Dynamic Password Interface Scrambling to Prevent Keylogging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current password logon systems are inconvenient, not customizable, difficult to use, prone to hacking through keylogging, and require lengthy and complicated passwords, making them hard to manage and secure.
Innovation Solution
A password entry user interface with a graphical user interface displaying password characters in a location-based structure that can be scrambled upon triggering events, allowing users to customize characters and layout with user-provided images, and includes a password management module for flexible password management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password entry interfaces are used, then password protection is provided, but the system is prone to keylogging attacks and requires lengthy passwords
Solution Approach 1:
The patent implements dynamic password character positioning where characters are randomly relocated on the screen during each password entry session. This dynamic behavior prevents keylogging attacks because the physical position of characters changes between attempts, making it impossible for keyloggers to capture the correct sequence. Users interact with characters by clicking or hovering, rather than typing, which eliminates the vulnerability to traditional keylogging methods while maintaining security.
Solution Approach 2:
The patent replaces the mechanical keyboard typing system with a graphical user interface-based selection system. Instead of pressing physical keys that can be monitored by keyloggers, users select password characters by clicking or hovering over them on the screen. This substitution of the input mechanism eliminates the vulnerability to keylogging while providing a more visual and potentially easier interaction method.
2Device complexity
If password characters are displayed statically, then the interface is simple, but it is easy to hack through keylogging and requires frequent password changes
Solution Approach 1:
The patent introduces dynamic random repositioning of password characters on the screen. During each password entry attempt, the characters are displayed at different random positions, creating a dynamic interface that adapts to each user interaction. This dynamic behavior maintains interface simplicity from the user's perspective while dramatically improving security by preventing keylogging attacks and eliminating the need for frequent password changes.
3Reliability
If traditional password policies are enforced, then security is maintained, but users must manage numerous complex passwords across different systems
Solution Approach 1:
The patent creates a universal password entry interface that can be deployed across multiple computing systems and applications. The same graphical interface with dynamic character repositioning can protect passwords for operating systems, application programs, databases, and network systems uniformly. This multi-functional approach allows users to manage all their passwords through a single consistent mechanism, eliminating the need to remember different password formats and policies for different systems while maintaining strong security.
4Reliability
If password characters are displayed as asterisks, then security is improved, but usability is reduced and users cannot verify entry
Solution Approach 1:
The patent inverts the traditional approach by displaying the actual password characters in their correct positions on the screen, rather than hiding them with asterisks. Users verify their password entry by visually matching the characters they select with the displayed characters, eliminating the need for asterisks. This inversion maintains security through the dynamic repositioning mechanism while significantly improving usability and user verification capability.
Data Source
AI summary
An interface, system and method of password entry in a computing device/system including a graphical user interface including a plurality of password characters displayed on a screen according to a location-based structure and selectable by a pointing device; a scrambling module that scrambles where at least a portion of the password characters are positioned within the location-based structure when triggered; and a triggering module to trigger the scrambling module. The location-based structure may be a 3-dimensional object. There is a password manager module that allows a user to upload password characters that are user customized images. Alpha-numeric characters are not scrambled.


