Password Management App Physical Escrow Keyfob Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex passwords are difficult to remember and manage, and existing password manager mobile applications are vulnerable to malware and security breaches, as they store encrypted passwords locally on devices, making them susceptible to interception and theft.
Innovation Solution
A password management mobile app that physically escrows each encrypted password into two parts, with one part stored on a separate user gadget like a keyfob, requiring both the mobile device and keyfob for password reconstruction, using Bluetooth Low Energy for secure communication and encryption/decryption processes to ensure secure storage and retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords are stored locally in a password manager mobile application, then password management convenience is improved, but security vulnerability to malware and breaches worsens
Solution Approach 1:
The encrypted password database is split into two separate physical locations: the mobile device and a keyfob. Each location stores a portion of the encrypted data, and both are required to reconstruct and access any password. This segmentation ensures that even if one device is compromised, the attacker cannot access passwords without the second device.
Solution Approach 2:
The keyfob acts as an intermediary security device that mediates password access. It contains a portion of the encrypted password database and requires wireless communication with the mobile device to reconstruct passwords. This intermediary layer adds a security buffer between the password manager application and potential attacks.
2Reliability
If complex passwords are used to secure websites, then security against fraudsters is improved, but ease of remembering and managing passwords worsens
Solution Approach 1:
The system creates encrypted copies of passwords and stores them in two separate physical locations (mobile device and keyfob). The user only needs to remember a single master password to decrypt the password database, while the actual complex passwords are stored as encrypted copies that require both devices to access. This eliminates the need for users to manually remember multiple complex passwords.
3Reliability
If encrypted passwords are stored in a vault on the mobile device, then password protection is improved, but susceptibility to interception and theft worsens
Solution Approach 1:
The encrypted password database is segmented across two separate physical devices. The mobile device stores one portion and the keyfob stores another portion. Both portions are required to reconstruct any password, which means that even if the mobile device is intercepted or breached, the attacker cannot access passwords without also obtaining and compromising the keyfob.
Solution Approach 2:
The system transitions from storing all encrypted passwords in a single location (mobile device vault) to distributing them across two separate physical dimensions (mobile device and keyfob). This spatial distribution across different physical devices creates an additional layer of security that mitigates interception risks.
Data Source
AI summary
Physical security methods and equipment are applied to mobile devices that use multi-factor authentication mobile apps. Herein, a password management mobile app physically escrows each encrypted password that must be stored into two parts. These are then distributed between two separate, independent physical devices. Only one of those parts is kept only in a separate user gadget like a keyfob. Any reconstitution of each password after decryption requires that the user have on-hand both the mobile device and the separate user gadget. Such reconstitution is one password at a time, and only as needed, and released for use in remote authentication with a master user password entry.


