Programmable Input Device Encryption for Phishing Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures are inadequate in protecting user confidential information from being compromised by phishing and keylogging attacks, as they can be breached even with temporary access to one-time passwords, allowing unauthorized access to accounts.
Innovation Solution
A programmable human input device configured to encrypt user input using a service-specific encryption key, ensuring that only the encrypted input is transmitted, preventing unauthorized decryption and access to the unencrypted data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password transmission methods are used, then ease of operation is maintained, but security is compromised due to phishing and keylogging attacks
Solution Approach 1:
The patent introduces an intermediary encryption device that sits between the user and the service. This device encrypts user input locally using stored encryption keys before transmission, preventing attackers from capturing plaintext passwords even if they intercept communications or compromise the user's device. The intermediary nature of this encryption layer resolves the contradiction by adding security without requiring users to change their input behavior.
Solution Approach 2:
The encryption keys are pre-stored in the encryption device before any user input occurs. By performing the encryption key storage and setup in advance, the system enables seamless secure communication without requiring users to perform complex security actions during operation. This preliminary preparation resolves the contradiction by making security transparent to the user.
2Reliability
If encryption is implemented at the service level, then security is improved, but device complexity increases due to key management requirements
Solution Approach 1:
The patent segments the security functionality into a separate, dedicated encryption device rather than embedding it within the general-purpose computer or service. This segmentation isolates the complex key management and encryption operations to a specialized component, keeping the main computer system simple while achieving robust security. The encryption device handles all cryptographic operations independently.
Solution Approach 2:
The encryption device operates autonomously, managing its own encryption keys and performing encryption operations without requiring complex configuration or intervention from the user or service provider. This self-service capability reduces the overall system complexity by eliminating the need for centralized key management infrastructure or complex authentication protocols.
3Reliability
If one-time passwords are used, then security is temporarily enhanced, but vulnerability increases because automated systems can capture and reuse them quickly
Solution Approach 1:
The patent replaces the time-based security mechanism (one-time passwords that expire after a set duration) with a cryptographic mechanism based on encryption keys. Instead of relying on temporal limitations to prevent attacks, the system uses mathematical encryption to protect credentials indefinitely. This substitution eliminates the vulnerability window that exists with time-based systems while maintaining strong security.
Data Source
AI summary
According to one general aspect, a method may include accessing a service via a computer. The computer may be coupled to a programmable human input device. The programmable human input device may be configured to directly receive user input from a human user and stores at least one encryption key. The method may include encrypting, by the programmable human input device, user confidential input using an encryption key associated with the service and stored within the programmable human input device. The method may also include transmitting the encrypted user confidential input to the service via the computer, wherein the computer is not configured to determine the unencrypted user confidential input from the encrypted user confidential input.


