Composite Password System Using Dynamic Hints and Cryptographic Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password systems are vulnerable to keyloggers, as passwords are often static and easily observable, making them insecure, especially for individuals with disabilities who struggle with complex alphanumeric passwords, and are prone to being compromised or disclosed.

Innovation Solution

A composite password system that generates unique passwords for each login session using multiple keywords with associated hints, such as pictures, sounds, or textures, which are stored on a local device and verified through a cryptographic hash, eliminating the need for users to remember static passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static alphanumeric password is used, then security is improved, but ease of operation deteriorates and the password becomes observable and memorable

Engineering Contradiction:
ImprovesecurityVSAvoidease of remembering
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic passwords that change with each login session based on a seed value and algorithm, rather than using static passwords. This resolves the contradiction by making passwords non-memorable and non-observable while maintaining security through automated generation and rotation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces the mechanical system of human memory and manual password creation with an automated computational system that generates passwords algorithmically based on seeds and cryptographic functions, eliminating the need for users to remember complex passwords.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a long or complicated password is used, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of entering
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically generating and managing complex passwords without requiring user input or memory. The automated system handles password creation, storage, and rotation, resolving the contradiction between complexity and ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual password entry with automated computational generation using cryptographic algorithms, eliminating the burden of entering long complicated passwords while maintaining high security through algorithmic complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If the same password is used for each login, then ease of operation is improved, but security deteriorates due to keylogger attacks

Engineering Contradiction:
ImproveconsistencyVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic password rotation where each login session uses a different password generated from a seed value, maintaining consistency in the authentication process while eliminating security risks associated with repeated use of the same password.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs periodic password regeneration at each login session based on the seed value and session identifier, creating a rhythm of changing credentials that maintains operational consistency while preventing keylogger attacks through regular rotation.

Inventive Principle:
Principle #19Periodic action

4Ease of operation

If hints are presented to help remember passwords, then ease of operation is improved, but security deteriorates as hints may reveal the password

Engineering Contradiction:
Improveease of rememberingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the hinting function from the password itself, using separate seed values and algorithms to generate passwords that are unrelated to any hinting information. This resolves the contradiction by removing the security risk of hint revelation while maintaining ease of operation through automated generation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10033724B2System of composite passwords incorporating hints
Publication Date: 2018.07.24 DONOHUE BEN DAMIAN
  • US10033724B2 patent drawing
  • US10033724B2 patent drawing
  • US10033724B2 patent drawing

AI summary

A system which generates composite passwords which can act to trigger a designated event; said system comprising a database having stored thereon at least first and second hints associated with at least respective first and second passwords, all of which are associated with a designated user; the system storing hints and passwords for multiple designated users and wherein each hint and password pair is generated by an association procedure whereby the password is uniquely derivable from the hint by the designated user with which that hint and password pair is associated; a composite password generated by the system presenting in a designated order of at least first and second hints to a designated user in response to which the designated user inputs respective first and second passwords to a local device thereby to assemble a composite password from the first and second passwords; the composite password then being stored on the local device.