Generating an evaluation mask for multi-factor authentication
By generating modified media files using Generative Adversarial Networks (GANs) and leveraging users' prior knowledge of the original images for multi-factor authentication, this approach addresses the security and privacy risks associated with relying on personal data in existing technologies, thus achieving a more secure user authentication method.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INTERNATIONAL BUSINESS MACHINE CORPORATION
- Filing Date
- 2021-11-11
- Publication Date
- 2026-08-04
AI Technical Summary
Existing multi-factor authentication technologies rely on users providing personal data, which poses security and privacy risks, and lacks verification methods based on users' prior knowledge.
A modified media file is generated using a Generative Adversarial Network (GAN). By comparing the original and modified images to identify differences, multi-factor authentication is performed using the user's prior knowledge of the media file. An evaluation mask is generated and verified through the user's response.
It improves online account security, reduces reliance on personal data, enhances the security and privacy protection of user authentication, and provides new forms of multi-factor authentication.
Smart Images

Figure CN116601661B_ABST
Abstract
Description
Background Technology
[0001] This invention relates generally to the field of multi-factor authentication, and more specifically to creating media files as a means of multi-factor authentication.
[0002] Generative adversarial networks (GANs) are machine learning (ML) models in which two neural networks compete against each other to become more accurate in their predictions. GANs typically operate unsupervised and use a cooperative zero-sum game framework for learning. The two neural networks that make up a GAN are called a generator and a discriminator. The generator is a convolutional neural network, and the discriminator is a deconvolutional neural network. The generator's goal is to artificially generate outputs that might be easily mistaken for real data. The discriminator's goal is to identify which outputs it receives have been artificially generated. Essentially, a GAN creates its own training data. As the feedback loop between the adversarial networks continues, the generator will begin to produce higher-quality outputs, and the discriminator will improve when labeling data that has been artificially generated.
[0003] The first step in building a GAN is to identify the desired final output and collect an initial training dataset based on these parameters. This data is then randomized and fed as input to the generator until it achieves basic accuracy in producing output. The generated images are then fed into a discriminator along with real data points from the original concept. The discriminator filters this information and returns a probability between 0 and 1 to represent the realism of each image (1 for real and 0 for fake). These values are then manually checked for success and repeated until the desired result is achieved. The core idea of GANs is based on “indirect” training via a discriminator, which itself is also dynamically updated. Essentially, this means that instead of being trained to minimize the distance to a particular image, the generator is tricked by the discriminator. This allows the model to learn in an unsupervised manner. GANs are becoming a popular ML model for online retail sales due to their ability to understand and accurately recreate visual content. Summary of the Invention
[0004] Embodiments of the present invention disclose a method, computer program product, and system for performing multi-factor authentication. The computer-implemented method includes: generating an evaluation mask for one or more modified items on a modified image, wherein the modified image is created by a generative adversary network (GAN); creating a scoring grid by comparing an original image with the modified image to identify different pixels between the original image and the modified image; overlaying the evaluation mask onto the identified different pixels on the modified image; displaying the modified image as a multi-factor authentication prompt to a user, wherein the user is prompted to provide a response identifying one or more modifications in the modified image; calculating an evaluation score based on a comparison of the user's response with the evaluation mask to verify the user's response; and authenticating the user and granting the user access to data or other resources in response to the evaluation score meeting or exceeding a predetermined threshold. Attached Figure Description
[0005] Figure 1 This is a functional block diagram illustrating a distributed data processing environment according to an embodiment of the present invention;
[0006] Figure 2 An embodiment of the invention is shown in Figure 1 The operational steps of the authentication mechanism 122 used for multi-factor authentication on a server computer within a distributed data processing environment; and
[0007] Figure 3 The invention describes an embodiment of the invention in Figure 1 A block diagram of the components of a server computer that performs authentication mechanisms within a distributed data processing environment. Detailed Implementation
[0008] Embodiments of the present invention improve online account security by performing second-factor authentication. More specifically, embodiments of the present invention improve upon existing techniques by generating an evaluation mask (i.e., a mask) on modified items in media files created by a GAN to serve as a multi-factor authentication. Embodiments of the present invention can be based on media files known to the user (e.g., personal media files) and can test the user's prior knowledge about the original media files. Personal media files can be family photos, images of the user's first car or residence, and / or any personalized images or videos known in the art. Embodiments of the present invention improve upon current techniques for user authentication by not requiring personal data from the user (such as date of birth, age, or residential address); instead, they use knowledge about the media files as a metric to authenticate the user. Embodiments of the present invention compare the original media file with the modified media file to identify differences based on pixel changes. By comparing differences between pixels, embodiments of the present invention are able to identify such differences as "target regions" to overlay a mask and use as verification points on the media file. Embodiments of the present invention generate an evaluation mask on modified items in media files created by a GAN as a means of multi-factor authentication. Embodiments of the present invention improve the technology by using GANs to create authentication puzzles as a new form of multi-factor authentication that can be applied to digital experiences and across screen-based devices (e.g., computing devices).
[0009] Embodiments of the present invention create a scoring grid by comparing the original image with a GAN-modified version of the image (i.e., the modified image) to identify distinct pixels between the original and modified images and overlay masks on the identified distinct regions. Embodiments of the present invention label the identified distinct regions as "distinct regions." When presenting the modified image to a user, embodiments of the present invention receive the user's response via touch, drawing, or clicking through a user interface, wherein the received user response (i.e., the input information) is compared with a mask (pixel region to pixel region) to calculate / verify the user's input. Embodiments of the present invention verify the user's prior knowledge of the original media file by comparing the original media file with the identified distinct regions in the user's response regarding the modified media file, wherein the user's response is verified if it is within a predetermined acceptable limit. For example, if the user's response selects / identifies 98% of the distinct regions in the modified image, embodiments of the present invention will verify the user.
[0010] The embodiments of the present invention can be implemented in various forms, and reference is subsequently made to the accompanying drawings (i.e., Figures 1-3 The details of the exemplary implementation will be discussed.
[0011] Figure 1This is a functional block diagram illustrating a distributed data processing environment, generally represented as 100, according to an embodiment of the present invention. As used herein, the term "distributed" describes a computer system comprising multiple physically distinct devices that operate together as a single computer system. Figure 1 This is merely an illustration of one implementation and does not imply any limitation regarding the environments in which different embodiments may be implemented. Many modifications to the described environment can be made by those skilled in the art without departing from the scope of the invention as set forth in the claims. The distributed data processing environment 100 includes computing devices 110 and server computers 120 interconnected via a network 130.
[0012] Network 130 may be, for example, a Storage Area Network (SAN), a telecommunications network, a Local Area Network (LAN), a Wide Area Network (WAN) (such as the Internet), a wireless technology for exchanging data over short distances (using short-wavelength ultra-high frequency (UHF) radio waves in the Industrial, Scientific, and Medical (ISM) band from fixed and mobile devices from 2.4 GHz to 2.485 GHz, and establishing a Personal Area Network (PAN) or a combination of all three), and may include wired, wireless, or fiber optic connections. Network 130 may include one or more wired and / or wireless networks that can receive and transmit data, voice, and / or video signals, including multimedia signals comprising voice, data, text, and / or video data. Generally, network 130 may be any combination of connections and protocols that will support computing devices 110 and server computers 120 within the distributed data processing environment 100, as well as any other computing devices and / or storage devices. Figure 1 Communication between (not shown in the image).
[0013] In some embodiments of the present invention, computing device 110 may be, but is not limited to, a standalone device, client, server, laptop computer, tablet computer, netbook computer, personal computer (PC), smartphone, desktop computer, smart TV, smartwatch, radio, stereo system, cloud-based service (e.g., cognitive cloud-based service), AR glasses, virtual reality headset, any HUD known in the art, and / or any programmable electronic computing device capable of communicating with various components and devices within the distributed data processing environment 100 via network 130 or any combination thereof. Generally, computing device 110 may represent any programmable computing device or combination of programmable computing devices capable of executing machine-readable program instructions and communicating with users of other computing devices via network 130 and / or capable of executing machine-readable program instructions and communicating with server computer 120. In some embodiments, computing device 110 may represent multiple computing devices.
[0014] In some embodiments of the invention, computing device 110 may refer to any programmable electronic computing device or a combination of programmable electronic computing devices capable of executing machine-readable program instructions, manipulating executable machine-readable instructions, and communicating via a network (such as network 130) with server computer 120 and other computing devices (not shown) within a distributed data processing environment 100. Computing device 110 may include instances of a user interface (interface) 106 and local storage device 104. Figure 1 In various embodiments not depicted herein, computing device 110 may have multiple interfaces 106. Figure 1 In other embodiments not depicted herein, the distributed data processing environment 100 may include multiple computing devices, multiple server computers, and / or multiple networks. The computing devices 110 may include internal and external hardware components, such as those described above. Figure 3 As described and further detailed.
[0015] User interface (interface) 106 provides an interface to the automatic feedback and authentication mechanism 122. The computing device 110, via user interface 106, enables users and / or clients to interact with the authentication mechanism 122 and / or server computer 120 in various ways, such as sending program instructions, receiving program instructions, sending and / or receiving messages, updating data, sending data, inputting data, editing data, collecting data, and / or receiving data. In one embodiment, interface 106 may be a graphical user interface (GUI) or a web user interface (WUI) and may display at least text, documents, web browser windows, user options, application interfaces, and operation instructions. Interface 106 may include data presented to the user (such as graphics, text, and sound) and control sequences used by the user to control operations. In another embodiment, interface 106 may be mobile application software that provides an interface between the user of computing device 110 and server computer 120. Mobile application software or "app" may be designed to run on smartphones, tablets, and other computing devices. In an embodiment, interface 106 enables a user of computing device 110 to at least send data, input data, edit data (annotate), collect data, and / or receive data.
[0016] Server computer 120 may be a standalone computing device, management server, web server, mobile computing device, one or more client servers, or any other electronic device or computing system capable of receiving, sending, and processing data. In other embodiments, server computer 120 may represent a server computing system utilizing multiple computers, such as, but not limited to, server systems in a cloud computing environment. In another embodiment, server computer 120 may represent a computing system utilizing a cluster of computers and components (e.g., database server computers, application server computers, etc.) that act as a single, seamless resource pool when accessed within the distributed data processing environment 100. Server computer 120 may include internal and external hardware components, such as those described above. Figure 3 As depicted and further described in detail. In some embodiments, server computer 120 may represent multiple server computers.
[0017] Each of the shared storage device 124 and the local storage device 104 can be a data / knowledge repository and / or database that can be written to and / or read from one or a combination of the authentication mechanism 122, the server computer 120, and the computing device 110. In the depicted embodiment, the shared storage device 124 resides on the server computer 120, and the local storage device 104 resides on the computing device 110. In another embodiment, the shared storage device 124 and / or the local storage device 104 can reside elsewhere within the distributed data processing environment 100, provided that each is accessible and can be accessed by the computing device 110 and the server computer 120. The shared storage device 124 and / or the local storage device 104 can each be implemented using any type of storage device capable of storing data and configuration files that can be accessed and utilized by the server computer 120, such as, but not limited to, a database server, a hard disk drive, or flash memory.
[0018] In the depicted embodiment, authentication mechanism 122 is executed on server computer 120. In other embodiments, authentication mechanism 122 may be executed on computing device 110. Figure 1 In various embodiments of the invention not depicted herein, the authentication mechanism 122 may be executed on multiple server computers 120 and / or multiple computing devices 110. In some embodiments, the authentication mechanism 122 may be located anywhere within the distributed data processing environment 100 and / or executed anywhere within the distributed data processing environment 100, provided that the authentication mechanism 122 is connected to and / or communicates with the computing devices 110 and / or server computers 120 via network 130.
[0019] In various embodiments of the invention, authentication mechanism 122 is a multi-factor authentication mechanism. Authentication mechanism 122 may include and implement a GAN model. In the depicted embodiments, authentication mechanism 122 includes an ingestion component 125, a secure image evaluation mask module (evaluation module) 126, and a rendering component 128. In other embodiments, the ingestion component 125, the evaluation module 126, and / or the rendering component 128 may each be executed on computing device 110. Figure 1 In various embodiments of the invention not depicted herein, the ingestion component 125, the evaluation module 126, and / or the presentation component 128 may each execute on a plurality of server computers 120 and / or on a plurality of computing devices 110. In some embodiments, the ingestion component 125, the evaluation module 126, and / or the presentation component 128 may each be located anywhere within the distributed data processing environment 100 and / or execute anywhere within the distributed data processing environment 100, provided that the ingestion component 125, the evaluation module 126, and / or the presentation component 128 are connected to, and / or communicate with, the authentication mechanism 122, the computing device 110, and / or the server computer 120 via the network 130.
[0020] Authentication mechanism 122 may receive uploaded media files (e.g., digital photos (i.e., pictures) / images) and metadata from a user or database (i.e., local storage device 104 and / or shared storage device 124) via ingestion component 125. In some embodiments of the invention, the received media files (e.g., user photos) may be photos of the user personally and / or photos associated with the user. Media files and metadata may be obtained from one or more social media sites and / or open-source websites on the Internet, wherein authentication mechanism 122 may use the obtained media files to generate modified media files via a GAN model. In other embodiments, the authentication component may use other available images at predetermined locations via a GAN model to generate modified media files. Metadata may include: the location of the photo, the name of the location, the time of year, the timestamp of the photo, the file size, the number of pixels, and / or any descriptive, structural, and administrative metadata known in the art. Media files may be photos, videos, and / or any other type of media files known in the art. In various embodiments of the invention, the received and / or retrieved metadata is associated with a specific media file. In some embodiments of the invention, authentication mechanism 122 is linked to or synchronized to one or more of the user’s social media profiles.
[0021] Authentication mechanism 122 may have user-enabled access to search data or other resources, in one example, photos and metadata from one or more linked user social media profiles. For example, authentication mechanism 122 retrieves a user's current social media profile image and creates a modified image to present to the user for authentication, wherein the user is prompted to identify / select differences in the modified image. In various embodiments of the invention, authentication mechanism 122 performs an internet search via one or more search engines to locate media files (e.g., photos) and metadata. In various embodiments of the invention, authentication 122 receives media files directly from the user.
[0022] The authentication mechanism 122, via the evaluation module 126, can generate altered / modified media files based on the original or uploaded image / photo. In various embodiments of the invention, the evaluation module 126 performs two steps: (i) altering the original image (e.g., the uploaded user media file) using a GAN model, and (ii) creating and placing a mask on the modified media file to evaluate the user's response, wherein the mask retains information about where changes were made to the original media file, and wherein the mask is not visible to the user being authenticated. In various embodiments of the invention, the authentication mechanism 122, via the evaluation module 126, alters the people, fashion, age, color, and pixels in the user-uploaded image, generates a modified second image based on the uploaded image, compares the two images, and creates and places a mask on the modified areas in the modified second image that were modified from the uploaded image.
[0023] For example, a user uploads a photo of a local park, which includes pedestrians walking dogs, trees, pedestrians rollerblading, birds flying in the air, and a pond. In this example, authentication mechanism 122 generates a modified image of the uploaded park photo via ingestion component 125 and a GAN model. The modified image removes the walking dog, adds birds to the trees, changes the leaf color from green to yellow, adds ducks to the pond, changes the vest color of one of the pedestrians, and removes the birds flying in the air, pixelating the area where the birds were removed. In this example, authentication mechanism 122 generates and places a mask on the modified image via evaluation module 126 to evaluate the user's response. In this example, the modified image is presented to the user, who is asked to identify the changes in the modified image relative to the uploaded park photo. When the user selects a portion of the modified image, the mask registers the user's response via evaluation module 126, and a score is calculated using the received user response.
[0024] In various embodiments of the invention, the mask is invisible to the user and serves as an interactive component that the user can click on via interface 106. Through this interaction, evaluation module 126 can determine whether the user has accurately selected one or more modifications to the original image to prove / verify that the user possesses prior knowledge about the image. In various embodiments of the invention, authentication mechanism 122 prompts the user to select / identify a predetermined number of changes in the modified media file. For example, prompting the user to select at least three changes in the image.
[0025] In various embodiments of the invention, presentation component 128 displays a modified image and one or more open-ended questions via interface 106. For example, presentation component 128 presents a modified image and a single open-ended question, such as “Identify the difference” or “Select the change in the image,” to a user via interface 106. In this example, presentation component 128 prompts the user to click “OK” to continue. The difference in the modified image can be one or more differences from the original image. Presentation component 128 may record the user’s interaction with the displayed one or more open-ended questions and send it back to a predetermined instance or evaluation module 126, where evaluation module 126 performs step two (i.e., secure image evaluation). Evaluation module 126 can then compare the user’s response with an evaluation mask to calculate an evaluation score. In various embodiments of the invention, in some cases, multiple media files (original and / or manipulated) may be required to more accurately evaluate the user’s response.
[0026] The presentation component 128 can evaluate how accurately a user responds to a challenge (i.e., the prompted question), where the accuracy / correctness of the user's response is based on a predetermined threshold. In various embodiments of the invention, the predetermined threshold can be defined by the user through user settings during setup or at any time the user desires. When evaluating the accuracy of the user's response, the presentation component 128 can take into account the order of the selected objects and the amount of time spent providing the response.
[0027] In various embodiments of the invention, authentication mechanism 122 broadcasts a predetermined identification threshold back to a website or mobile application in binary format. Based on a calculated score of one or more of the user's responses, the user's status is determined as either authenticated or unauthenticated, wherein the user's status is sent to the website or mobile application with which the user interacts, and the website processes the binary result to grant or deny access.
[0028] In various embodiments of the invention, authentication mechanism 122 compares an image with identified differences to create a puzzle and prevent fraud, wherein the puzzle may be a modified media file used to authenticate the user. In various embodiments of the invention, authentication mechanism 122 adjusts the media file according to user-defined preferences and accessibility settings. For example, image colors may be changed for users experiencing color vision deficiencies. The presentation of the image may be timed so that the time allocated to the user to identify differences in the modified data file can be adjusted by increasing or decreasing the allocated time. In some embodiments, the time allocated to the user to identify differences in the manipulated media file is predetermined.
[0029] In various embodiments of the invention, authentication mechanism 122 is transmitted via camera component ( Figure 1 (Not depicted in the text) Eye tracking is performed to identify what the user is looking at, so as to associate the user's visual patterns with the user's selections. Authentication mechanism 122 identifies and analyzes the items / areas of the media file that the user spends time viewing and the items / areas selected by the user to determine a score.
[0030] Figure 2 An embodiment of the invention is shown with Figure 1 The operation steps of the authentication mechanism 122 (usually denoted as 200) for multi-factor authentication, which communicates with the computing device 110 within the distributed data processing environment 100. Figure 2 An illustration of an implementation is provided, and no limitation is implied regarding the environments in which different embodiments may be implemented. Many modifications can be made to the described environment by those skilled in the art without departing from the scope of the invention as set forth in the claims.
[0031] In step 202, authentication mechanism 122 receives media files from the user. In various embodiments of the invention, authentication mechanism 122 receives one or more media files from the user, or retrieves one or more media files from local storage device 104 and / or shared storage device 124. For example, a new user registering an account on a social media site is required to upload a secure image, including metadata such as time of year, location, city, and country (e.g., Flinders Street station, summer). In this example, the user uploads an image of a custom birthday cake recently received by the user. In various embodiments of the invention, authentication mechanism 122 issues a display prompt instructing the user to submit new / fresh media after a predetermined amount of time (e.g., week, month, etc.).
[0032] In step 204, authentication mechanism 122 generates a GAN-modified media file. In various embodiments of the invention, authentication mechanism 122 generates one or more GAN-modified media files based on one or more received user media files. Continuing the example above, the user's account is under security threat (e.g., an attempted hacking attack). In this example, authentication mechanism 122 is alerted to the security threat and is triggered to perform multi-factor authentication. In this example, authentication mechanism 122 retrieves the user's initially uploaded image (e.g., a customized birthday cake) and metadata from local storage device 104 and / or shared storage device 124, and identifies similar images from the same location, different angles, objects, people, and lighting from the Internet. In various embodiments of the invention, authentication mechanism 122 uses a GAN-based image alteration model to edit the original image, wherein the editing includes, but is not limited to: changing objects, people, colors, brightness, people's age, walls, clothing, and fashion in the original image. For example, change the color of the frosting, change the name on the cake, change the books on the shelf in the background to plants, reduce the number of candles, add a photo to the wall behind the cake, and change the brightness of the candles and the room.
[0033] In step 206, authentication mechanism 122 generates an evaluation mask. In various embodiments of the invention, authentication mechanism 122 performs a pixel-to-pixel comparison between the original media file and a GAN-modified media file (e.g., a modified media file). Based on the pixel comparison, authentication mechanism 122 can identify regions that differ between the original and modified media files and label the identified regions as "differences." Based on the identified "differences," authentication mechanism 122 can overlay one or more masks, where the one or more masks are evaluation points. In various embodiments of the invention, authentication mechanism 122 creates one or more scoring grids by comparing the original image with the GAN-modified version of the image to identify different pixels between the original and modified images and overlays masks on the identified "differences."
[0034] In step 208, authentication mechanism 122 displays the modified media file to the user. In various embodiments of the invention, authentication mechanism 122 displays one or more modified media files with an overlaid mask to the user via interface 106. Continuing with the above example, authentication mechanism 122 would display a modified image with an overlaid evaluation mask (i.e., a mask) to a hacker.
[0035] In step 210, authentication mechanism 122 issues a response display prompt to the user. In various embodiments of the invention, authentication mechanism 122 issues one or more response display prompts to the user, wherein the response display prompts are displayed to the user via interface 106. Continuing the above example, when a modified image with an overlaid mask is displayed to a hacker (i.e., the user), authentication mechanism 122 issues a response prompt instructing the hacker to identify items in the image by tapping, drawing, and / or clicking on items that have been altered, depending on the type of computing device the hacker is using. In various embodiments of the invention, authentication mechanism 122 utilizes HoloGAN (i.e., GAN) to achieve a 2D to 3D conversion from an image by adding depth to the original media file, and allows the user to rotate the media file (e.g., the modified image) to select items that have been placed (e.g., items behind other objects). Based on the response prompt, user selection (i.e., selection) can also be performed by first selecting a depth plane and tapping a predetermined object in the selected plane of the media file.
[0036] In step 212, authentication mechanism 122 compares the received user response information (i.e., user selection) with an evaluation mask. In various embodiments of the invention, authentication mechanism 122 compares the user's selection with the evaluation mask to calculate an evaluation score. For example, continuing the example above, when authentication mechanism 122 receives a hacker's selection, it compares the received selection with a generated mask to determine whether the hacker has identified the correct region on the modified image. In various embodiments of the invention, in some cases, multiple media files (original and / or manipulated) may be required for more accurate user evaluation.
[0037] In step 214, authentication mechanism 122 calculates an evaluation score based on the user's response. In various embodiments of the invention, authentication mechanism 122 calculates the evaluation score based on a comparison of the received user response and an evaluation mask. In some embodiments of the invention, authentication mechanism 122 calculates the evaluation score based on a comparison of the user's response and an evaluation mask to verify the user's response. In various embodiments of the invention, authentication mechanism 122 calculates a score based on multiple attempts to determine successful identification, wherein the multiple attempts include multiple media files, wherein the multiple media files are different media files and / or the same media file with different modifications. In various embodiments of the invention, authentication mechanism 122 calculates an evaluation score based on multiple response attempts from the user to verify the user's identification, wherein the multiple response attempts are based on multiple security prompts, each security prompt using a different modified image selected from multiple modified images.
[0038] In step 216, authentication mechanism 122 determines whether the user is authenticated. In various embodiments of the invention, authentication mechanism 122 determines whether the user is authenticated based on a calculated evaluation score. In various embodiments of the invention, authentication mechanism 122 broadcasts a binary authentication or unauthentication determination to the platform to allow or deny the user access to data or other resources. If the user score is within or above a predetermined threshold (“Yes” step), authentication mechanism 122 verifies and authenticates the user and proceeds to step 220. If the user score is below the predetermined threshold (“No” step), authentication mechanism 122 may not verify the user and proceed to step 218.
[0039] In step 218, authentication mechanism 122 prompts the user to retry authentication. In various embodiments of the invention, authentication mechanism 122 denies the user access to data or other resources and prompts the user to retry authentication, wherein the prompt is a response prompt displayed via interface 106. In the depicted embodiments, authentication mechanism 122 may repeat steps 204 to 218 until the user is authenticated or a predetermined number of attempts is reached, and the account is locked.
[0040] In step 220, authentication mechanism 122 grants user access. In various embodiments of the invention, authentication mechanism 122 grants user access to data or other resources based on an evaluation score and authentication, wherein the evaluation score meets or exceeds a predetermined threshold. In various embodiments of the invention, authentication mechanism 122 issues a survey prompt that assesses the difficulty and accuracy of the modified media file and authentication processing.
[0041] Figure 3 An embodiment of the invention is depicted. Figure 1 A block diagram of the components of server computer 120 within a distributed data processing environment 100. It should be understood that... Figure 3 This illustration provides only one possible implementation and does not imply any limitations regarding the environments in which different embodiments may be implemented. Many modifications can be made to the depicted environment.
[0042] Figure 3A computer system 300 is depicted, wherein server computing 120 represents an example of a computer system 300 including an authentication mechanism 122. The computer system includes a processor 301, a cache 303, memory 302, persistent storage 305, a communication unit 307, an input / output (I / O) interface 306, a display 309, external devices 308, and a communication structure 304. The communication structure 304 provides communication between the cache 303, memory 302, persistent storage 305, communication unit 307, and input / output (I / O) interface 306. The communication structure 304 can be implemented using any architecture designed for transferring data and / or control information between processors (such as microprocessors, communication and network processors, etc.), system memory, peripheral devices, and any other hardware components within the system. For example, the communication structure 304 can be implemented using one or more buses or crossbar switches.
[0043] Memory 302 and persistent storage device 305 are computer-readable storage media. In this embodiment, memory 302 includes random access memory (RAM). Typically, memory 302 may include any suitable volatile or non-volatile computer-readable storage medium. Cache 303 is a fast memory that enhances the performance of processor 301 by storing recently accessed data from memory 302 and data near the recently accessed data.
[0044] Program instructions and data for implementing embodiments of the present invention may be stored in persistent storage device 305 and memory 302 for execution by one or more of the respective processors 301 via cache 303. In an embodiment, persistent storage device 305 includes a magnetic hard disk drive. Alternatively, or attached to a magnetic hard disk drive, persistent storage device 305 may include a solid-state hard disk drive, a semiconductor storage device, a read-only memory (ROM), an erasable programmable read-only memory (EPROM), flash memory, or any other computer-readable storage medium capable of storing program instructions or digital information.
[0045] The media used by the persistent storage device 305 can also be removable. For example, a removable hard disk drive can be used for the persistent storage device 305. Other examples include optical discs and disks, thumb drives and smart cards, which are inserted into the drive to transfer to another computer-readable storage medium that is also part of the persistent storage device 305.
[0046] In these examples, communication unit 307 provides communication with other data processing systems or devices. In these examples, communication unit 307 includes one or more network interface cards. Communication unit 307 can provide communication by using either or both physical and wireless communication links. Program instructions and data for implementing embodiments of the invention can be downloaded to permanent storage device 305 via communication unit 307.
[0047] I / O interface 306 enables data input and output with other devices that can be connected to each computer system. For example, I / O interface 306 can provide connectivity to external device 308 (such as a keyboard, keypad, touchscreen, and / or other suitable input devices). External device 308 may also include portable computer-readable storage media, such as thumb drives, portable optical discs or disks, and memory cards. Software and data used to implement embodiments of the invention can be stored on such portable computer-readable storage media and can be loaded onto permanent storage device 305 via I / O interface 306. I / O interface 306 is also connected to display 309.
[0048] The display 309 provides a mechanism for displaying data to the user and may be, for example, a computer monitor.
[0049] The programs described herein are identified based on applications that implement them in specific embodiments of the invention. However, it should be understood that any particular procedural terminology used herein is for convenience only, and therefore the invention should not be limited to use only in any particular application identified and / or implied by such terminology.
[0050] The present invention can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to execute aspects of the present invention.
[0051] Computer-readable storage media can be any tangible device capable of retaining and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory sticks, floppy disks, mechanical encoding devices on which instructions are recorded (such as punched cards or raised structures in recesses), and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses transmitted through fiber optic cables), or electrical signals transmitted through wires.
[0052] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device, or downloaded via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network) to an external computer or external storage device. The network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the suitable computing / processing device.
[0053] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages (such as Smalltalk, C++, etc.) and conventional procedural programming languages (such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as a standalone software package, partially on a user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)) or may be connected to an external computer (e.g., via the Internet provided by an Internet service provider). In some embodiments, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions by personalizing the electronic circuits with state information utilizing the computer-readable program instructions in order to perform aspects of this invention.
[0054] This document describes aspects of the invention with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0055] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other devices to operate in a particular manner, such that the computer-readable storage medium storing the instructions includes an article of writing comprising instructions for implementing aspects of the functions / actions specified in one or more blocks of a flowchart and / or block diagram.
[0056] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus, or other device, perform the functions / actions specified in one or more boxes in a flowchart and / or block diagram.
[0057] The flowcharts and block diagrams in the accompanying drawings (i.e., the figures) illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than indicated in the figures. For example, depending on the function involved, two consecutively shown blocks may actually be executed substantially simultaneously, or these blocks may sometimes be executed in reverse order. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified function or action or performs a combination of dedicated hardware and computer instructions.
[0058] Various embodiments of the invention have been described for illustrative purposes, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the invention. The terminology used herein has been chosen to best explain the principles of the embodiments, their practical application, or technical improvements to techniques found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A computer-implemented method for performing multi-factor authentication, the computer-implemented method comprising: An evaluation mask is generated for one or more modified regions on a modified image, wherein the modified image is created by a generative adversary network (GAN). A scoring grid is created by comparing the original image with the modified image to identify the different pixels between the original image and the modified image; The evaluation mask is placed on the identified distinct pixels in the modified image; The modified image is displayed to the user as a multi-factor authentication prompt, wherein the user is prompted to provide a response that identifies one or more modifications in the modified image; An evaluation score is calculated based on a comparison between the user's response and the evaluation mask to verify the user's response; and In response to the evaluation score meeting or exceeding a predetermined threshold, the user is authenticated and granted access to data or other resources.
2. The computer-implemented method of claim 1, wherein, The comparison between the response from the user and the evaluation mask includes: Regarding the response from the user, the pixels in the original image are compared with the pixels in the modified image.
3. The computer-implemented method according to claim 1, further comprising: The modified image is generated from the original image by the GAN, wherein generating the modified image includes: Editing the original image, wherein editing includes at least one of the following: changing objects, people, colors, brightness, people's age, walls, or clothes in the original image.
4. The computer-implemented method of claim 1, wherein, Displaying the modified image as a multi-factor authentication prompt to the user further includes: A response prompt is issued, instructing the user to identify the one or more modified regions in the modified image by tapping, drawing, or clicking on them.
5. The computer-implemented method according to claim 1, further comprising: The evaluation score is calculated based on multiple response attempts from the user to verify the user's identification, wherein the multiple response attempts are based on multiple security prompts, each security prompt using a different modified image selected from multiple modified images.
6. The computer-implemented method of claim 1, wherein, Calculating assessment scores based on comparison further includes: Regarding one or more modifications to the original image, the response from the user is compared with the evaluation mask.
7. The computer-implemented method according to claim 1, further comprising: The user is determined to be authenticated based on a calculated evaluation score, wherein the evaluation score is within or above a predetermined threshold, and wherein a binary authentication determination is broadcast to the platform to grant the user access to the data or other resources.
8. A computer program product for performing multi-factor authentication, the computer program product comprising: One or more computer-readable storage devices and program instructions stored on the one or more computer-readable storage devices, the stored program instructions including: Program instructions for generating evaluation masks for one or more modified regions on a modified image, wherein the modified image is created by a generative adversary network (GAN); Program instructions for creating a scoring grid by comparing the original image with the modified image to identify the different pixels between the original image and the modified image; Program instructions for placing the evaluation mask on the identified different pixels in the modified image; The program instruction displays the modified image as a multi-factor authentication prompt to the user, wherein the user is prompted to provide a response that identifies one or more modifications in the modified image; The program instructions to verify the user's response are to calculate an evaluation score based on a comparison of the user's response with the evaluation mask; and A program instruction to authenticate the user and grant the user access to data or other resources in response to the evaluation score meeting or exceeding a predetermined threshold.
9. The computer program product of claim 8, wherein, The comparison between the response from the user and the evaluation mask includes: In response to the user's response, program instructions compare the pixels in the original image with the pixels in the modified image.
10. The computer program product according to claim 8, further comprising: The program instructions for generating the modified image from the original image by the GAN, wherein generating the modified image includes: The program instructions for editing the original image, wherein editing includes at least one of the following: changing objects, people, colors, brightness, people's age, walls, and clothes in the original image.
11. The computer program product of claim 8, wherein, Displaying the modified image as a multi-factor authentication prompt to the user further includes: A program instruction to issue a response prompt, the response prompt instructing the user to identify the one or more modified regions in the modified image by tapping, drawing or clicking on the one or more modified regions in the modified image.
12. The computer program product according to claim 8, further comprising: The program instructions for calculating the evaluation score to verify the user's identification are based on multiple response attempts from the user, wherein the multiple response attempts are based on multiple security prompts, each security prompt using a different modified image selected from multiple modified images.
13. The computer program product of claim 8, wherein, Calculating assessment scores based on comparison further includes: Program instructions to compare the user's response with the evaluation mask in relation to one or more modifications to the original image.
14. The computer program product according to claim 8, further comprising: The program instruction for authenticating the user is determined based on the calculated evaluation score, wherein the evaluation score is within or above a predetermined threshold, and wherein a binary authentication determination is broadcast to the platform to allow the user access to the data or other resources.
15. A computer system for performing multi-factor authentication, the computer system comprising: One or more computer processors; One or more computer-readable storage devices; Program instructions stored in the one or more computer-readable storage devices for execution by at least one of the one or more computer processors, the stored program instructions including: Program instructions for generating evaluation masks for one or more modified regions on a modified image, wherein the modified image is created by a generative adversary network (GAN); Program instructions for creating a scoring grid by comparing the original image with the modified image to identify the different pixels between the original image and the modified image; Program instructions for placing the evaluation mask on the identified different pixels in the modified image; The program instruction displays the modified image as a multi-factor authentication prompt to the user, wherein the user is prompted to provide a response that identifies one or more modifications in the modified image; The program instructions to verify the user's response are to calculate an evaluation score based on a comparison of the user's response with the evaluation mask; and A program instruction to authenticate the user and grant the user access to data or other resources in response to the evaluation score meeting or exceeding a predetermined threshold.
16. The computer system of claim 15, wherein, The comparison between the response from the user and the evaluation mask includes: In response to the user's response, program instructions compare the pixels in the original image with the pixels in the modified image.
17. The computer system of claim 15, further comprising: The program instructions for generating the modified image from the original image by the GAN, wherein generating the modified image includes: The program instructions for editing the original image, wherein editing includes at least one of the following: changing objects, people, colors, brightness, people's age, walls, and clothes in the original image.
18. The computer system of claim 15, wherein, Displaying the modified image as a multi-factor authentication prompt to the user further includes: A program instruction to issue a response prompt, the response prompt instructing the user to identify the one or more modified regions in the modified image by tapping, drawing or clicking on the one or more modified regions in the modified image.
19. The computer system of claim 15, further comprising: The program instructions for calculating the evaluation score to verify the user's identification are based on multiple response attempts from the user, wherein the multiple response attempts are based on multiple security prompts, each security prompt using a different modified image selected from multiple modified images.
20. The computer system of claim 15, further comprising: Program instructions to compare the response from the user with the evaluation mask in relation to one or more modifications to the original image; as well as The program instruction for authenticating the user is determined based on the calculated evaluation score, wherein the evaluation score is within or above a predetermined threshold, and wherein a binary authentication determination is broadcast to the platform to allow the user access to the data or other resources.