Randomized Character Selection for Keystroke Logging Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure password entry are vulnerable to keystroke logging techniques, allowing unauthorized observers to detect password entries through visual, electrical, or other forms of covert monitoring, especially in public access environments where physical security is difficult to enforce.

Innovation Solution

A method that randomizes the timing and movement of character selection on input devices, such as keyboards or wheels, making the number of keystrokes or button presses unpredictable, thereby masking the entry of private information from covert observation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password entry methods are used, then ease of operation is maintained, but security is compromised due to vulnerability to keystroke logging

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies dynamics by making the character selection process variable and unpredictable. The system dynamically changes the number of keystrokes required to select each character, the timing between keystrokes, and the sequence of character presentation. This dynamic behavior prevents covert observers from using fixed patterns to log keystrokes, as each password entry session has different temporal and sequential characteristics.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes multiple parameters of the input process: the number of keystrokes per character, the timing intervals between keystrokes, the presentation speed of candidate characters, and the selection mechanism. By varying these parameters randomly or unpredictably, the system maintains ease of operation while preventing keystroke logging, as the observed parameters no longer correlate consistently with the entered password.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If keystroke logging prevention measures are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal input mechanism that serves multiple functions: standard character selection, randomization for security, and timing control. The same keyboard or input device is used for both conventional typing and the secure randomized entry method, eliminating the need for separate hardware systems. The software layer handles the complexity of randomization and timing while the physical device remains simple and familiar.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If randomization of input timing is implemented, then security against covert observation is improved, but productivity decreases due to longer entry time

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial randomization rather than complete randomization of all input parameters. The system randomizes certain aspects (timing intervals, number of keystrokes) while maintaining predictable aspects (character set, basic selection process). This partial action provides sufficient security against covert observation while limiting the increase in entry time, balancing productivity and security requirements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8495732B2Entering an identifier with security improved by time based randomization of input steps
Publication Date: 2013.07.23 EVIDEN USA INC
  • US8495732B2 patent drawing
  • US8495732B2 patent drawing
  • US8495732B2 patent drawing

AI summary

A secure method, apparatus or computer program incorporates a method for entering private information such as a user identifier, password or other secret code comprising at least one symbol or character. According to method in one illustrated embodiment, the user selects characters for input starting from presentation of an initial suggested character, moving under user control to presentation of a user's desired input character, and then followed by the selection by the user of that presented character as a character for data input. The method includes randomizing the timing of the display and/or reaction time to user input so that the number and timing of the key presses required to select any specific desired character for input is made unpredictable. This makes it difficult during entry of information to determine by covert means what specific information is being entered.