Color-Encoded Password Generation for Keylogging Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional password-based authentication systems are vulnerable to attacks such as brute force, dictionary attacks, and keylogging, making them insecure, and measures to enhance password complexity often compromise user memorability.

Innovation Solution

The system allows users to add colors to textual passwords and encodes this color information to generate more secure passwords, using a user interface that separates color selection from text input, thereby increasing password complexity without affecting memorability and potentially identifying keylogging attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators require users to select passwords of certain complexity and length to make attacks more difficult, then password security is improved, but passwords become more difficult for users to remember

Engineering Contradiction:
Improvepassword securityVSAvoiduser memorability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent adds a color dimension to traditional text-based passwords. Instead of only increasing password length and character complexity in one dimension, the system introduces color as a second dimension, allowing users to create secure passwords while maintaining memorability through visual differentiation of password components.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system directly applies color changes to password characters to enhance security. Users can assign different colors to different parts of their password, creating a multi-colored password that is both more secure against attacks and more memorable for users through visual cues.

Inventive Principle:
Principle #32Color changes

2Ease of operation

If traditional password-based authentication systems are used, then ease of operation is maintained, but systems become vulnerable to brute force, dictionary attacks, and keylogging

Engineering Contradiction:
Improveoperation simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system transforms traditional monochrome text passwords into multi-colored passwords where different colors represent different semantic components (e.g., subject, verb, object). This visual differentiation thwarts dictionary attacks by making colored passwords unreadable to automated systems while remaining intuitive for human users.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces color as an intermediary layer between the user and the authentication system. The color information acts as a mediator that enhances security without requiring users to change their input behavior, as colors are automatically applied and transmitted to the authentication system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If color information is added to passwords to increase informational complexity, then password security is enhanced, but device complexity increases

Engineering Contradiction:
Improvepassword securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs self-service mechanisms where the client application automatically handles color selection and encoding without requiring additional user input. The authentication system automatically decodes color information from the transmitted password, eliminating the need for manual color configuration and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary encoding of color information into the password string before transmission. By pre-encoding the color data in a standardized format during password creation, the system avoids the need for complex real-time processing during authentication, simplifying the overall system architecture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9009814B1Systems and methods for generating secure passwords
Publication Date: 2015.04.14 GEN DIGITAL INC
  • US9009814B1 patent drawing
  • US9009814B1 patent drawing
  • US9009814B1 patent drawing

AI summary

A computer-implemented method for generating secure passwords may include 1) displaying a user interface for entering a textual password, 2) receiving user input via the user interface to select a color for at least one character of the textual password, 3) displaying the entered textual password via the user interface by displaying the character in the selected color and by displaying at least one additional character in at least one additional color, and 4) generating a modified textual password by encoding the textual password with information relating the selected color to the character. Various other methods, systems, and computer-readable media are also disclosed.