Composite Password System Using Dynamic Hints and Cryptographic Hashing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password systems are vulnerable to keyloggers, as passwords are often static and easily observable, making them insecure, especially for individuals with disabilities who struggle with complex alphanumeric passwords, and are prone to being compromised or disclosed.
Innovation Solution
A composite password system that generates unique passwords for each login session using multiple keywords with associated hints, such as pictures, sounds, or textures, which are stored on a local device and verified through a cryptographic hash, eliminating the need for users to remember static passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static alphanumeric password is used, then security is improved, but ease of operation deteriorates and the password becomes observable and memorable
Solution Approach 1:
The patent implements dynamic passwords that change with each login session based on a seed value and algorithm, rather than using static passwords. This resolves the contradiction by making passwords non-memorable and non-observable while maintaining security through automated generation and rotation.
Solution Approach 2:
The patent replaces the mechanical system of human memory and manual password creation with an automated computational system that generates passwords algorithmically based on seeds and cryptographic functions, eliminating the need for users to remember complex passwords.
2Reliability
If a long or complicated password is used, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system performs self-service by automatically generating and managing complex passwords without requiring user input or memory. The automated system handles password creation, storage, and rotation, resolving the contradiction between complexity and ease of operation.
Solution Approach 2:
The patent replaces manual password entry with automated computational generation using cryptographic algorithms, eliminating the burden of entering long complicated passwords while maintaining high security through algorithmic complexity.
3Ease of operation
If the same password is used for each login, then ease of operation is improved, but security deteriorates due to keylogger attacks
Solution Approach 1:
The patent implements dynamic password rotation where each login session uses a different password generated from a seed value, maintaining consistency in the authentication process while eliminating security risks associated with repeated use of the same password.
Solution Approach 2:
The system performs periodic password regeneration at each login session based on the seed value and session identifier, creating a rhythm of changing credentials that maintains operational consistency while preventing keylogger attacks through regular rotation.
4Ease of operation
If hints are presented to help remember passwords, then ease of operation is improved, but security deteriorates as hints may reveal the password
Solution Approach 1:
The patent extracts the hinting function from the password itself, using separate seed values and algorithms to generate passwords that are unrelated to any hinting information. This resolves the contradiction by removing the security risk of hint revelation while maintaining ease of operation through automated generation.
Data Source
AI summary
A system which generates composite passwords which can act to trigger a designated event; said system comprising a database having stored thereon at least first and second hints associated with at least respective first and second passwords, all of which are associated with a designated user; the system storing hints and passwords for multiple designated users and wherein each hint and password pair is generated by an association procedure whereby the password is uniquely derivable from the hint by the designated user with which that hint and password pair is associated; a composite password generated by the system presenting in a designated order of at least first and second hints to a designated user in response to which the designated user inputs respective first and second passwords to a local device thereby to assemble a composite password from the first and second passwords; the composite password then being stored on the local device.


