Password Derivation from User Phrases Using Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional password methods, such as using words or substituting characters with metacharacters, are easily guessable and not effective in strengthening access control, as they can be found in dictionaries or predicted with relative ease.
Innovation Solution
A method of deriving a password from a phrase provided by a user, where multiple words are selected and modified to form a strong, unique password that is difficult to predict, yet easy for the user to remember, by concatenating alternative words generated from the original phrase.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional passwords (words or metacharacter substitutions) are used, then passwords are easy to remember, but they are easily guessable and found in dictionaries
Solution Approach 1:
The patent segments a phrase into multiple individual words, then selects and modifies specific words to create password components. This segmentation allows the system to extract meaningful elements from the user's phrase while transforming them into secure password material that resists dictionary attacks.
Solution Approach 2:
The patent applies parameter changes by modifying selected words through various transformations (substitution, deletion, insertion, transposition) to create alternative words. These parameter changes ensure the resulting password is not found in dictionaries while maintaining a connection to the user's memorable phrase.
2Reliability
If metacharacters are substituted for characters in passwords, then passwords appear more complicated, but the substitution patterns are easy to predict
Solution Approach 1:
Instead of starting with a simple password and adding metacharacter substitutions, the patent inverts the approach by starting with a phrase, segmenting it into words, and then applying systematic modifications to create password components. This inversion fundamentally changes the password creation process to avoid predictable substitution patterns.
Solution Approach 2:
The patent creates a composite password structure by combining multiple modified words into a single password string. This composite approach integrates multiple transformation operations across different word segments, creating a password that is both strong and resistant to prediction while maintaining user memorability through its phrase-based origin.
3Reliability
If multiple words are selected and modified from a user's phrase to form a password, then the password becomes highly secure and difficult to predict, but the process becomes more complex
Solution Approach 1:
The system performs self-service by automatically segmenting the user's phrase, selecting appropriate words, applying modifications, and generating the final password without requiring manual intervention. This automation handles the complexity of the multi-step process while presenting a simple interface to the user, resolving the contradiction between security and process complexity.
Data Source
AI summary
A technique controls access to a resource. The technique includes deriving, by processing circuitry, a password based on a phrase/thought provided by a user. The technique further includes confirming with the user that the password is to control access to the resource. The technique further includes, after confirming with the user that the password is to control access to the resource, imposing a requirement that the user provide the password before obtaining access to the resource. Such a password may be formed by concatenating multiple words (e.g., four words) that may be unrelated to each other. Such a password may be relatively strong since the resulting concatenation would not be found in any dictionary, and since it would be an extremely difficult and time consuming endeavor to predict such a password by attempting to combine words from a dictionary to form the concatenations.


