Dynamic Virtual Keypad for Secure PIN Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure online debit card transactions are vulnerable to keystroke monitoring and mouse tracking, which can compromise the secrecy of the PIN, leading to unauthorized transactions.
Innovation Solution
A dynamically changing virtual keypad is provided on a GUI, where the location, geometry, size of buttons, and spacing between them are altered for each transaction, making it difficult for spy software to track and correlate mouse movements with PIN entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static virtual keypad is used for PIN entry, then the user interface is simple and familiar, but the security against keystroke monitoring and mouse tracking is compromised
Solution Approach 1:
The patent applies the dynamics principle by making the keypad layout change dynamically for each transaction. The positions of keypad buttons are randomly rearranged after each PIN entry, transforming the static interface into a dynamic one. This prevents spy software from tracking mouse movements to correlate with PIN digits, as the button positions change between transactions.
Solution Approach 2:
The patent changes the spatial parameters (position coordinates) of the keypad buttons between transactions. By randomly permuting the button positions on the virtual keypad, the system alters the geometric arrangement parameter, making it impossible for tracking software to establish a consistent mapping between mouse coordinates and PIN digits across multiple transactions.
2Reliability
If the keypad layout changes for each transaction, then security against tracking is improved, but the user interface becomes less predictable and may confuse users
Solution Approach 1:
The patent applies local quality by maintaining the functional identity of each button while changing its position. Each button retains its association with a specific digit or function, but its spatial location on the screen changes. This allows users to remember the logical mapping (button 1 always enters '1') while the physical layout varies, balancing security with usability.
Solution Approach 2:
The system provides feedback to users through visual indicators showing which button was pressed and what digit it corresponds to. This feedback mechanism helps users understand the changing layout, reducing confusion while maintaining security. The feedback loop allows users to adapt to the dynamic layout without compromising the security benefit.
3Ease of operation
If traditional keypad layout is used, then ease of use is maintained, but vulnerability to spy software and mouse tracking increases
Solution Approach 1:
The patent transforms the static traditional keypad into a dynamic virtual keypad that reconfigures its button positions after each transaction. This dynamic behavior prevents spy software from establishing consistent tracking patterns, as the spatial relationship between mouse clicks and PIN digits changes with each use, effectively neutralizing the harmful tracking capability.
Solution Approach 2:
The system performs periodic reconfiguration of the keypad layout between transactions. By randomly rearranging button positions at regular intervals (after each PIN entry), the system creates a periodic change pattern that disrupts any attempt by spy software to correlate mouse movements with PIN digits across multiple transactions.
Data Source
AI summary
A method is provided for authenticating debit card transactions engaged in by a cardholder on a communications network. The method includes: a) establishing a connection over the network with a client being used by the cardholder to engage in a transaction on the network; b) providing over the connection to the client a web page containing a keypad (22) having a plurality of buttons (24) that collectively define a geometry of the keypad (22), the keypad (22) being employed by the cardholder to enter a PIN via selection of the buttons (24) with a pointing device of the client; c) obtaining over the connection the PIN enter by the cardholder; d) determining if the obtained PIN is correct for a debit card being used by the cardholder to engage in the transaction; e) repeating step a) through d) for each transaction the cardholder engages in on the network; and, f) with respect to two transactions engaged in by the cardholder, changing at least one of a location of the keypad (22) on the web page, the geometry of the keypad (22), a size of the buttons (24) and a spacing between neighboring buttons (24).


