Security Key Island for Password Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face security risks due to the common practice of using the same username and password across multiple online accounts, making them vulnerable to 'break once, run everywhere' attacks, and managing distinct passwords is inconvenient.
Innovation Solution
A system comprising a master controller and a sensitive information storage device (SIS device) with a user-activatable 'island' that controls access to stored sensitive information, using direct machine-to-machine communication and encryption to minimize software and internet-based security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users use the same username and password across multiple online accounts, then ease of operation is improved, but security reliability deteriorates due to break-once-run-everywhere attacks
Solution Approach 1:
The patent introduces a physical security key device as an intermediary between the user and online accounts. This device stores cryptographic credentials and requires physical possession plus user authentication (via display confirmation) to access stored credentials, thereby eliminating the need for users to manage multiple passwords while preventing unauthorized access without the physical device.
2Reliability
If users create distinct usernames and passwords for each online account, then security reliability is improved, but ease of operation deteriorates due to the inconvenience of remembering and managing multiple credentials
Solution Approach 1:
The patent uses cryptographic copying where the security key device contains a private key that corresponds to a public key stored on remote servers. This allows the device to sign authentication requests without exposing the private key, effectively copying the authentication capability while maintaining security. The user only needs to remember a single PIN code for the device rather than multiple passwords.
3Ease of operation
If software-based authentication systems are used, then ease of operation is improved through automated login, but security reliability deteriorates due to software vulnerabilities and internet-based attacks
Solution Approach 1:
The patent replaces software-based authentication with a hardware-based security key device that uses cryptographic operations. The device contains a secure element that performs cryptographic signing locally, replacing vulnerable software authentication mechanisms with hardware-enforced security. The device requires physical presence and user confirmation via display, eliminating remote software-based attacks.
4Ease of operation
If the island is always activated for easy access to sensitive information, then ease of operation is improved, but security reliability deteriorates due to potential unauthorized access
Solution Approach 1:
The patent implements a dynamic activation model where the island (containing sensitive information) is activated only when the user physically holds the device and provides authentication. The display shows a prompt requiring explicit user confirmation before the island becomes accessible. This dynamic state changes from inactive to active only at the moment of authorized use, balancing accessibility with security.
Data Source
AI summary
Devices, systems, and methods for storing and managing sensitive information in a connected environment are provided. The system comprises a master controller and a sensitive information storage device (“SIS device”). The SIS device has an island that can be activated by user interaction with the SIS device. In general, the island is deactivated by default and when the island is deactivated, sensitive information that is stored on the SIS device cannot be accessed. Only when the island is activated by user interaction can the stored sensitive information be accessed.


