and a storage device operatively connected to the processor and containing instructions. The processor executes the instructions to: The system performs operations including generating a high-entropy character set, displaying the high-entropy character set on a display device, accepting input from a user to edit the high-entropy character set, generating a machine-readable representation representing the high-entropy character set, calculating a key check value from the entropy set of characters, printing the high-entropy character set, the machine-readable representation, and the key check value on paper with a printer, and deleting the high-entropy character set and the machine-readable representation.

[0015] In various embodiments, the operations performed by the processor further include deleting the key check value. In various embodiments, deleting the high entropy character set further includes erasing the high entropy character set from the display device.

[0016] In some embodiments, the operations further include determining a number of characters in the high-entropy security information, and generating the high-entropy character set includes generating the high-entropy character set according to the number of characters.

[0017] In some embodiments, the storage device is a removable storage device, and deleting the high entropy character set and the machine-readable representation comprises deleting the high entropy character set and the machine-readable representation from the removable storage device.

[0018] In some embodiments, the high-entropy character set is input to the target computer using a machine-readable representation printed on paper.

[0019] In some embodiments, the machine-readable representation is a barcode.

[0020] In some embodiments, generating a high-entropy character set comprises randomly selecting a character set from a keyboard character set.

[0021] In some embodiments, generating the high entropy character set includes determining that the high entropy character set does not include one or more of words, names, and dates.

[0022] In some embodiments, the high-entropy character set is input to the target computer using a printed machine-readable representation.

[0023] In some embodiments, the system further includes a target system, the target system including a reading device operably connected to the target computer, the reading device reading the machine-readable representation from the paper and providing the high-entropy character set represented by the machine-readable representation to the target computer. In some such embodiments, the reading device is a barcode scanner and the machine-readable representation is a barcode. In some other such embodiments, the reading device is a digital camera and the machine-readable representation is a barcode.

[0024] It is contemplated that combinations of the above elements with elements herein may be made unless otherwise contradictory. [Brief explanation of the drawings]

[0025] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate examples and embodiments of the invention and, together with the description, serve to explain the principles of the invention. [Figure 1A] 1 is a block diagram illustrating an example of a system for securely producing high-entropy security information, consistent with embodiments of the present invention. [Figure 1B] 1 is an example of a printed form containing a high-entropy password represented in characters and a QR code that may be generated and used by a system consistent with embodiments of the present invention. [Figure 2] 1 is a block diagram illustrating an example of a system for inputting and using high-entropy security information consistent with embodiments of the present invention. [Figure 3] 1 is a flow diagram illustrating an example of a process for securely producing high-entropy security information consistent with embodiments of the present invention. [Figure 4] 1 is a flow diagram illustrating an example of a process for verifying high-entropy security information, consistent with embodiments of the present invention. [Figure 5] 1 is a flow diagram illustrating an example of a process for inputting and using high-entropy security information consistent with embodiments of the present invention. [Figure 6] 1 is an example printed form containing a high-entropy personal identification number (PIN) represented in characters and a QR code that may be generated and used by a system consistent with embodiments of the present invention. [Figure 7] 1 is an example of a printed form containing a 64-character key represented in letters and a QR code that may be generated and used by a system consistent with embodiments of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0026] Reference will now be made in detail to the embodiments of the present invention, examples of which are illustrated in the accompanying drawings.

[0027] Various embodiments and implementations consistent with the present invention provide systems, components, methods, and computer program products for generating and using high-entropy security information (e.g., high-entropy passwords, PINs, keys, or other high-entropy character sets) that can be entered or used, for example, to access a target secure computing system (e.g., a computing device containing sensitive data), and that can be expressed and entered in a manner that essentially eliminates user input errors. This is a significant technical improvement over systems that use high-entropy security information, which allow very few input errors (e.g., no more than five incorrect password entry attempts) before initiating a lockout.

[0028] As used herein, high-entropy information refers to information (e.g., a character set) that is difficult for someone to determine, guess, or solve, such as through a brute force attack. For passwords and other types of security information, entropy is based on the size of the character set used (i.e., the number of possible characters available, expandable using lowercase letters, uppercase letters, numbers, special characters, symbols, etc.), the randomness of the characters in the password (e.g., randomly selected characters, each character selected randomly independent of previous characters, that do not intentionally or unintentionally form or contain words, names, or dates), and the password length, i.e., the total number of characters in the password or other security information string. For example, the longer the password (or other security information), the larger the possible character set, and the more non-random subsets are avoided, the higher the entropy of the password.

[0029] An example of high-entropy information (i.e., a high-entropy character set) is a set of eight or more characters (e.g., for a PIN) randomly selected from a group of keyboard characters (keyboard character set), including the 26 lowercase letters of the alphabet, 26 uppercase alphabetic characters, numbers 0-9, punctuation marks (period, question mark, exclamation point, comma, semicolon, colon, dash, hyphen, open parenthesis) PARENTHESES, CLOSE PARENTHESES, OPEN BRACKET, CLOSE BRACKET, OPEN BRACE, CLOSE BRACE, APOSTROPHE, OPEN SINGLE QUOTATION MARK, CLOSE SINGLE QUOTATION MARK, OPEN DOUBLE QUOTATION MARK, and CLOSE DOUBLE QUOTATION MARK, including the special keyboard characters @, #, $, %, ^, &, *, +, =, |, \, <, >, / , and ´. Another example of high-entropy information (i.e., a high-entropy character set) is a set of 12 or more characters (e.g., for a password) randomly selected from the keyboard character set described above. Another example of high-entropy information (i.e., a high-entropy character set) is a set of 20 or more characters randomly selected from the keyboard character set described above, minus the subgroups 1-3 listed, such as minus the special character subgroup. Yet another example of high-entropy information (i.e., a high-entropy character set) is a collection of 32 or more characters (e.g., a 64-character set for a cryptographic key) randomly selected from the group of 16 hexadecimal letters or symbols (0, 1, 2, 3, 4, 5, 6, 7, 8, 9, A, B, C, D, E, F).

[0030] However, a significant drawback to using high-entropy security information is that the higher the entropy of the character set making up the security information (e.g., password, PIN, key, etc.), the more difficult it is to enter or type correctly on a keyboard (especially if the characters are not visible as they are typed) and to remember. This can be particularly problematic when used with secure systems that lock out users after a small number of unsuccessful attempts to enter a password, PIN, etc. (e.g., after two or three failed attempts) and / or that have a short time period (e.g., 15 seconds or less) to enter a password, PIN, etc. and complete login. These drawbacks lead users to prefer, create, and commonly use passwords or PINs that are relatively short (e.g., less than 12 characters in length), contain non-random strings of characters (e.g., words, names, birth dates, etc.), do not use uppercase and lowercase letters, and / or contain no or a minimal amount of punctuation and special characters (e.g., @, #, $, etc.).

[0031] The systems, methods, apparatus, and techniques described herein address these and other shortcomings and provide several technical advantages over existing systems and techniques, including, among other things, encouraging or requiring the use of high-entropy security information (e.g., long random broad character set-based character sets for passwords, PINs, etc.), increased security from the use of high-entropy security information, significantly increasing the speed at which high-entropy character sets can be entered into a target computer, and eliminating or significantly reducing input (e.g., typing) errors.

[0032] Various implementations of the systems, methods, devices, and techniques described herein reduce or eliminate the need for users to use password managers, etc., or to record and store their high-entropy passwords using insecure documents or devices. Various implementations described herein also reduce or eliminate the need for users to use password managers, etc., or to record and store their high-entropy passwords using insecure documents or devices. It allows users to quickly and accurately enter their high-entropy passwords (or similar) into secure target computer systems with virtually no input errors, despite the long, difficult to type, unmemorable, random character sets that are prone to typing errors when entered.

[0033] Various implementations of the systems, methods, apparatus, and techniques described herein also reduce or eliminate the need or tendency for users to create non-random and non-long passwords (i.e., low entropy) for ease of usability, memorization, and entry.

[0034] In many of the examples, embodiments, and implementations described herein, passwords are used as an example of a high-entropy character set used as security information. As previously mentioned, passwords are merely an example of one type of security information described herein, and it should be understood that the principles of the present invention apply to all types of security information in addition to passwords, such as PINs, encryption keys, and other types of keys or character strings.

[0035] FIG. 1A is a block diagram illustrating an example of a system 100 for securely generating high-entropy security information 130 consistent with embodiments of the present invention. In the example shown in FIG. 1A, system 100 includes a generator computer or generator computing system 105 that may be dedicated to (e.g., solely for) calculating, computing, generating, verifying, or generating high-entropy passwords 130 for use as security information, such as high-entropy passwords 130. In various embodiments, generator computer 105 may be a computing device including a processor, memory, and program instructions as known in the art, such as a laptop computer, desktop computer, server, tablet computer, or the like. In various embodiments, generator computer 105 may be configured to not have (or disable) computer-to-computer communication components and functions, such as not having a wireless transceiver or wireless networking capabilities (e.g., no RF / BLUETOOTH components) and not having wired networking components or functions (e.g., no Ethernet components). In general, system 100 may be an isolated, offline, stand-alone system that does not communicate with other computers, devices, or systems. Thus, generator computer 105 and system 100 cannot communicate security information 130, such as passwords, to another computer, device, or system, preferably electronically.

[0036] As shown, the generator computer 105 of the system 100 may also include one or more storage devices 110A, 110B, which may include an internal storage device 110A (e.g., an internal disk drive, solid state drive, memory (e.g., RAM), or similar storage medium) and / or an external or removable storage device 110B (e.g., an external or removable disk drive, solid state drive, thumb drive, removable hard drive, or similar storage medium). In embodiments including an external / removable storage device 110B, it may be connected to the generator computer 105 via wired (e.g., non-RF) means such as a USB or HDMI cable, by plugging it directly into a port (e.g., a USB port for a thumb drive), or by other means. In various embodiments, the generator computer 105 may be configured or programmed to delete all generated security information 130 from the storage devices 110A, 110B after printing, as described further below.

[0037] In various embodiments, a removable storage medium 110B (e.g., a removable storage medium Removable storage medium 110B, such as a lid state or hard drive, may be erasable using another computer (not shown), so that any security information (e.g., passwords, barcode representations of passwords, corresponding key check values, etc.) accidentally or intentionally stored on removable storage medium 110B can be permanently and securely deleted. In some embodiments, removable storage medium 110B can be configured to detect whether it has been tampered with and to render any unrecoverable security information (e.g., high-entropy character sets and their machine-readable representations) unrecoverable upon detection of tampering (e.g., by permanently erasing the high-entropy character sets and their machine-readable representations). In various embodiments in which an application or program that generates and / or validates high-entropy character sets is stored on removable storage medium 110B, deleting or erasing the high-entropy character sets may be performed without deleting or erasing the application or program itself.

[0038] In some embodiments, storage device 110A may be a volatile storage device or medium, such as RAM, that does not retain any information when generator computer 105 is powered off, and storage device 110B may be a non-writable storage device or medium, such as a ROM device, that contains application or program code that performs the operations, functions, methods, and processes described herein, such as processes 300 and 400 described below with respect to Figures 3 and 4. In such embodiments, security information and associated representations generated by system 100 cannot be stored in non-writable storage device 110B, but can only be stored temporarily in volatile storage device 110A, and at worst, can be stored for the longest time until generator computer 105 is turned off after use.

[0039] System 100 may also include a display device 115, such as a touchscreen computer monitor, connected to generator computer 105 via wired (e.g., non-RF) means, such as a USB or HDMI cable. Display device 115 may display a user interface, including prompts and questions posed by an application or program, characters and responses entered by a user, and controls for the user to enter information via the touchscreen, such as a virtual keyboard or radio buttons.

[0040] System 100 also includes a printer 120, such as a laser printer or inkjet printer, connected to generator computer 105 via wired (e.g., non-RF) means, such as a USB or HDMI cable. The generator computer can interface with printer 120 (e.g., by sending commands or instructions) to cause printer 120 to print various things, such as a character set 130, a machine-readable representation 135 of the character set, etc., on paper 125, as shown, for example, in FIGS. 1B, 6, and 7. In various embodiments, printer 120 may be configured to not have (or disable) any non-volatile memory or other internal storage that can store information such as a password after printer 120 is powered off, which increases security. In various embodiments, printer 120 may be configured to not have (or disable) any wireless communication components and capabilities, such as not having a wireless transceiver or wireless networking capabilities (e.g., no RF / BLUETOOTH components), which also increases security. Thus, in such embodiments, the printer 120 cannot wirelessly communicate security information 130, such as a password, to another computer or device. In various embodiments, the generator computer 105 can be configured or programmed to delete or cause to be deleted all generated security information 130 from the printer 120 after printing.

[0041] In various embodiments, generator computer 105 can perform processes, operations, and calculations to generate or produce representations of high entropy character set 130 both in the form of a human-readable sequence or keyboard character set 130 and in a machine-readable form 135, such as a barcode 135 (e.g., a QR code, etc.). As shown in the example of FIG. 1A , generator computer 105 can display high entropy character set 130 to a user using display device 130, and generator computer 105 can print the human-readable high entropy character set 130 along with a machine-readable representation 135 of high entropy character set 130 onto paper 125 using printer 120. In various embodiments, generator computer 105 can also create and print additional information onto paper 125 with printer 120, as described in more detail with respect to FIG. 1B .

[0042] The printer 120 prints the generated security information 130 on paper in both the form of, for example, a string, sequence, or character set 130 and a machine-readable barcode 135, so that the user does not need to remember or manually write the high-entropy security information created by the system 100. Both the printed sequence of characters and the printed barcode contain, represent, and convey the same security information 130, for example, the same high-entropy character set generated by the system 100.

[0043] As described in more detail elsewhere herein, a user can read the paper form 125 while typing the human-readable high-entropy character set 130 into the target computer or device, and / or can input the machine-readable representation 135 (e.g., a barcode) into the target computer or device (e.g., a secure target computer 205 as shown in FIG. 2 ) by scanning the machine-readable representation 135 (e.g., a barcode) using an automated reading device (e.g., a barcode scanner or reader) connected to the target computer or device.

[0044] In the example of FIG. 1A, when the user is not using the paper 125 to input the security information 130 into the target computer or device, the safe 140 or other locked enclosure can be utilized to store the printed paper 125 and physically ensure security. In various embodiments, the only record of the generated security information 130 may be the printed paper 125. In some embodiments, the safe 140 may also be used to store the removable storage device 110B when it is not in use, so that program code stored in the removable storage device 110B, etc., is inaccessible to those who cannot open the safe 140.

[0045] As described above, in various embodiments, the generator computer 105 may be programmed or configured to securely and completely delete all generated security information 130, etc., from its storage devices 110A, 110B, from the printer 120, and / or from the display device 115. In various embodiments, for example, the generator computer 105 can be programmed or configured such that all security information 130 is stored only in volatile memory (e.g., volatile RAM) that is automatically erased during normal operation or when the power is turned off, so as not to store the security information 130 in any type of non-volatile or persistent memory device.

[0046] FIG. 1B shows an example of a paper format 125 that can be printed by the printer 120 when the generator computer 105 creates or generates security information 130, which in this example is a high-entropy password 130. As shown in FIG. 1B, the paper password format 125 is shown as a set of 20 human-readable characters 130 "HV)ZDFGQT%}R1F3[T<ZD", and also as a machine-readable QR code 135 that includes or represents the barcode-formatted characters "HV)ZDFGQT%}R1F3[T<ZD", indicating or representing the high-entropy password.

[0047] In some embodiments, as shown in the example of FIG. 1B , the system 100 can calculate a checksum value, such as a key check value 210 (also known as a key checksum value or KCV), from or based on the high-entropy character set 130 and can print the calculated KCV 210 on a paper form 125.

[0048] In various embodiments, the generator computer 105 can calculate or create a KCV 210, etc., by applying a cryptographically secure hash algorithm, such as the Advanced Encryption Standard Cipher Block Chaining (AES CBC) algorithm, to 16 bytes of zeros while using the security information (in this example, password 130) as the key for the hash algorithm, and then truncating the result so that only the first three bytes remain as the output value 210, which can be represented as a six-character hexadecimal string. In the example of FIG. 1B, the output of the checksum algorithm is the six-character hexadecimal string "86A739," which is KCV 210. As described above, other checksum algorithms, etc., can be used to create KCV 210 based on character set 130. In embodiments including KCV 130, character set 130 (e.g., password 130) on format 125 can be verified using KCV 130, as described with respect to FIG. 4.

[0049] 1B, system 100 may also represent character set 130 by using or listing the phonetic or descriptive names of each character 220. Set of phonetic / descriptive names 220 aids a human user who might otherwise become confused or misled about characters that have similar appearances when printed, such as, for example, the number 1 "1" and the lowercase letter EL "L," when the user attempts to type character set 130 into a keyboard.

[0050] Those skilled in the art will recognize that the components and functionality of system 100 described in the examples of Figures 1A and 1B may be modified or varied without departing from the scope of the present invention. For example, system 100 may not have storage device 110B or may have additional storage devices such as device 110B. As another example, storage device 110A may be a non-volatile, non-writable storage device (e.g., ROM) that stores application or program code for performing the functions, operations, methods, and / or processes described herein. Storage device 110B may be a volatile, writable, erasable storage device (e.g., RAM) that only temporarily stores data generated and used by application or program code (e.g., until deleted or until the device is powered off). In another example, system 100 may not have a safe 140. As yet another example, system 100 may include a keyboard in addition to or in place of touchscreen display 115 to allow a user to input information into generator computer 105. Other variations are possible.

[0051] 2 is a block diagram illustrating an example of a target system 200 for entering and using high-entropy security information 130, consistent with embodiments of the present invention. In the example shown in FIG. 2, target system 200 includes a target computer or computing device 205 that is secure in that in order to operate (e.g., to log in), or one or more of its programs or applications, requires a password, PIN, encryption key, or some other type of security information 130. For example, secure target computer 205 may require a user to enter a password to log on to secure target computer 205, and / or the password may be required to be changed periodically by the user, as is known in the art.

[0052] In various embodiments, target computer 205 may be a device such as a laptop computer, a desktop computer, a server, a tablet computer, a smartphone, etc., which may be password protected. For example, target computer 205 may be a password-protected secure server containing sensitive, confidential, proprietary, sensitive, and / or top secret information.

[0053] As shown, the target system 200 may include a keyboard 225 or the like, which may be connected to the secure target computer 205 via wired (e.g., non-RF) means, such as a USB or HDMI cable, and may be used by a user to input information, such as security information in the form of character set 130, into the target computer 205.

[0054] The target system 200 may also include a display device 215, such as a computer monitor, touchscreen monitor, or the like, which may be connected to the target computer 205 via wired (e.g., non-RF) means, such as a USB or HDMI cable.

[0055] The target system 200 may further include a reading device 220 capable of scanning, reading, and / or interpreting the machine-readable representation 135 printed from the paper 125 printed by the generator computer 105.

[0056] In various embodiments, machine-readable representation 135 may be a printed indicia such as a barcode (e.g., a QR code), and reading device 220 may be a barcode scanner, a digital camera, or the like. In various embodiments, reading device 220 may scan, image, or detect black and white elements of machine-readable representation 135, for example, using its own built-in decoder firmware and / or decoder software installed on target computer 205, and then interpret or convert the elements into the corresponding characters they represent. In the example of barcode reader 220, the decoder may validate barcode 135 using a check digit present in barcode 134, recognize or detect the black and white elements of barcode 135, and convert the black and white elements into character set 130. This converted character set 130 may be used by secure target computer 205, for example, as a login password, etc.

[0057] In some embodiments, the reading device 220 (e.g., a barcode scanner) may be connected to the target computer 205 via wired (e.g., non-RF) means, such as a USB or HDMI cable, while in other embodiments, the reading device 220 may be incorporated into the target computer 205, such as a digital camera 220 incorporated into a laptop computer, tablet computer 220, smartphone, etc. In various embodiments, the reading device 220 that automatically reads the machine-readable representation 135 may mimic a keyboard 225 in terms of interfacing with the target computer 205. In such embodiments, from the perspective of the target computer 205, the output of the reading device 220 is the same or similar to the output of the keyboard 225 when a user is typing the character set 130 using the keyboard 225, albeit much faster and more accurate. In various embodiments, the reading device 220 may also be configured to delete any scanned representation 135, converted character set 130, etc. from its memory if it stores such data.

[0058] In various embodiments, the display device 215 may display prompts, instructions, etc. instructing the user to scan (using the reading device 220) or type (using the keyboard 225) the security information 130, 135 from paper 125. The security information 130 may be entered into the secure target computer 205 by automatically reading the machine-readable representation 135 using the reading device 220. The user avoids the time-consuming and extremely difficult task of correctly typing into the high-entropy character set 130 without exceeding the time or retry limits imposed by the system 200. This is a significant improvement over conventional keyboard techniques for entering high-entropy information because it is significantly faster (e.g., less than 1 second vs. 10+ seconds) and virtually error-free compared to manually typing a password, which, by the nature of its characters, is difficult to enter manually, especially for users lacking reading, physical, or dexterity skills.

[0059] Those skilled in the art will recognize that the components and functionality of the system 200 described in the example of Figure 2 may be modified or varied without departing from the scope of the present invention. For example, the target system 200 may not have a keyboard 225, or the keyboard 225 may be disabled for entry of security information, thereby requiring the use of the reading device 220 to enter the passwords 130, 135.

[0060] In another example, reader 220 may be a digital camera, and system 200 may use optical character recognition to automatically read character set 130 instead of or in addition to using a barcode reader. Other variations are possible.

[0061] 3 is a flow diagram illustrating an example of a process 300 for securely creating or generating high-entropy security information consistent with embodiments of the present invention. In various implementations, some or all of the operations of process 300 may be performed by a generator computer 105 or a similar computing system.

[0062] As shown in the example of FIG. 3 , process 300 begins at block 305 by determining the number of characters in character set 130. In some implementations, process 300 may obtain the number of characters from the user, for example, by prompting the user to enter the number of characters the user desires. In such implementations, the process may prompt and / or require the user to enter a minimum number, such as 12 or more, so that the resulting character set has high entropy. In other implementations, process 300 obtains an indication of the type of security information 130 desired, for example, by prompting the user to enter or select a type such as a “password,” “PIN,” or “encryption key,” and The number of characters can then be determined based on the selected type by setting the number to a predetermined value or to a value randomly selected from a predetermined range of values, where the range corresponds to the selected type. For example, the predetermined number of characters may be 20 for a "password" type, 8 for a "PIN" type, and 64 for an "encryption key" type. Similarly, an example of a predetermined number range may be 12-24 for a password and 6-9 for a PIN.

[0063] At block 315, process 300 randomly generates character set 130 from the keyboard character set (e.g., all printable characters available on the keyboard, or a subset thereof), where the length of the character set is equal to the number of characters determined at block 305. In various implementations, generator computer 105 generates a randomizing function or a true random number generator (also known as a TRNG, which is a high-efficiency generator), as known in the art. Using an entropy-based hardware-based seed value and a computer algorithm, a character set 130 can be selected from all possible printable characters available on a standard keyboard, such as lowercase letters, uppercase letters, numbers, punctuation marks, and special characters (e.g., @, #, $, %, {, etc.).

[0064] For example, consider a use case where process 300 determines that the number of characters is 20 based on information input by a user indicating that the user wants to generate a password. In this use case, the generator computer 105 can generate a password by randomly selecting 20 characters, such as "HV)ZDFGQT%}R1F3[T<ZD" (shown in FIG. 1B), from all possible keyboard characters. Thus, the 20-character set "HV)ZDFGQT%}R1F3[T<ZD" is the character set 130 output by block 315.

[0065] In the implementation shown in FIG. 3, at block 320, process 300 determines whether the generated character set meets a reference set that characterizes high-entropy character strings. In an example where one of the criteria is that it does not contain words or names, process 300 can parse the generated character set into subsets of characters, i.e., substrings, and compare the substrings with a dictionary and / or a list of names to determine whether the generated character set contains any words or names. In some such embodiments, the criterion may be that it does not contain words or names with four or more characters, and in such embodiments, the substrings may have a minimum length, such as four or more characters, so that the system 300 ignores three-character words and names, two-character words and names, and one-character words and names.

[0066] As another example, process 300 can determine whether the generated character set includes any substrings in the format of a date, such as "29 SEP 62," or "12-25-2020." In another example where any of the criteria does not include common names, process 300 can determine whether the generated character set includes words or names spelled forward or backward, such as "REYEM."

[0067] If the generated character set does not meet the criteria set that characterize a high-entropy string (block 320, no), for example, because it contains a six-letter word, process 300 returns to block 315 to create a new random character set.

[0068] In other embodiments (not shown), process 300 may perform other operations instead of repeating block 315 to produce a character set that meets the entropy criteria. For example, process 300 may scramble, reorder, remove, or otherwise modify only substrings that do not meet the criteria (e.g., form words or names or dates) while leaving the rest of the character set intact. Other variations are possible.

[0069] On the other hand, if the process 300 determines that the generated character set meets the criteria characterizing a high-entropy string (block 320, Yes), the process 300 proceeds to display the character set (block 325). In an implementation using the system 100, the generated character set 130 may be displayed on the display device 115.

[0070] In block 330, process 300 determines whether the generated character set has been approved by the user. In some implementations, process 300 obtains approval from the user, for example, by prompting the user to select either an “approved” or “unapproved” control on the user interface shown on display device 115. It is possible.

[0071] If the generated character set is not approved (block 330, no), process 300 proceeds to block 340. At block 340, the user can edit the displayed character set (block 340, yes) (e.g., using the touch screen or keyboard of display device 115 (not shown in FIG. 1A)), or can instruct process 300 to proceed to block 315 (block 340, no) to generate a new random character set. If the user decides to edit the displayed character set at block 340, process 300 accepts input from the user (e.g., addition of characters, deletion of characters, change of characters, etc.) to modify character set 130. In such an implementation, generator computer 105 can provide an editing application for the user to interact with via the touch screen of display device 115.

[0072] On the other hand, if the generated character set is approved (block 330, yes), process 300 proceeds to generate a machine-readable representation of the character set (block 325), such as a barcode, magnetic ink pattern, etc. For example, continuing with the previous use case, generator computer 105 can generate a matrix barcode 135, such as a QR code, that encodes or contains information representing character set 130 "HV)ZDFGQT%}R1F3[T<ZD".

[0073] At block 345, process 300 calculates a key check value (KCV) from the character set. In some embodiments, as described above with respect to FIG. 1B, generator computer 105 can create a KCV 210 consisting of the hexadecimal number "86A739" from character set 130 "HV)ZDFGQT%}R1F3[T<ZD" using, for example, the AES CBC algorithm.

[0074] In block 350, process 300 prints the character set and the machine-readable representation thereof on, for example, a sheet of paper, cardboard, etc. Continuing with the previous use case, generator computer 105 can cause printer 120 to print character set 130 "HV)ZDFGQT%}R1F3[T<ZD" and matrix barcode 135 on a sheet of paper 125, as shown in FIG. 1B.

[0075] In block 355 of the example of FIG. 3, process 300 prints the KVC on the same paper normally used in block 350, as shown in the example of FIG. 1B. Blocks 350 and 355 are described separately in the context of the implementation of FIG. 3 to clarify that the KCV-related operations are optional, but in other implementations, character set 130, machine-readable representation 135, and KCV 210 may all be printed together at approximately the same time. In other words, blocks 350 and 355 may be combined into a single block.

[0076] In block 360, process 300 deletes the character set and the machine-readable representation from, for example, any storage device (e.g., memory) of memory and / or storage devices 110A, 110B, display device 115, and / or printer 120. In various embodiments, this can include instructing or commanding printer 120 to delete high-entropy character set 130 and machine-readable representation 135 from its memory. In various embodiments, this can include stopping, erasing, or clearing the display of the character set on display device 115 (see block 325). In various embodiments where storage device 110B is a removable storage device (e.g., a removable drive), this can include erasing or deleting the character set and the machine-readable representation from removable storage device 110B.

[0077] In embodiments in which a key check value was calculated according to block 345, block 360 may further include, for example, erasing or deleting the key check value from memory and / or storage devices 110A, 110B, display device 115, and / or any storage device (memory) of printer 120. Thus, some embodiments aim, among other things, for printed paper 125 to be the only record of character set 125, machine-readable representation 135, etc. after process 300 is complete.

[0078] Those skilled in the art will recognize that the operations, functions, blocks, sequences, and orders described in the example of Figure 3 may be modified or varied without departing from the scope of the present invention. For example, all or some of the blocks enclosed in dashed lines may be considered optional and may be omitted. For example, process 300 may be reduced to operations 305, 315, 335, 350, and 360 in some implementations.

[0079] For another example, in some implementations, blocks 325, 330, and 340 may be omitted. For yet another example, block 330 may be omitted so that the user may be the sole judge of the entropy of the generated character set. For yet another example, in some implementations, blocks 350 and 355 may be combined into a single block.

[0080] In yet another example, new blocks can be added to encrypt the character set, machine-readable representation, and / or KCV (in other words, to securely store the generated security information representation) instead of removing them in block 360, or block 360 can be omitted without replacement. Other variations are possible.

[0081] FIG. 4 is a flowchart showing an example of a process 400 for verifying high entropy security information that conforms to an embodiment of the present invention. In various implementations, some or all of the operations and functions of process 400 may be performed by generator computer 105 or a similar computing system. In some such implementations, system 100 may further include a reader device 220 and / or a keyboard 225. A user can use process 400 to confirm or verify that security information 130 and / or machine-readable representation 135 on paper form 125 have not been miscalculated, forged, altered, modified, etc. The user may desire to verify the information and representations on paper form 125, for example, before setting or changing the password of target computer 205, before setting or changing the PIN of a target smartphone or tablet computer.

[0082] As shown in the example of FIG. 4, process 400 begins at block 405 by receiving a character set, e.g., the character password set 130 "HV)ZDFGQT%}R1F3[T<ZD" as shown in the example of FIG. 1B. In some embodiments, the generator computer 105 implementing process 400 can receive or obtain the character set 130 via a touchscreen display device 115 or a keyboard (e.g., similar to keyboard 225) by prompting the user, e.g., via the display device 115, to input the character set from a password form 125 previously printed by printer 120. Additionally or alternatively, in some implementations, the generator computer can receive or obtain the character set 130 from a reader device (e.g., similar to reader device 220) or via a reader device by prompting the user, e.g., via the display device 115, to scan a barcode 135 from a password form 125 previously printed by printer 120.

[0083] In block 410, process 400 calculates a key check value (KCV) from the character set received in block 405. In various embodiments, generator computer 105 uses the same checksum algorithm in block 410 as that used in block 345 of FIG. 3. For example, using the AES CBC algorithm, a KCV 210 having the value "86A739" can be created from the password of the character set "HV)ZDFGQT%}R1F3[T<ZD".

[0084] In block 415, process 400 displays the key check value calculated in block 410. For example, in an implementation of system 100, the key check value 210 "86A739" can be displayed on display device 115.

[0085] In block 420, process 400 determines whether the calculated and displayed KCV is the same as the KCV 210 printed on paper, such as password format 125 shown in FIG. 1B.

[0086] In some implementations, this determination may be made by the user comparing the KCV displayed in block 415 with the printed KVC 210 printed in password format 125. In such an implementation, block 420 can include additional operations to prompt the user to select an "Approved" button or control on the user interface shown on display device 115 to indicate that the displayed KCV is the same as the printed KVC 210, or conversely, to select a "Not Approved" button or control to indicate that they are not the same.

[0087] In some other implementations, this determination may be made by process 400 automatically comparing the KCV displayed in block 415 with the printed KVC 210 printed on password form 125. In some such implementations, the printed KVC 210 on password form 125 is read using a reading device in block 405, the characters are subjected to optical character recognition, and then compared to the calculated KCV from block 410. In some other such implementations, block 420 may include an act of obtaining the printed KVC 210 printed on password form 125 from the user by prompting the user to type the printed KVC 210 into system 100 and then comparing it with the calculated KCV from block 410.

[0088] If the calculated KCV is not the same as the printed KCV 210 (block 420, no), process 400 proceeds to block 430. At block 430, the process generates an error warning. Upon receiving the error warning, for example, via display device 115, the user may abandon or discard password format 125 before the password is used (e.g., before it is used as a password on secure target computer 205) and then create a new password and corresponding password format 125 using generator computer 105, for example, as described with respect to process 300 of FIG. 3.

[0089] On the other hand, if the calculated and displayed KCV is the same as the printed KCV 210 (block 420, Yes), the process 400 ends without displaying an error. If there is no error, the user can set or change a password, etc., on the target computer 205 using the password format 125 to be high-entropy characters 130.

[0090] Those skilled in the art will recognize that the operations, functions, blocks, sequences, and orders described in the example of Figure 4 may be modified or varied without departing from the scope of the present invention. For example, block 405 may be configured to automatically rewrite the paper form 1 to eliminate the possibility of a user making a typographical error. This can be modified to require receiving the character set only from a reader 220 that interprets the machine-readable bar code 135 on the display 25. Other variations are possible.

[0091] 5 is a flow diagram illustrating an example of a process 500 for entering and using high-entropy security information consistent with embodiments of the present invention. In various implementations, some or all of the operations and functions of process 400 may be performed by a target computer 205 of a secure computing system 200 or a similar computing system or device, such as a smartphone. A user can use process 500 to enter security information 130 and / or its machine-readable representation 135 from a paper form 125 into the target computer 205 in a fast and error-free manner. In some embodiments, the security information (i.e., the high-entropy character set 130) may be used by the operating system of the target computer 205 or by any application or program running on the target computer 205 that requires or uses security information, such as a password, PIN, or encryption key. For example, a user may use process 500 to change the password of target computer 205 by first entering a current high-entropy password from a first password format 125 to log in to target computer 205, and then entering a new high-entropy password from a different password format 125 into a change password application running on target computer 205.

[0092] 4, process 500 begins by determining whether reading device 220 (e.g., a barcode reader) is operational at block 505. In the example implementation shown, process 500 may require the user to use reading device 220, if operational, to enter security information 130 in a minimal amount of time and to eliminate the possibility of human error when typing security information 130.

[0093] If the reading device 220 is operational (block 505, yes), the process 500 proceeds to block 510, where it receives the character set 130 (e.g., the password 130 from the paper password format 125 shown in FIG. 1B) via the reading device 220 and interprets, reads, or converts the character set 130 from or based on the machine-readable representation 135 on the paper password format 125, as known in the art.

[0094] On the other hand, if the reading device 220 is not operational (block 505, no), the process 500 proceeds to block 515 to receive the character set 130 (e.g., the password 130 shown in FIG. 1B) via the keyboard 225. In this case, the user can read the character set 130 from the paper password form 125 and type the characters into the keyboard 225.

[0095] In block 520, process 500 calculates a key check value from the received character set 130 and, in block 525, displays the key check value on, for example, display device 215. In various embodiments, target computer 205 executes the same checksum algorithm in block 520 as was executed by generator computer 105 to produce the KCV 210 that generator computer 105 printed in paper password format 125. One example is the AES CBC algorithm used to produce a KCV 210 having the value "86A739" from the password character set "HV)ZDFGQT%}R1F3[T<ZD" as described above with respect to block 345 of FIG. 3. As described above, other checksum algorithms known in the art can be used to generate and verify the key check value.

[0096] In block 530, process 500 determines whether the calculated KCV of block 520 is the same as the printed KCV 210 as shown, for example, in password format 125 shown in FIG. 1B.

[0097] In some implementations, this determination can be made by a user comparing the KCV displayed in block 525 to the printed KVC 210 on the printed password format 125 in the same manner as described above with respect to block 420 of FIG. 4.

[0098] In some other implementations, the determination in block 530 may be made by process 500 (such as when executed by target computer 205) automatically comparing the KCV displayed in block 525 to the printed KVC 210 printed on password format 125 in the same manner as described above with respect to block 420 of FIG. 4.

[0099] If the calculated KCV from block 520 is not the same as the printed KCV 210 (block 530, no), process 500 proceeds to block 540. At block 540, process 500 generates an error warning. A KCV error warning may indicate that the character set 130 and / or machine-readable representation 135 on the paper form 125 has been altered, misread, or entered incorrectly, such that upon receiving the error warning via, for example, display device 215, a user may stop, abort, or retry (e.g., by re-executing blocks 510 or 515) entering security information (e.g., a password set of characters 130) into target computer 205.

[0100] On the other hand, if the calculated and displayed KCV is the same as the printed KCV 210 (block 5300, yes), process 500 proceeds to block 535. At block 535, the high-entropy character set 130 (e.g., a password) received at blocks 510 or 515 is entered into the target computer 205 (e.g., into a program or application), and process 500 ends. In some embodiments, process 500 may ask the user for permission via display device 215 before entering the character set 130 into the target computer 205.

[0101] Those skilled in the art will recognize that the operations, functions, blocks, sequences, and orders described in the example of FIG. 5 may be modified or varied without departing from the scope of the present invention. For example, all or some of the blocks enclosed within dashed lines may be considered optional and may be omitted. For example, process 500 may be reduced to operations 505, 510, 515, and 535 in some implementations. As another example, even if reader 220 is operational, block 505 may be modified to allow the user to enter security information 130 using keyboard 225, if desired by the user. Other variations are possible.

[0102] 6 is another example of a piece of paper 125, here in the form of a personal identification number (PIN), that may be printed by printer 120 when generator computer 105 creates or generates a high-entropy PIN 130 for a user. As shown in FIG. 6, this example PIN form 125 represents the PIN as an eight-character human-readable character set 130, "DZ0B4FR~G," and as a QR code 135. PIN form 125 also includes a KCV 210 that is calculated based on the PIN character set 130.

[0103] FIG. 7 is another example of a paper format 125, this time in key component form, that is printed to the printer 100 when the system 100 creates or produces a high entropy key 130 for the user. 20. As shown in FIG. 7, key component format 125 represents the key as a 64-character human-readable character set 130 and a QR code 135 and includes a corresponding KCV 210. In the example of FIG. 7, high-entropy security information 130 is a cryptographic key. When used as a cryptographic key, character set 130 may be restricted to be drawn only from the group of hexadecimal symbols (0, 1, 2, 3, 4, 5, 6, 7, 8, 9, A, B, C, D, E, F). Other use cases and implementations may similarly require character set 130 to be drawn (e.g., randomly selected) from a specified group of characters. In such implementations, process 300 of FIG. 3 may be modified such that block 315 randomly generates character set 130 from a set of hexadecimal symbols (rather than from a keyboard character set).

[0104] In various embodiments described herein, because security information (e.g., PINs, passwords, keys, etc.) is represented in a machine-readable format 135 that is automatically entered into the target computer 205, the generator system 100 can be configured to create long, random, highly secure character sets for passwords, etc., containing 20 or more characters, such as 25, 30, or 64 characters, without the drawbacks associated with conventional systems. The high-entropy nature of these character sets does not prevent their use by humans because they do not require a human to memorize or manually type the characters.

[0105] Various aspects of the present disclosure can be summarized as follows.

[0106] Aspect 1. A system for securely producing high entropy security information, the system comprising: A printing means; A display means; a computing means operably connected to the printing means and the display means, the computing means comprising: processing means; storage means operatively connected to the processing means and containing instructions; Equipped with Here, the processing means generating a high entropy character set; generating a machine-readable representation representing the high-entropy character set; providing a high entropy character set and a machine-readable representation to a printing means for printing on paper; and removing the high entropy character set and the machine-readable representation.

[0107] Aspect 2 In the system of aspect 1, the printing means does not have a storage means.

[0108] Aspect 3: In the system of any one of Aspects 1 to 2, the step of removing high entropy character sets and machine-readable representations comprises: instructing the printing means to remove the high entropy character set and machine-readable representation after printing.

[0109] Aspect 4: The system of any of Aspects 1 to 3, The storage means comprises a removable storage medium; generating a high-entropy character set includes storing the high-entropy character set on a removable storage medium; Generating the machine-readable representation includes storing the machine-readable representation on a removable storage medium.

[0110] Aspect 5: The system of aspect 4, The step of removing high entropy character sets and machine readable representations comprises: Erasing the high entropy character set and the machine-readable representation from the removable storage medium.

[0111] Aspect 6. The system of aspect 4, The removable storage medium is configured to render the high entropy character set and machine-readable representation unrecoverable upon detecting tampering with the removable storage medium.

[0112] Aspect 7. The system of any of aspects 1 to 6, comprising: The operation is determining the number of characters of the high-entropy security information; The step of generating a high entropy character set comprises: generating a high-entropy character set according to the number of characters;

[0113] Aspect 8. The system of any of aspects 1 to 7, comprising: The operation is displaying the high entropy character set on a display means; and allowing a user to edit the high entropy character set using the display means.

[0114] Aspect 9. The system of any of aspects 1 to 8, comprising: The step of removing high entropy character sets and machine readable representations comprises: Clearing the high entropy character set from the display means.

[0115] Aspect 10: The system of any of aspects 1 to 9, A high-entropy character set is input to the target computer using a printed machine-readable representation.

[0116] Aspect 11 The system of any of aspects 1 to 10, The high-entropy character set is at least one of a password, a personal identification number (PIN), or a key used in a cipher.

[0117] Aspect 12: The system of any of aspects 1 to 11, The machine-readable representation is a barcode.

[0118] Aspect 13: The system of any of aspects 1 to 11, The machine-readable representation is a Quick Response (QR) code.

[0119] Aspect 14. The system of any of aspects 1 to 13, comprising: The system is a target system, a target computing means; a target system comprising: reading means operatively connected to the target computing means for reading the machine-readable representation from the paper and providing the high-entropy character set represented by the machine-readable representation to the target computing means; Prepare.

[0120] Aspect 15: The system of aspect 14, The reading means is a barcode scanner and the machine-readable representation is a barcode.

[0121] Aspect 16. The system of aspect 14, comprising: The reading means is a digital camera and the machine-readable representation is a barcode.

[0122] Aspect 17. The system of any of aspects 1 to 16, comprising: The operation is calculating a key check value (KCV) from a high-entropy character set; providing the key check value to a printing means for printing on paper; Further provided are:

[0123] Aspect 18. A system for producing high entropy security information, comprising: The system is Printer and A display device; a generator computer operably connected to a printer and a display device, a processor; a memory device operatively connected to the processor and containing instructions; a generator computer comprising: Here, the processor: generating a high entropy character set; displaying the high entropy character set on a display device; accepting input from a user to compile a high-entropy character set; generating a machine-readable representation representing the high-entropy character set; calculating a key check value from the entropy set of the character; causing a printer to print the high entropy character set, the machine-readable representation, and the key check value on paper; removing high entropy character sets and machine-readable representations; The instructions are executed to perform the operations that they include.

[0124] Aspect 19. The system of aspect 18, comprising: The operations further include deleting the key check value.

[0125] Aspect 20. The system of any of aspects 18-19, comprising: The step of deleting the high entropy character set further includes the step of erasing the high entropy character set from the display device.

[0126] Aspect 21 The system of any of aspects 18 to 20, comprising: The operation is determining the number of characters of the high-entropy security information; wherein the step of generating a high entropy character set comprises: generating a high-entropy character set according to the number of characters;

[0127] Aspect 22. The system of any of aspects 18 to 21, comprising: the storage device comprises a removable storage device; The step of removing high entropy character sets and machine readable representations comprises: Deleting the high entropy character set and the machine-readable representation from the removable storage device.

[0128] Aspect 23. The system of any of aspects 18 to 22, comprising: A high-entropy character set is input to the target computer using a machine-readable representation printed on paper.

[0129] Aspect 24. The system of any of aspects 18 to 23, comprising: The machine-readable representation is a barcode.

[0130] Aspect 25. The system of any of aspects 18 to 24, comprising: Generating a high entropy character set includes randomly selecting a character set from a keyboard character set.

[0131] Embodiment 26: The system of any of embodiments 18 to 25, comprising: Generating a high-entropy character set includes determining that the high-entropy character set does not include one or more of words, names, and dates.

[0132] Aspect 27. The system of any of aspects 18 to 26, comprising: A high-entropy character set is input to the target computer using a printed machine-readable representation.

[0133] Aspect 28. The system of any of aspects 18 to 27, comprising: The system is a target system, The target computer, a reading device operatively connected to the target computer for reading the machine-readable representation from the paper and providing the high-entropy character set represented by the machine-readable representation to the target computer; The target system further comprises:

[0134] Aspect 29. The system of aspect 28, comprising: The reading device is a barcode scanner and the machine-readable representation is a barcode.

[0135] Embodiment 30: The system of embodiment 28, comprising: The reader is a digital camera and the machine-readable representation is a barcode.

[0136] Aspect 31 is a method for securely producing high entropy security information, comprising: The method is: generating a high entropy character set; generating a machine-readable representation representing the high-entropy character set; providing the high entropy character set and the machine-readable representation to a printer for printing on paper; and removing high entropy character sets and machine-readable representations.

[0137] Throughout this specification, including the claims, the term "comprising" should be understood to be synonymous with "comprising at least one" unless otherwise specified. Furthermore, any range set forth in this specification, including the claims, should be understood to be inclusive of its final value unless otherwise specified. Specific values ​​for the elements set forth should be understood to be within accepted manufacturing or industry tolerances known to those skilled in the art, and the use of the terms "substantially" and / or "approximately" and / or "generally" should be understood to mean within such accepted tolerances.

[0138] Other embodiments of the invention will be apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. It is intended that the specification and description herein be considered as examples only, with a true scope and spirit of the invention being indicated by the following claims.

Claims

1. 1. A system for securely producing high entropy security information, comprising: a computer operably connected to a printer and a display device; The computer includes a processor, the processor comprising: generating a high entropy character set; generating a representation representing said high entropy character set; providing the high-entropy character set and the representation to the printer for printing on paper; removing the high entropy character set and the representation; Executing instructions to perform operations including: A system for securely producing high-entropy security information.

2. The system of claim 1 , wherein the printer is storage-less.

3. Further comprising a storage device, generating the high-entropy character set includes storing the high-entropy character set in the storage device; generating the representation includes storing the representation in the storage device; 3. The system according to claim 1 or 2.

4. The step of removing the high entropy character sets and the representations comprises:

4. The system of claim 3, further comprising the step of erasing the high entropy character set and the representation from the storage device.

5. The system of claim 3 , wherein the storage device is configured to render the high-entropy character set and the representation unrecoverable upon detecting tampering with the storage device.

6. The operation is determining the number of characters in the high-entropy security information; The step of generating a high entropy character set comprises: The system of claim 1 , further comprising: generating the high-entropy character set according to the number of characters.

7. The operation is displaying the high entropy character set on the display device; The system of claim 1 , further comprising: enabling a user to edit the high-entropy character set using the display device.

8. The step of removing the high entropy character sets and the representations comprises:

8. The system of claim 7, further comprising the step of clearing said high entropy character set from said display device.

9. 9. The system of claim 1, wherein the high-entropy character set is input to a target computer using a printed representation of the character set.

10. The system of claim 1 , wherein the high-entropy character set is at least one of a password, a personal identification number (PIN), or a key used in a cipher.

11. The system of claim 1 , wherein the representation is a barcode.

12. The system of claim 1 , wherein the representation is a Quick Response (QR) code.

13. a target computer; a reading device operatively connected to the target computer for reading the representation from the paper and providing the high-entropy character set represented by the representation to the target computer; a target system, 13. A system according to any one of claims 1 to 12.

14. The system of claim 13 , wherein the reader is a barcode scanner and the representation is a barcode.

15. The system of claim 13 , wherein the reader is a digital camera and the representation is a bar code.

16. The operation is calculating a Key Check Value (KCV) from the high entropy character set; 16. The system of claim 1, further comprising the step of: providing the key check value to the printer for printing on the paper.

17. 1. A computer for generating high-entropy security information, comprising: a processor, the processor comprising: generating a high entropy character set; generating a representation representing said high entropy character set; printing the high entropy character set and the representation on paper using a printer; removing the high entropy character set and the representation; A computer that executes instructions to perform operations including:

18. The operation is displaying the high entropy character set on a display device; and enabling a user to edit the high-entropy character set using the display device.

19. 20. The computer of claim 18, wherein removing the high entropy character set further comprises erasing the high entropy character set from the display device.

20. The operation is calculating a Key Check Value (KCV) from the high entropy character set; 20. The computer of claim 17, further comprising the step of: printing the key check value on the paper.

21. A computer described in any one of claims 17 to 20, wherein the representation is a barcode.

22. When executed by a processor, the processor: generating a high entropy character set; generating a representation representing said high entropy character set; printing the high entropy character set and the representation on paper using a printer; removing the high entropy character set and the representation; A computer-readable non-transitory storage medium containing instructions for performing operations including:

23. The operation is displaying the high entropy character set on a display device; and enabling a user to edit the high-entropy character set using the display device.

24. The computer-readable non-transitory recording medium of claim 23, wherein the step of deleting the high-entropy character set further comprises the step of erasing the high-entropy character set from the display device.

25. The operation is calculating a Key Check Value (KCV) from the high entropy character set; 25. The computer-readable non-transitory storage medium of claim 22, further comprising the step of: printing the key check value on the paper.

26. A computer-readable non-transitory recording medium described in any one of claims 22 to 25, wherein the representation is a barcode.

27. A computer as claimed in any one of claims 17 to 21, wherein the high entropy character set is input to a target computer using a printed representation of the character set.

28. A computer as described in any one of claims 17 to 21 and 27, wherein the representation is a quick response (QR) code.

29. A computer-readable non-transitory recording medium described in any one of claims 22 to 26, wherein the representation is a quick response (QR) code.

Citation Information

Patent Citations

  • Barcode processing system

    JP2002197407A

  • Confidential data generating / reading system, and confidential data generating / reading method

    JP2008312001A

  • Printing method, program, information processor and printing apparatus

    JP2012083810A

  • Service provision system and management server

    JP2012137962A

  • Method, system, and apparatus using forward-secure cryptography for passcode verification.

    JP2019506789A