Automatic Credential Injection via Visual Code Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in entering and remembering complex passwords, credit card numbers, and digital signatures, leading to security vulnerabilities as they often reuse weak passwords across multiple systems, making them susceptible to unauthorized access.

Innovation Solution

A method involving a device with a microprocessor and memory that stores user credentials, transmits signals to mimic keyboard and cursor controller actions to automatically enter credentials into data entry fields on another device, using visual codes to determine entry locations and types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually enter complex passwords and security credentials, then security requirements are met, but user convenience deteriorates and password reuse increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically captures credentials from the authentication challenge screen and fills them into the login form without user intervention. The mobile device self-services the entire authentication process by detecting the challenge, generating the response, and injecting it into the target application, eliminating manual password entry while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile device acts as an intermediary between the authentication server and the target application. It receives the authentication challenge, processes it through secure credential storage, and returns the authenticated response, mediating the security process without requiring the user to handle sensitive credentials directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users store passwords in memory devices for retrieval, then security is improved, but convenience deteriorates as users still must enter passwords manually

Engineering Contradiction:
ImprovesecurityVSAvoidtime to authenticate
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-storing credentials in secure memory and pre-configuring the authentication flow. When authentication is needed, the credentials are already prepared and can be automatically injected into the login form, eliminating the time required for manual entry and retrieval.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces the mechanical process of manual password entry with automated electronic credential injection. The mobile device electronically transmits the authenticated response directly to the target application, substituting the manual typing process with an automated digital workflow that eliminates time loss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If automatic credential entry is implemented, then user convenience is improved, but device complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The mobile device performs multiple functions: it serves as the authentication server, credential storage, challenge responder, and automated form filler. By consolidating these functions into a single universal device, the system avoids the complexity of dedicated hardware for each function while maintaining automated credential entry convenience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10079826B2Methods and systems for data entry
Publication Date: 2018.09.18 BLUINK
  • US10079826B2 patent drawing
  • US10079826B2 patent drawing
  • US10079826B2 patent drawing

AI summary

User identities, password, etc. represent the barrier between a user's confidential data and any other third party seeking to access this data. As multiple software applications, web applications, web services, etc. embody this confidential data it is a tradeoff between easy recollection of said identities, passwords, etc. and data security. Generally for most users the balance is too far to convenience and ease of recollection such that the probability of third party illegally accessing the confidential data increases. Accordingly, it would be beneficial for users as well as organizations providing/controlling access to systems, resources, and data to be provided with an automatic means of entering password and/or security credential information without the user, for example, selecting the password, knowing the password, having access to the password, or entering the password.