Password Theft Protection via Output Credential Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password security methods are vulnerable to theft, as thieves can intercept and record individual characters using keyloggers or observation, compromising password security.

Innovation Solution

A method that generates an output password from an input password using password generation data, where the output password differs from the input password, allowing access to password-secured applications while keeping the original password inaccessible, utilizing a system comprising a password acquirer and generator that substitutes the output password in access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a password is used to control access to computer software, then access control is achieved, but the password becomes vulnerable to theft through keyloggers or observation

Engineering Contradiction:
Improvepassword securityVSAvoidpassword theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary transformation process between the user's input password and the password stored/verified by the application. A password generator component transforms the input password into a different output password using cryptographic algorithms or encoding schemes. This intermediary transformation ensures that the actual password never exists in its original form during transmission or storage, preventing keyloggers and observers from capturing the usable password.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by transforming the password through cryptographic functions that alter its form while maintaining its functional equivalence for authentication. The transformation uses secret keys, salts, or other parameters to generate a derived password that is functionally equivalent but structurally different, making it useless to attackers who intercept the transformed version.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the original password is used for access, then simplicity of access is maintained, but security against theft is compromised

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system maintains ease of operation by keeping the user's interaction simple - they still enter only one password as usual. The complexity of the transformation process occurs automatically in the background through the password generator, which the user never directly interacts with. This preserves the simple user experience while implementing strong security transformations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a functional copy or derivative of the password through transformation rather than using the original directly. The transformed password serves as a secure substitute that maintains the authentication function while eliminating security vulnerabilities. The user works with the simple input, while the system manages the complex transformation to secure copies.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9984247B2Password theft protection for controlling access to computer software
Publication Date: 2018.05.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9984247B2 patent drawing
  • US9984247B2 patent drawing
  • US9984247B2 patent drawing

AI summary

Accessing a password-secured computer software application by acquiring an input password, generating at a first computer an output password from the input password using password generation data, where the output password differs from the input password, and providing the output password to a second computer as part of a request to access a password-secured computer software application using the output password, where the password-secured computer software application is accessible using the output password, and where the password-secured computer software application is inaccessible using the input password.