Credential Injector Agent for Malware-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for user credential management are vulnerable to malware, as they often require direct entry of passwords, which can be intercepted or exploited, leading to unauthorized access to multiple systems and data.

Innovation Solution

Establishing an encrypted, mutually authenticated secure channel between a software application and a portable electronic device, using a credential injector agent and an authentication server to verify transactions without exposing user credentials to malware, ensuring secure communication and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct password entry is used for authentication, then ease of operation is improved, but security deteriorates due to malware interception

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a credential injector agent as an intermediary component that runs in memory and mediates between the application and the password manager. This agent captures authentication requests, retrieves credentials securely, and injects them into the application without exposing passwords to malware on the host system. The intermediary layer protects credentials while maintaining automated authentication convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of direct password entry with a software-based credential injection system. Instead of manually typing passwords or having them displayed, the system uses programmatic credential retrieval and injection through the credential injector agent, eliminating the need for direct password exposure while maintaining authentication functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If passwords are stored in a password manager for security, then security is improved, but ease of operation deteriorates due to manual retrieval requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of credential access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service automation where the credential injector agent automatically monitors for authentication requests, retrieves appropriate credentials from the password manager, and injects them into the application without user intervention. This eliminates manual password retrieval while maintaining security, as the automated agent operates securely in memory without exposing credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The credential injector agent serves as an intermediary that bridges the password manager and applications, enabling automatic credential retrieval and injection. This intermediary layer allows secure automated access to stored passwords without requiring users to manually retrieve and enter them, thus improving ease of operation while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the same password is reused across multiple systems, then ease of operation is improved, but security deteriorates due to widespread vulnerability

Engineering Contradiction:
Improveease of password managementVSAvoidvulnerability to malware
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts passwords from the host system environment where they would be vulnerable to malware, and stores them securely in a dedicated password manager. The credential injector agent then retrieves only the necessary credential data in memory without exposing the actual passwords on the host system. This extraction isolates credentials from malware threats while maintaining the convenience of centralized password management.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If passwords are encoded and stored for security, then security is improved, but ease of operation deteriorates due to manual entry requirement

Engineering Contradiction:
ImprovesecurityVSAvoidease of password entry
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The credential injector agent provides self-service automation by automatically retrieving encoded credentials from the password manager and injecting them into applications without user intervention. This eliminates the need for users to manually decode or enter passwords, maintaining security through encoded storage while improving ease of operation through automated credential injection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11563740B2Methods and systems for blocking malware attacks
Publication Date: 2023.01.24 BLUINK INC
  • US11563740B2 patent drawing
  • US11563740B2 patent drawing
  • US11563740B2 patent drawing

AI summary

User identities, password, etc. represent the barrier between a user's confidential data and any other third party seeking to access this data. As multiple software applications, web applications, web services, etc. embody this confidential data it is a tradeoff between easy recollection of said identities, passwords, etc. and data security. However, malware by intercepting user credentials provides third parties access to even complex passwords, user credentials, security keys etc. even where these are changed/updated regularly. Within the prior art substantial work has gone into addressing malware. However, in many instances the user is at or very near the computer with a software application executing a transaction requiring credentials/authorisation with a portable electronic device or another device. Accordingly, it would be beneficial to provide users with an out-of-band communications channel for exchanging credentials and/or keys etc.