Dummy Character Interleaving for Password Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing vulnerability of passwords to observation and unauthorized access due to the ease with which they can be seen or recorded, especially in busy environments, necessitates enhanced security measures to protect user accounts from nefarious actors.
Innovation Solution
The implementation of dummy characters that are intermixed with actual password characters, which are specific to a user's device or account, allowing multiple valid password strings to be entered that all evaluate to the user's actual password, thereby preventing unauthorized access from different devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dummy characters are intermixed with actual password characters to enhance security, then password security is improved, but device complexity increases
Solution Approach 1:
The patent introduces dummy characters as an intermediary element between the user and the actual password. These dummy characters are mixed with real password characters during input, creating a layered security mechanism where the dummy characters act as a protective veil over the actual credentials without requiring fundamental changes to the authentication system architecture
Solution Approach 2:
The system changes the parameter of password input by adding dummy characters that modify the apparent password string. This parameter change allows the same actual password to be entered in multiple valid ways (different combinations of dummy and real characters), thereby enhancing security without changing the underlying password storage or verification mechanisms
2Reliability
If dummy characters are made device-specific to prevent unauthorized access from different devices, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments the dummy characters into device-specific groups, where each registered device has its own set of dummy characters associated with it. This segmentation allows users to operate different devices with their respective dummy character sets without needing to remember multiple entirely different passwords, as the core actual password remains the same across all devices
Solution Approach 2:
The system performs preliminary registration of devices and associates dummy characters with each device before actual password entry. This preliminary action sets up the security framework in advance, so that during normal operation, users simply need to enter their password with the appropriate dummy characters for their current device, without needing to manually configure or remember complex device-specific credentials
Data Source
AI summary
Various systems and methods are provided for using dummy characters to provide enhanced security of a user's login credentials. The functionality disclosed herein provides specific steps for the creation, evaluation, storage, and use of such dummy characters in conjunction with a user's login credentials. Dummy characters can be thought of as characters that are not part of a user's actual password, but which are mixed in and around the actual characters when the password is being entered, in order to protect a user's true password from prying eyes and nefarious actors. Dummy characters can be associated with a specific user and/or a specific device or devices associated with a specific user. The functionality provided herein prevents a nefarious actor from simply repeating an entire password string (including the dummy characters) on a device that is not associated with the user whose credentials the nefarious actor is attempting to misappropriate.


