Password Version Data for User Recall

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in recalling the correct password for password-protected devices, especially when private cryptographic keys are encrypted with a Key Store password and need to be backed up and restored, as they may change passwords over time and forget which password is associated with restored key sets.

Innovation Solution

Automatically defining unique password 'version' data, such as using the date/time the password was set, to help users identify the correct password, providing a clue for memory recall without revealing sensitive information to attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user-defined passwords are used for password-protected functionality, then user flexibility and security control are improved, but user recall difficulty increases

Engineering Contradiction:
Improveuser flexibilityVSAvoiduser recall
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by automatically generating and storing version data (such as date/time stamps) at the moment a password is created or changed. This version data is saved alongside the encrypted data, so when users need to recall their password, they are presented with the version data that serves as a clue without revealing the actual password. This preliminary recording of contextual information resolves the contradiction by providing recall assistance without compromising security or flexibility.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If password version data provides detailed clues to help user recall, then user recall ability is improved, but security against attackers deteriorates

Engineering Contradiction:
Improveuser recallVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by providing different types of information to different users in different contexts. For the legitimate user who needs to recall their password, the system provides version data (such as 'password created on June 1, 2004') that serves as a helpful clue. For potential attackers, the same version data reveals nothing about the actual password content. This localized differentiation of information quality resolves the contradiction between aiding user recall and maintaining security.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If generic password prompts are used, then security is maintained, but user frustration increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system introduces an intermediary element - the version data - that mediates between the security requirements and user experience needs. Instead of directly prompting users with generic messages that provide no help, or with specific password hints that compromise security, the version data acts as an intermediary that provides contextual information (such as creation dates) that helps users recall their passwords without revealing sensitive information. This intermediary resolves the contradiction by satisfying both security and user experience requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7594120B2User-defined passwords having associated unique version data to assist user recall of the password
Publication Date: 2009.09.22 MALIKIE INNOVATIONS LTD
  • US7594120B2 patent drawing
  • US7594120B2 patent drawing
  • US7594120B2 patent drawing

AI summary

An electronic device includes password protected functionality using a password that can be changed by the user. A user-specified password is stored in association with unique version data that is subsequently provided to help user recall of the password associated therewith.