Mobile Device Malware Resistance via Segmented Password Escrow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to malware due to ubiquitous hardware resources and the risk of password interception, especially when complex and unique passwords are required for secure websites, which can be difficult to manage and remember.

Innovation Solution

A mobile device and keyfob system that uses multi-factor authentication, where encrypted passwords are physically escrowed between two separate devices, requiring both for reconstitution and use in remote authentication, with Bluetooth Low Energy for secure data transfer and encryption/decryption handled by the mobile app.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are stored in mobile device for authentication, then authentication function is enabled, but device becomes vulnerable to malware interception

Engineering Contradiction:
Improveauthentication securityVSAvoidmalware vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The password is divided into multiple fragments and stored in different locations (mobile device, keyfob, server). No single location contains the complete password, preventing malware from intercepting the full credential. This segmentation approach directly resolves the contradiction by maintaining authentication functionality while eliminating the security vulnerability of storing complete passwords in one device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A keyfob device serves as an intermediary between the user and the authentication system. The keyfob holds a fragment of the password and must be physically present for authentication, creating a hardware-based intermediary that prevents remote malware interception. This intermediary approach enables authentication while blocking the harmful factor of network-based malware attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex unique passwords are used for secure websites, then security against fraudsters is improved, but ease of management and remembering is reduced

Engineering Contradiction:
Improvesecurity against fraudstersVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the complex password management task into automated components. The password manager application automatically generates, stores, and manages multiple complex passwords across different websites, while the user only needs to remember a single master password. This segmentation of the management burden resolves the contradiction by maintaining high security through complex passwords while improving ease of operation through automation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The password manager system provides self-service capabilities for password management. It automatically generates secure passwords, encrypts them, and manages them across multiple websites without requiring user intervention for each password. The system serves itself by handling the complex management tasks, thereby maintaining security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If passwords are encrypted and stored in vault, then security is maintained, but exposure time to malware increases

Engineering Contradiction:
Improvepassword securityVSAvoidexposure time to malware
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The password is segmented into fragments stored in different locations with different access requirements. The mobile device stores encrypted fragments but cannot reconstruct the full password without the keyfob. This segmentation reduces exposure time because even if malware compromises one storage location, it cannot access the complete password, thereby maintaining security while limiting the window of vulnerability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary encryption and fragmentation of passwords before storage. Passwords are encrypted and divided into fragments before being stored in the vault or keyfob, so that even during storage, the complete password is never exposed in plaintext. This preliminary action maintains security throughout the storage period while minimizing exposure time to potential malware threats.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10216935B2Mobile device resistant to malware
Publication Date: 2019.02.26 INTERSECTIONS LLC
  • US10216935B2 patent drawing
  • US10216935B2 patent drawing
  • US10216935B2 patent drawing

AI summary

A mobile device is made resistant to malware. Wireless mobile devices are paired with short-distance wireless technology to separate user gadgets like keyfobs. Two or more pieces of security passwords are escrowed separately amongst the physically distinct devices. Neither the mobile device nor its matching keyfob store or keep entire passwords.