Covert Password Manager Using Decoy Application Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional login interfaces for accessing confidential information, such as password, medical, and financial data, pose security risks as they invite unauthorized access, with hackers attempting to gain access by entering valid credentials, despite additional security features like limiting invalid attempts.

Innovation Solution

A password manager application with a decoy module that disguises its functionality, using a covert login interface where inputs are evaluated for expected data types, allowing authorized users to customize login credentials and appearance, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a traditional login interface is provided for accessing confidential information, then ease of operation is improved, but security is worsened due to inviting unauthorized access

Engineering Contradiction:
Improveease of accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a decoy application that is a visual copy of the actual password manager interface. The decoy application appears identical to the real application but contains fake functionality and no actual password storage. This copies the appearance and structure of the legitimate application to mislead unauthorized users into interacting with a harmless fake version, thereby resolving the contradiction by maintaining ease of access for authorized users while preventing unauthorized access through deception.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The decoy application serves as an intermediary layer between the user interface and the actual password storage system. When a user launches the application, they are presented with the decoy interface first, which mediates the interaction. The decoy acts as a barrier that intercepts potential unauthorized access attempts while allowing authorized users to proceed to the real functionality through proper authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If additional security features like limiting invalid login attempts are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidsecurity feature complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Instead of implementing complex security features within the actual password manager, the patent creates a simplified decoy application that replicates the basic interface structure without the complex authentication and security logic. The decoy contains only the visual and interactive elements needed for the interface, while the actual security mechanisms remain hidden in the legitimate application, thereby reducing the complexity visible to users and analysts.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts the complex security validation logic from the visible user interface and places it within the legitimate application's backend. The decoy application takes out only the superficial interface elements, separating the complex security functionality from the visual presentation. This extraction allows the interface to remain simple while the security mechanisms operate independently in the actual application.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9716706B2Systems and methods for providing a covert password manager
Publication Date: 2017.07.25 FITZGERALD JOSEPH
  • US9716706B2 patent drawing
  • US9716706B2 patent drawing
  • US9716706B2 patent drawing

AI summary

The present invention relates to an application that is configured to provide secure access to confidential information. To protect the confidential information, the application may include functions that utilize a decoy application to disguise the functionality of the application. A unique sequence of inputs received through an interface associated with the decoy application may permit a user to access the confidential information. An authorized user that has been provided access to the confidential information may access configuration interfaces that permit the user to define the inputs that will serve as login credentials and to customize the appearance and functionality of the decoy application.