Dummy Character Interleaving for Password Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing vulnerability of passwords to observation and unauthorized access due to the ease with which they can be seen or recorded, especially in busy environments, necessitates enhanced security measures to protect user accounts from nefarious actors.

Innovation Solution

The implementation of dummy characters that are intermixed with actual password characters, which are specific to a user's device or account, allowing multiple valid password strings to be entered that all evaluate to the user's actual password, thereby preventing unauthorized access from different devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dummy characters are intermixed with actual password characters to enhance security, then password security is improved, but device complexity increases

Engineering Contradiction:
Improvepassword securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces dummy characters as an intermediary element between the user and the actual password. These dummy characters are mixed with real password characters during input, creating a layered security mechanism where the dummy characters act as a protective veil over the actual credentials without requiring fundamental changes to the authentication system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of password input by adding dummy characters that modify the apparent password string. This parameter change allows the same actual password to be entered in multiple valid ways (different combinations of dummy and real characters), thereby enhancing security without changing the underlying password storage or verification mechanisms

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dummy characters are made device-specific to prevent unauthorized access from different devices, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the dummy characters into device-specific groups, where each registered device has its own set of dummy characters associated with it. This segmentation allows users to operate different devices with their respective dummy character sets without needing to remember multiple entirely different passwords, as the core actual password remains the same across all devices

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary registration of devices and associates dummy characters with each device before actual password entry. This preliminary action sets up the security framework in advance, so that during normal operation, users simply need to enter their password with the appropriate dummy characters for their current device, without needing to manually configure or remember complex device-specific credentials

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11361068B2Securing passwords by using dummy characters
Publication Date: 2022.06.14 DELL PROD LP
  • US11361068B2 patent drawing
  • US11361068B2 patent drawing
  • US11361068B2 patent drawing

AI summary

Various systems and methods are provided for using dummy characters to provide enhanced security of a user's login credentials. The functionality disclosed herein provides specific steps for the creation, evaluation, storage, and use of such dummy characters in conjunction with a user's login credentials. Dummy characters can be thought of as characters that are not part of a user's actual password, but which are mixed in and around the actual characters when the password is being entered, in order to protect a user's true password from prying eyes and nefarious actors. Dummy characters can be associated with a specific user and/or a specific device or devices associated with a specific user. The functionality provided herein prevents a nefarious actor from simply repeating an entire password string (including the dummy characters) on a device that is not associated with the user whose credentials the nefarious actor is attempting to misappropriate.