Hierarchical Password Mechanism for Mobile Security Usability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face challenges in managing access to applications with varying security requirements, particularly in the BYOD scenario, where complex passwords hinder usability and increase input errors, especially for users with physical impairments or in unstable conditions.

Innovation Solution

A hierarchical password protection mechanism is implemented, where passwords are configured in a hierarchy with varying security levels, each associated with application groups, allowing automatic access to lower-level applications and prompting for higher-level passwords as needed, along with event-responsive configurations and virtual home screens with hot keys for fast access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a complex password with mixed letters and numbers is required to secure enterprise data, then security is improved, but usability deteriorates due to frequent keyboard switching and increased input errors

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the application set into multiple groups with different security levels, each protected by a corresponding password level. Users only need to enter passwords for the specific application group they are accessing, not for all applications. This segmentation allows enterprise applications to have strong password protection while personal applications can use simpler passwords or no password, thus resolving the contradiction between security and usability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a complex password is required, then security is improved, but the likelihood of input errors increases greatly

Engineering Contradiction:
ImprovesecurityVSAvoidinput accuracy
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

By segmenting applications into security groups, the system allows users to enter simpler passwords for less sensitive application groups while maintaining strong passwords for enterprise application groups. This reduces the overall frequency of complex password entry and associated input errors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary classification of applications into security groups during setup. This preliminary action organizes applications by security requirements, so that during normal use, users only encounter password prompts for the specific group they are accessing, reducing unnecessary complex password entry and potential input errors.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a single complex password is enforced for all applications, then security is improved, but device accessibility for users with physical impairments deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments applications into multiple security groups, allowing different password complexity requirements for different groups. Users with physical impairments can access personal applications with simpler passwords or alternative authentication methods, while enterprise applications maintain stronger security requirements. This segmentation provides adaptability for different user needs while preserving security where required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different security qualities to different application groups based on their sensitivity. Personal applications can have lower security requirements with simpler passwords, while enterprise applications have higher security requirements. This local differentiation of security quality allows the system to be accessible to users with impairments while maintaining security for sensitive data.

Inventive Principle:
Principle #3Local quality

4Reliability

If multiple password levels are implemented for different application groups, then security management is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity managementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments applications into security groups and implements corresponding password levels. The system automatically manages this segmentation and password level assignment, so while the security management capability is improved through differential protection, the user does not need to manually manage the complexity. The system handles the complexity automatically based on the segmented structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal password management system that handles multiple password levels and application groups through a single integrated mechanism. This multi-functional system can manage simple and complex passwords, different application groups, and various security levels all through one unified interface and process, reducing the perceived complexity for users while providing advanced security management capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9984246B2Differential hierarchical-based password security mechanism for mobile device
Publication Date: 2018.05.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9984246B2 patent drawing
  • US9984246B2 patent drawing
  • US9984246B2 patent drawing

AI summary

Mobile device application access is managing by a hierarchical password protection mechanism. In this scheme, a set of passwords is configured in a hierarchy, wherein a password at a higher level in the hierarchy authorizes greater permissions than a password at a lower level in the hierarchy. Each password in the set of passwords is then associated with a respective application group of a set of application groups, each application group comprising applications having a common security requirement. Thus, a given password in the password hierarchy is associated with a particular application group. When the device detects entry of a given password at a given level in the hierarchy, access to the applications in the application group associated with the given password is then enabled automatically. In addition, access to the applications in each application group associated with passwords that are lower in the hierarchy also is enabled.