Randomized Keypad Transformation for Snooping-Resistant Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for keyboard and keypad entry, such as PIN/pinpad authentication, are vulnerable to snooping and keylogging attacks, particularly for high-value targets, with biometrics and Multi-Factor Authentication (MFA) having limitations.
Innovation Solution
Implementing a Random Transformation Algorithm (RTA) that randomly transforms keyboard or keypad characters during password entry, instructing users to apply the transformation, and reversing it internally to generate a unique key sequence for each session, enhancing security against visual snooping and keylogging.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical covers are used to block observation of the keyboard or keypad, then security against snooping is improved, but ease of operation deteriorates due to reduced visibility for users
Solution Approach 1:
The keyboard layout is dynamically transformed using a Random Transformation Algorithm that randomly repositions keys and modifies their functions for each authentication session. This dynamic change ensures that even if an attacker observes the keyboard, the layout will be different in the next session, providing security without requiring physical covers that would block user visibility.
Solution Approach 2:
The system changes the parameters of the keyboard interface by applying transformations such as random repositioning of keys, swapping key functions, and modifying key mappings. These parameter changes create a unique keyboard layout for each session, preventing snooping while maintaining full visibility and accessibility for the legitimate user.
2Reliability
If biometrics or Multi-Factor Authentication are used to improve security, then authentication security is enhanced, but device complexity and user burden increase
Solution Approach 1:
The Random Transformation Algorithm acts as an intermediary layer between the user and the authentication system. Instead of adding complex biometric sensors or multiple authentication factors, the RTA transforms the existing keyboard into a secure interface that prevents snooping and keylogging while maintaining the simplicity of the original authentication mechanism.
Solution Approach 2:
The system creates a virtual copy of the keyboard with transformed key positions and functions. This virtual keyboard layer provides security against physical and digital attacks without requiring additional hardware components or complex authentication protocols, thus avoiding increased device complexity.
3Ease of operation
If standard keyboard layouts are used for ease of use, then ease of operation is maintained, but security against keylogging and snooping deteriorates
Solution Approach 1:
The keyboard layout transitions from a static, predictable arrangement to a dynamic, randomly transformed configuration for each authentication session. This dynamic transformation maintains ease of operation for legitimate users who receive the transformation instructions, while preventing keylogging attacks since the layout changes between sessions.
Solution Approach 2:
The system performs preliminary transformation of the keyboard layout before the authentication session begins. The Random Transformation Algorithm generates and applies the transformation, then communicates the transformed layout to the user in advance, allowing the user to adapt to the new layout without difficulty while the attacker remains oblivious to the changes.
Data Source
AI summary
An information handling system (IHS) (e.g., a terminal, automated teller machine, etc.) initiates a password input session, creates a Random Transformation Algorithm (RTA) for the input session, instructs an IHS user to apply the RTA to entry of a key sequence of the password, accepts entry of the key sequence from the user via an IHS keyboard and/or keypad, and reverses transformation of the user entry of the key sequence in accordance with the RTA logically arriving at the password. The IHS may then (encrypt and) send the password to a server for authentication. The RTA may swap keyboard and/or keypad characters by position and/or value, shift keyboard and/or keypad character values up or down, geometrically move keyboard and/or keypad characters, and/or rotate keyboard and/or keypad characters about an axis. The instructions may be communicated to the user via a third party device, the keyboard, a display, or the like.


