Dynamic Grid Secure Data Entry Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure data entry methods are vulnerable to unauthorized access, particularly through shoulder surfing and keystroke logging, and often require complex passwords that are difficult for users to remember and secure.
Innovation Solution
A system and method for secure data entry using a graphic input pattern on a client device, where the pattern corresponds to alphanumeric digits, and the data entered is communicated to a server for interpretation as a credential, providing additional security through dynamic patterns and obfuscation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional one-dimensional password input is used, then the system is simple to operate, but security is compromised due to shoulder surfing and keystroke logging
Solution Approach 1:
The patent transitions from traditional one-dimensional linear password input to a two-dimensional grid-based input system. Users select characters by touching grid positions rather than sequential typing, adding a spatial dimension to the input method. This dimensional change prevents shoulder surfing and keystroke logging while maintaining user-friendly operation through direct touch selection.
Solution Approach 2:
The patent implements dynamic character arrangement where the grid positions of alphanumeric characters change with each display. Characters are randomly positioned within the grid, and the layout is refreshed for each authentication attempt. This dynamic repositioning prevents observers from predicting or memorizing character locations, enhancing security while keeping the interface consistent and easy to use.
2Reliability
If complex passwords are required for security, then unauthorized access is prevented, but users struggle to remember and securely store these passwords
Solution Approach 1:
The patent extracts the memorability burden from the authentication system by eliminating the need for users to remember complex passwords. Instead, users only need to remember a simple passcode (e.g., 1234), while the system handles the complex character selection process through the dynamic grid interface. This separation of concerns maintains strong security while dramatically improving user experience.
Solution Approach 2:
The patent introduces a software intermediary layer between the user's simple passcode and the system's authentication requirements. The application on the client device acts as a mediator that translates the simple passcode into secure authentication credentials through the dynamic grid character selection process, protecting users from having to manage complex passwords while maintaining security.
3Ease of operation
If static pattern matrices are used for password protection, then the input method is simple, but the system remains vulnerable to shoulder surfing and key-stroke loggers
Solution Approach 1:
The patent transforms the static pattern matrix into a dynamic system where character positions are randomly reassigned with each display. The grid layout changes continuously, preventing observers from capturing or memorizing the pattern. This dynamic behavior maintains the simplicity of grid-based selection while eliminating the security vulnerability of static patterns to shoulder surfing and screenshot attacks.
Data Source
AI summary
A system or method of secure data entry can include one or more processors and memory having computer instructions which when executed by the one or more processors causes the one or more processors to perform the operations at a client edge device of executing a user interface data entry application on the client edge device, receiving data by the user interface data entry application, wherein the data entered is a graphic input pattern corresponding to characters, communicating the data entered to a server, and receiving access to the server if a data processing application at the server interprets the data entered as a credential based on rules negotiated between the data entry application and the data processing application and a template for the graphic input pattern.


