Virtual Keyboard Feedback for Compliant Password Creation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password composition policies (PCP) are complex and difficult for users to comply with, leading to poor password hygiene due to user frustration and the adoption of insecure practices, especially for users with disabilities or limited literacy, and existing feedback methods are not accessible or user-friendly across various devices.
Innovation Solution
A policy-enabled-virtual keyboard (PKBD) provides in-place feedback through visual, audio, and haptic cues to guide users in creating compliant passwords, embedding password composition policies to highlight accessible keys and disable inaccessible ones, ensuring compliance with PCP rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strict and complex password composition policy is enforced, then password security is improved, but user usability and compliance deteriorate
Solution Approach 1:
The system provides real-time feedback during password creation by highlighting accessible keys (in green) and inaccessible keys (in red) on a virtual keyboard. This continuous feedback loop guides users to create compliant passwords without requiring them to read or understand complex policy documentation, thereby maintaining security requirements while significantly improving usability.
Solution Approach 2:
A policy-enabled virtual keyboard acts as an intermediary between the password composition policy and the user. The keyboard translates complex policy rules into visual cues that users can intuitively understand and follow, serving as a mediator that bridges the gap between security requirements and user capabilities.
2Reliability
If complex password composition policy is enforced, then password strength is improved, but user comprehension and adherence deteriorate
Solution Approach 1:
The virtual keyboard uses color coding to represent policy compliance status: green highlights indicate keys that can be pressed to meet policy requirements, while red highlights indicate keys that would result in non-compliant passwords. This visual encoding transforms complex policy rules into simple, universally understandable color signals.
Solution Approach 2:
The system continuously provides feedback about password compliance status through the colored key highlights, allowing users to understand exactly which policy requirements are met and which need to be addressed, thereby simplifying their interaction with complex policies.
3Loss of information
If text-based feedback is provided for password compliance, then information is conveyed, but accessibility for users with disabilities deteriorates
Solution Approach 1:
The system replaces text-based feedback with a visual interface on a virtual keyboard that uses color-coded highlights and spatial positioning. This substitution makes compliance information accessible to users with literacy challenges, language barriers, or visual preferences, as the feedback is conveyed through universal visual cues rather than text.
Data Source
AI summary
There is a need for design and implementation of interfaces for providing user-friendly feedback while creating and updating compliant passwords. This disclosure relates to a method of creating compliant password by in-place feedback to a password composition policy (PCP). A policy-enabled-virtual keyboard (PKBD) receives input from a user and is processed based on parameters associated with the PCP to identify accessible and inaccessible keys on the PKBD with in-place feedback. The in-place feedback is provided to highlight accessible keys of the PKBD for the user, if class associated with character, or mandated number of characters by the PCP are received are covered. Alternatively, the keys of the PKBD are disabled for access to the user by validating if class associated with character received are not covered, and a deviation of the parameters. A compliant password is created based on the PCP by providing in-place feedback for a resultant validation.


