Randomized Character Selection for Keystroke Logging Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure password entry are vulnerable to keystroke logging techniques, allowing unauthorized observers to detect password entries through visual, electrical, or other forms of covert monitoring, especially in public access environments where physical security is difficult to enforce.
Innovation Solution
A method that randomizes the timing and movement of character selection on input devices, such as keyboards or wheels, making the number of keystrokes or button presses unpredictable, thereby masking the entry of private information from covert observation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password entry methods are used, then ease of operation is maintained, but security is compromised due to vulnerability to keystroke logging
Solution Approach 1:
The patent applies dynamics by making the character selection process variable and unpredictable. The system dynamically changes the number of keystrokes required to select each character, the timing between keystrokes, and the sequence of character presentation. This dynamic behavior prevents covert observers from using fixed patterns to log keystrokes, as each password entry session has different temporal and sequential characteristics.
Solution Approach 2:
The patent changes multiple parameters of the input process: the number of keystrokes per character, the timing intervals between keystrokes, the presentation speed of candidate characters, and the selection mechanism. By varying these parameters randomly or unpredictably, the system maintains ease of operation while preventing keystroke logging, as the observed parameters no longer correlate consistently with the entered password.
2Reliability
If keystroke logging prevention measures are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal input mechanism that serves multiple functions: standard character selection, randomization for security, and timing control. The same keyboard or input device is used for both conventional typing and the secure randomized entry method, eliminating the need for separate hardware systems. The software layer handles the complexity of randomization and timing while the physical device remains simple and familiar.
3Reliability
If randomization of input timing is implemented, then security against covert observation is improved, but productivity decreases due to longer entry time
Solution Approach 1:
The patent applies partial randomization rather than complete randomization of all input parameters. The system randomizes certain aspects (timing intervals, number of keystrokes) while maintaining predictable aspects (character set, basic selection process). This partial action provides sufficient security against covert observation while limiting the increase in entry time, balancing productivity and security requirements.
Data Source
AI summary
A secure method, apparatus or computer program incorporates a method for entering private information such as a user identifier, password or other secret code comprising at least one symbol or character. According to method in one illustrated embodiment, the user selects characters for input starting from presentation of an initial suggested character, moving under user control to presentation of a user's desired input character, and then followed by the selection by the user of that presented character as a character for data input. The method includes randomizing the timing of the display and/or reaction time to user input so that the number and timing of the key presses required to select any specific desired character for input is made unpredictable. This makes it difficult during entry of information to determine by covert means what specific information is being entered.


