Password Hopping System Using Disposable Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password security practices are inadequate due to user behavior, such as selecting weak, reused, or old passwords, leading to data breaches and compromised security, despite the implementation of complex password policies and additional authentication factors.

Innovation Solution

The Password Hopping System (PHS) dynamically generates and replaces passwords using a hopping algorithm that incorporates time-variable data sources, ensuring passwords are strong, easy to remember, and have a limited lifespan, thereby enhancing security without increasing complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users select simple passwords for ease of use, then ease of operation is improved, but security strength deteriorates

Engineering Contradiction:
Improveease of useVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSStrength

Solution Approach 1:

The system generates disposable passwords that are valid for only a single authentication transaction. After use, each password becomes invalid and is discarded. This allows users to employ simple, easy-to-type passwords without security risk, as each password can be compromised only once before expiring automatically.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system dynamically generates a new password for each authentication transaction rather than using static passwords. The password changes automatically between uses, making the authentication credentials dynamic and time-sensitive, thereby preventing reuse attacks while maintaining simplicity.

Inventive Principle:
Principle #15Dynamics

2Strength

If passwords are made strong and complex to improve security, then security strength is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity strengthVSAvoidease of use
Core Design Contradiction:
StrengthVSEase of operation

Solution Approach 1:

Instead of requiring complex passwords that are hard to remember, the system uses simple disposable passwords that are easy to type but valid for only one use. This reverses the traditional approach by making password simplicity acceptable through the disposable nature of each credential.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system automatically generates and manages the password sequence without requiring user intervention for complexity management. Users simply receive and use the passwords as provided, eliminating the burden of creating and remembering complex passwords while maintaining strong security through automated password rotation.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If password lifetime is extended to reduce changes, then ease of operation is improved, but security deteriorates due to increased exposure time

Engineering Contradiction:
Improveease of useVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Each password is designed to have an extremely short lifetime—valid for only a single authentication transaction. This disposable approach ensures that even if a password is compromised, the window of vulnerability is minimized to the duration of a single use, thereby maintaining security while simplifying user interaction.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system implements periodic password generation where a new password is automatically created for each authentication transaction. This regular renewal of credentials ensures that no single password remains valid for an extended period, preventing long-term exposure risks while maintaining operational simplicity.

Inventive Principle:
Principle #19Periodic action

4Ease of operation

If password reuse is allowed for convenience, then ease of operation is improved, but security deteriorates due to credential stuffing attacks

Engineering Contradiction:
Improveease of useVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system eliminates password reuse by making each password valid for only one authentication transaction. After a password is used, it automatically expires and cannot be reused. This prevents credential stuffing attacks where stolen passwords are tried across multiple sites, as each password is unique to a single transaction.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system makes password credentials dynamic by generating a new password for each authentication event rather than allowing static password reuse. This dynamic credential generation ensures that even if one password is compromised, it cannot be reused for other authentications, thereby preventing cross-site credential attacks.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11151243B1Password hopping system and method
Publication Date: 2021.10.19 HOPR CORP
  • US11151243B1 patent drawing
  • US11151243B1 patent drawing
  • US11151243B1 patent drawing

AI summary

The present invention is a system and method for the repeated, dynamic, and automated transformation and manipulation of strings of printable or typeable characters that are commonly used for passwords, PINs, keys, tokens, keys, encryption, and filenames forming a class of printable strings. The system and method described makes use of secured password “Hopping” to maximize data security and user's ease of implementation. “Hopping” refers to a method of automated random-password construction and serial substitution. The process of Hopping as described herein is based upon a set of user-selected transformation rules that employ, among other variables, easily accessible, time-variable, data as sources of randomized inputs. Use of randomized inputs and automated serial substitution at time intervals heightens the security of resulting generated passwords.