Content encryption and on-the-spot decryption using visually coded ciphertexts
Patent Information
- Application Number
- CN202480068927.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-09-18
- Filing Date
- 2024-07-26
- Publication Date
- 2026-08-18
AI Technical Summary
然而,目前的加密方法是“全或无”,要求整个文件要么加密,要么不加密
[0079] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation is a still image.
Smart Images

Figure CN122603331A_ABST
Abstract
Description
Cross-references to related applications
[0001] This application claims priority to U.S. Nonprovisional Application No. 18 / 369,214, filed September 18, 2023, pursuant to 35 USC119(e), the contents of which are incorporated herein by reference in their entirety. Technical Field
[0002] This invention relates to the encryption and decryption of content using visually encoded ciphertext, and more particularly to systems and methods for two-way, two-factor remote user authentication. Background Technology
[0003] Previous methods of remote user authentication typically relied on single-factor authentication methods, such as passwords or PINs, which are vulnerable to security breaches. These methods often lack the necessary security levels to protect sensitive information and are susceptible to unauthorized access. Furthermore, these methods do not provide a comprehensive solution for two-way authentication, in which the user and the computer system authenticate each other.
[0004] Some existing systems attempt to address the limitations of single-factor authentication by implementing two-factor authentication methods. In addition to a password or PIN, these methods typically use secondary authentication factors such as physical tokens or one-time passwords. While these methods provide an extra layer of security, they still do not fully meet the needs of two-way authentication and may require additional hardware or software components.
[0005] Other methods focus on remote user authentication via network-based terminals. These systems allow users to remotely access computer systems through network interfaces. However, these methods typically rely on traditional single-factor authentication methods (such as passwords) and do not provide a comprehensive solution for two-way authentication.
[0006] However, none of these methods provide a comprehensive solution combining the features described in this disclosure. The present invention aims to overcome the limitations of prior methods by providing a system for two-way, two-factor remote user authentication that utilizes one or more encrypted login identifiers and authentication images for secure authentication between a user and a computer system. For example, many network information systems assign login functionality, which can be used to establish a login to retrieve data from a service provider. Currently, the process of logging into many online systems (such as websites, some user interfaces of applications) and / or performing some critical actions typically requires a password from the user. The password is often referred to as the first authentication factor. However, in today's market, with the increase in cyberattacks, the scientific community has introduced many other authentication factors. Multi-factor authentication is an example of a security system that requires at least two different types of authentication to authorize a login request. Some identifying factors are considered to be what you know, what you possess, or characteristics you have.
[0007] What you know is your password. The characteristics you possess are your user biometrics (e.g., your fingerprint). What you own is what many call a second authentication factor (“2FA”), which can include coded text, coded email, coded phone number, or physical token. Any combination of these three can be used to log into a website or perform key actions (e.g., online money transfer). Specifically, 2FA is a method where a user needs to provide additional data to prove ownership of the second factor (what you own). For example, the second factor could be a hardware token or a mobile phone. In this case, the hardware token or mobile phone would display a unique digital code that the user needs to provide to the website to prove ownership of the hardware token or mobile phone (what you own).
[0008] In many typical 2FA solutions, users further authenticate themselves to the server by proving ownership of a second factor. However, the server does not authenticate the user. In other words, this second-factor authentication is one-way: the user further proves their identity to the server, but the server does not prove its identity to the user. This leads to numerous phishing attacks where unauthenticated servers request sensitive information (e.g., user passwords) from users. To address these issues, an additional authentication step can be implemented while avoiding complex user login processes. Therefore, an improved second-factor authentication is needed, where the authentication server verifies the server's identity to the user. As a result, security can be enhanced.
[0009] In many scenarios, only certain parts of a file contain sensitive information and require encryption (e.g., account balances on a bank statement, SSNs on a tax return). However, current encryption methods are "all or nothing," requiring the entire file to be either encrypted or not. Therefore, there is a need for a system and method that effectively enables users to selectively encrypt data fragments and visually embed these fragments into large amounts of data.
[0010] Examples of related technologies are described below:
[0011] U.S. Patent No. 9,183,677 generally describes a system that allows camera-enabled applications, such as augmented reality applications, to operate in a protected area. The system may include: a first device including a camera, the camera including a secure operating mode and a display; an image processing module configured to convert image data from the camera into encoded data when the camera is in secure mode, and to protect the image data stored in the system; an encryption module configured to encrypt the encoded data from the image processing module; and a protected audio / video path mechanism configured to securely transmit the enhanced encoded data to the display.
[0012] U.S. Patent No. 9,213,854 generally describes a head-mounted display (HMD) device and a method for accessing encrypted information through the device, wherein the head-mounted display device with enhanced security includes: a biometric information input unit for receiving biometric information of a user; a communication module for sending information to or receiving information from a server; a memory for storing encrypted information; a processor that sends the biometric information received through the biometric information input unit to a user authentication server via the communication module, receives access permission information from the user authentication server, and decrypts the encrypted information stored in the memory based on the received access permission information; and a display unit that displays the decrypted information via the processor.
[0013] U.S. Patent No. 9,251,366 generally describes a method, a non-transitory computer-readable medium, and an apparatus for decrypting files. For example, the method captures a tag on an encrypted file, sends the tag to an application server on a communication network to request a per-file decryption key, receives the per-file decryption key if the tag is authenticated, and decrypts a portion of the encrypted file using a temporary decryption key contained in the tag, the tag being decrypted with the per-file decryption key.
[0014] U.S. Patent No. 9,330,272 generally describes a head-mounted display (HMD) device and a method for accessing encrypted information through the device, wherein the head-mounted display with enhanced security includes: a biometric information input unit for receiving biometric information of a user; a communication module for sending information to or receiving information from a server; a memory for storing encrypted information; a processor that sends the biometric information received through the biometric information input unit to a user authentication server via the communication module, receives access permission information from the user authentication server, and decrypts the encrypted information stored in the memory based on the received access permission information; and a display unit that displays the decrypted information via the processor.
[0015] U.S. Patent No. 9,893,890 generally describes a method for decrypting encrypted messages. The method includes storing a wearer's decryption code in the memory of a wearable mobile device having a head-mounted augmented reality display that generates an augmented reality view for the wearer of the wearable mobile device; capturing a video sequence using the wearable mobile device, the video sequence including at least one frame of visible code imaged using the image sensor of the wearable mobile device; processing the video sequence to identify the visible code; decrypting the visible code using the wearer's decryption code to create decrypted content; and presenting the decrypted content in the augmented reality view on top of at least some of the visible code.
[0016] U.S. Patent No. 9,948,659 generally describes a system that allows camera-enabled applications, such as augmented reality applications, to operate in a protected area. The system may include: a first device including a camera with a secure operating mode and a display; an image processing module configured to convert image data from the camera into encoded data when the camera is in secure mode and to protect the image data stored in the system; an encryption module configured to encrypt the encoded data from the image processing module; and a protected audio / video path mechanism configured to securely transmit the enhanced encoded data to the display.
[0017] U.S. Patent Publication No. 2015 / 0295715 generally describes a method for decrypting encrypted messages. The method includes storing a wearer's decryption code in the memory of a wearable mobile device with a head-mounted augmented reality display (HUD) that generates an augmented reality view for the wearer of the wearable mobile device; capturing a video sequence using the wearable mobile device, the video sequence including at least one frame of visible code imaged using the image sensor of the wearable mobile device; processing the video sequence to identify the visible code; decrypting the visible code using the wearer's decryption code to create decrypted content; and presenting the decrypted content in the augmented reality view on top of at least some of the visible code.
[0018] U.S. Patent Publication No. 2018 / 0167215 generally describes a method for decrypting encrypted messages. The method includes storing a wearer's decryption code in the memory of a wearable mobile device with a head-mounted augmented reality display (HUD) generating an augmented reality view for the wearer of the wearable mobile device; capturing a video sequence using the wearable mobile device, the video sequence including at least one frame of visible code imaged using the image sensor of the wearable mobile device; processing the video sequence to identify the visible code; decrypting the visible code using the wearer's decryption code to create decrypted content; and presenting the decrypted content in the augmented reality view on top of at least some of the visible code.
[0019] International Patent Publication No. WO2014 / 005736A1 generally describes a method for providing private information to a user, comprising the following steps: a) encrypting one or more private messages containing private information of one or more users; b) encoding the encrypted one or more messages into a public content stream including public content for public presentation; c) simulating the presentation of the public content stream, wherein the encoded one or more messages are imperceptible to humans; d) capturing the presented public content stream by the user's user device; e) decoding one or more encrypted private messages for the user from the captured public content stream; f) decrypting the decoded one or more encrypted private messages; and g) providing the decrypted private information to the user. It also relates to a system for providing private information to a user.
[0020] None of the above-mentioned techniques have solved all the problems addressed by the present invention. Summary of the Invention
[0021] A system for two-way, two-factor remote user authentication includes a workflow engine comprising one or more processors and at least one memory element for storing instructions. The workflow engine generates and encrypts data, such as various website-specific data, including but not limited to one or more login identifiers. The system also includes a client device that communicates with the workflow engine via a network. The client device includes one or more processors, at least one memory element for storing instructions, a display, and a user login interface. The user login interface receives user identification data for logging into the computer system. The workflow engine generates and encrypts one or more login identifiers, visually encoding them as an authentication image displayed on the client device's display. Electronic devices also communicating with the workflow engine include a display with a graphical user interface, one or more processors, at least one memory element storing the login identifiers and user identification data, and an authentication identifier reader. The reader decrypts the login identifiers from the authentication image, and during decryption, the workflow engine verifies the decrypted login identifiers and user identification data to authenticate the user. The authenticated login identifier is displayed on the screen of the electronic device, and the user sends the authorization of the login request to the workflow engine to access the computer system. This also includes improvements to overcome the limitations of existing two-factor authentication systems and methods, which are now met by new, useful, and non-obvious inventions.
[0022] Images are displayed to the user via a web-based terminal's graphical user interface on the client device's display. The images are scanned by the user's electronic device. Image processing performed on the images by the workflow engine includes decryption and key management. Within the scope of this invention, after the image has been scanned by the user's electronic device, the workflow engine determines who has access to the image and how to assign a key to it. Specifically, Transport Layer Security (TLS) key exchange allows both parties to use encryption algorithms by exchanging encryption keys. In the example, a symmetric key is generated during the TLS handshake before sending the encrypted message. Public Key Infrastructure (PKI) is an example of exchanging symmetric keys. In a PKI system, the client generates a public-private key pair. The public key and / or data intended to be embedded in the certificate are sent to a Certificate Authority (CA). The CA then creates a digital certificate consisting of the user's public key and certificate attributes. The certificate is signed by the CA with its private key. Symmetric key encryption (also known as symmetric encryption) refers to encrypting plaintext and decrypting ciphertext using the same key. This method is the opposite of asymmetric encryption, in which one key is used for encryption and another for decryption. In this process, the data is converted into a format that cannot be read or inspected by anyone who does not have the encryption key used to encrypt the data. Both users, including those using network-based terminals and electronic devices, need access keys to maintain private data pairing.
[0023] According to another aspect of the present invention, a method for encrypting and decrypting data using visually encoded ciphertext is provided. The method includes selecting one or more portions of a file to be encrypted using a graphical user interface coupled to an electronic device; visually encoding the selected one or more portions of the file to generate a visual representation, wherein the visual representation corresponds to encrypted content; and replacing the selected one or more portions of the file with the visual representation. The method further includes displaying the visual representation to a user; capturing the visual representation using one or more cameras; decrypting the visual representation; obtaining the encrypted content; and decrypting the encrypted content to generate decrypted content.
[0024] In some aspects, the technology described herein relates to a method for securely sharing data using visually encoded ciphertext, the method comprising: inputting and submitting digital content by a first user (user 1); receiving, by user 1, encrypted visually encoded ciphertext (cyphlens1) containing the digital content; decrypting the cyphlens1 image to verify the encrypted digital content therein; approving, by user 1, the cyphlens1 image containing the verified encrypted digital content for further use; encrypting the approved digital content in a second visually encoded ciphertext (cyphlens2), wherein: the cyphlens2 image can only be decrypted by a designated second user (user 2); and the cyphlens2 image includes an identifier of user 1; and sending the cyphlens2 image to a user... User 2; User 2 receives the cyphlens2 image; User 2 decrypts the cyphlens2 image to verify the encrypted information therein; User 2 approves the cyphlens2 image containing the verified encrypted information for further use; encrypts the digital content approved by both User 1 and User 2 in a third visual coded ciphertext (cyphlens3), wherein: the cyphlens3 image can only be decrypted by User 1, User 2, and other designated users; the cyphlens3 image includes User 1's identifier; sends the cyphlens3 image to the designated users; the designated users receive the cyphlens3 image; one or more of the designated users decrypt the cyphlens3 image to obtain the encrypted information therein, respectively.
[0025] In some respects, the techniques described herein relate to a method in which at least one of User 1 and User 2 inputs and submits information to be encrypted via a web form, an application, or an API (Application Programming Interface).
[0026] In some respects, the techniques described herein relate to a method in which the cyphlens3 image also includes an identifier for user 2.
[0027] In some respects, the technology described herein relates to a method in which at least one of user 1 and user 2 approves cyphlens1 and cyphlens2 respectively by using at least one of actions on a touchscreen, actions using a real or virtual keyboard, and actions using a biometric reader.
[0028] In some respects, the techniques described herein relate to a method in which a mobile device with a camera is used to decrypt at least one of cyphlens1, cyphlens2, and cyphlens3.
[0029] In some respects, the techniques described herein relate to a method in which at least one of the cyphlens2 image and the cyphlens3 image is one of a modified cyphlens1 image and a first newly generated image, and a modified cyphlens2 image and a second newly generated image, respectively.
[0030] In some respects, the techniques described herein relate to a method in which at least one of the cyphlens2 and cyphlens3 images expires after a selected time or duration and a corresponding one of a predetermined default time or duration.
[0031] In some respects, the technology described herein relates to a method in which the identifier of at least one of User 1 and User 2 is a respective email address or telephone number.
[0032] In some respects, the techniques described herein relate to a method in which at least one of a Cyphlens2 image and a Cyphlens3 image is transmitted via at least one of email, text message, messaging application, website, printed paper, wired communication system and wireless communication system.
[0033] In some respects, the techniques described herein relate to a method in which at least one of user 1 and user 2 decrypts a cyphlens3 image.
[0034] In some respects, the techniques described herein relate to a method in which one of the recipients of a cyphlens3 image further processes at least one of the cyphlens3 image and information decrypted therefrom.
[0035] In some aspects, the technology described herein relates to a system for securely sharing data using visually encoded ciphertext, the system comprising a first graphical user interface, a first memory, and a first processor configured to: receive digital content submitted by a first user (user 1); generate encrypted visually encoded ciphertext (cyphlens1) containing the submitted digital content; return cyphlens1 to user 1; decrypt the cyphlens1 image in response to a request received from user 1 for user 1 to verify the encrypted digital content therein; receive the verified digital content; generate encrypted second visually encoded ciphertext (cyphlens2) containing the verified digital content, wherein: the cyphlens2 image can only be decrypted by a designated second user (user 2); and the cyphlens2 image includes an identifier of user 1; and send the cyphlens2 image to user 2.
[0036] In some aspects, the technology described herein relates to a system further comprising: a second electronic device including a second graphical user interface, a second memory, and a second processor, the second processor being configured to: receive a cyphlens2 image; decrypt the cyphlens2 image in response to a request received from user 2 for user 2 to verify encrypted information therein; receive verification input data submitted by user 2; generate an encrypted third visual encrypted image (cyphlens3) containing the input data verified by user 2, wherein: the cyphlens3 image can only be decrypted by user 1, user 2, and at least one other designated user (user 3); the cyphlens3 image includes an identifier of user 1; and only some of at least one of user 3 can approve further use of the cyphlens3 image and send the cyphlens3 image to at least one user 3.
[0037] In some respects, the technology described herein relates to a system further comprising: at least one third electronic device including a third graphical user interface, a third memory, and a third processor, the third processor being configured to: receive a cyphlens3 image; and, in response to a corresponding request received from one or more corresponding users among at least one user 3, decrypt the cyphlens3 image and provide the encrypted information therein to the corresponding user 3.
[0038] In some respects, the technology described herein relates to a system in which at least one of User 1 and User 2 inputs and submits information to be encrypted via a web form, an application, or an API (Application Programming Interface).
[0039] In some respects, the technology described herein relates to a system in which the cyphlens3 image also includes an identifier for user 2.
[0040] In some respects, the technology described herein relates to a system in which at least one of user 1 and user 2 authorizes cyphlens1 and cyphlens2 respectively by using at least one of actions on a touchscreen, actions using a real or virtual keyboard, and actions using a biometric reader.
[0041] In some respects, the technology described herein relates to a system in which a mobile device with a camera is used to decrypt at least one of cyphlens1, cyphlens2, and cyphlens3.
[0042] In some respects, the technology described herein relates to a system in which at least one of the cyphlens2 image and the cyphlens3 image is one of a modified cyphlens1 image and a first newly generated image, and a modified cyphlens2 image and a second newly generated image, respectively.
[0043] In some respects, the technology described herein relates to a system in which at least one of the cyphlens2 and cyphlens3 images expires after a selected time or duration and a corresponding one of a predetermined default time or duration.
[0044] In some respects, the technology described herein relates to a system in which the identifier of at least one of User 1 and User 2 is a respective email address or telephone number.
[0045] In some respects, the technology described herein relates to a system in which at least one of Cyphlens2 and Cyphlens3 images is transmitted via at least one of email, text message, messaging application, website, printed paper, wired communication system and wireless communication system.
[0046] In some respects, the technology described herein relates to a system in which at least one of user 1 and user 2 further decrypts the cyphlens3 image.
[0047] In some respects, the techniques described herein relate to a system in which one of the receivers of a cyphlens3 image further processes at least one of the cyphlens3 image and information decrypted therefrom.
[0048] In some aspects, the technology described herein relates to a system for two-way, two-factor remote user authentication, comprising: a workflow engine, a client device, and electronic devices. The workflow engine includes one or more processors and at least one memory element configured to store instructions for controlling the one or more processors, and the at least one memory element retains login data; the client device communicates with the workflow engine via a network, and the client device includes one or more processors, at least one memory element, a display, and a user login interface. At least one memory element is configured to store instructions for controlling one or more processors; a user login interface is configured to receive user identification data for a client device to log in to a computer system, the computer system having one or more login identifiers that identify the user login interface, wherein a login request is created at the user login interface, one or more login identifiers are generated and encrypted by a workflow engine, wherein, in response to encryption, one or more encrypted login identifiers are visually encoded into an authentication image, the authentication image being displayed on the monitor of the client device; an electronic device communicates with the workflow engine via a network, the electronic device including a monitor with a graphical user interface, one or more processors, at least one memory element, and an authentication identifier reader, the at least one memory element storing one or more login identifiers of the computer system and user identification data; the authentication identifier reader is configured to decrypt one or more login identifiers from the authentication image when the authentication identifier reader recognizes the authentication image, wherein, in response to decryption, one or more decrypted login identifiers and user identification data are configured to be verified by the workflow engine to authenticate the user, wherein one or more authenticated decrypted login identifiers are configured to be displayed on the monitor of the electronic device, and authorization for a login request to access the computer system of the client device is configured to be sent to the workflow engine via the electronic device.
[0049] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein an authentication identifier reader is configured to decrypt one or more login identifiers from an authentication image when the authentication identifier reader recognizes the authentication image at a predetermined distance from a predetermined location.
[0050] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein an authentication identifier reader is configured to decrypt one or more login identifiers from an authentication image when the authentication identifier reader identifies the authentication image at a predetermined time.
[0051] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein one or more encrypted login identifiers have encrypted content.
[0052] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the authentication image is a visual representation of one or more encrypted login identifiers.
[0053] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the electronic device has a camera configured to capture an authentication image of the client device's display.
[0054] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein an authentication image of the client device's display is uploaded to an electronic device.
[0055] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein user identification data is at least one of a username, email address, or password.
[0056] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the electronic device has an input sensor disposed on the display of the electronic device that senses external input to submit authorization for a login request to a workflow engine.
[0057] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein authorization of a login request is sent to a workflow engine when one or more authenticated, decrypted login identifiers are manually entered by the user into the computer system of the client device.
[0058] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the computer system of a client device is configured to prompt a user to input user identification data into the computer system of the client device.
[0059] In some respects, the techniques described herein relate to a system for two-way, two-factor remote user authentication, and also include generating a symmetric key during pairing using transport layer security before importing the authentication image into the electronic device.
[0060] In some respects, the techniques described herein relate to a system for two-way, two-factor remote user authentication, which also includes public key infrastructure encryption of one or more login identifiers and decryption of one or more login identifiers from an authentication image.
[0061] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein an authentication image is linked to a specific browser session.
[0062] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the authentication image is valid for a configurable duration, and the authentication image and user identification data become invalid after the configurable duration has elapsed.
[0063] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein an authentication image is configured to be sent to an electronic device at time and the authentication image is configured to be decrypted at time.
[0064] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein an authentication image is configured to be decrypted when decryption is performed within a predetermined range at a predetermined location.
[0065] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the authentication image has geographic data.
[0066] In some respects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the authentication image includes a shared authentication image with a decryption key.
[0067] In some aspects, the technology described herein relates to a system for two-way, two-factor remote user authentication, comprising: a workflow engine and an electronic device. The workflow engine includes one or more processors and at least one memory element configured to store instructions for controlling the one or more processors, and the at least one memory element retains login data; the electronic device communicates with the workflow engine via a network, and the electronic device includes one or more processors, at least one memory element, a display, a user login interface, and an authentication identifier reader. At least one memory element is configured to store instructions for controlling one or more processors; the user login interface is configured to receive user identification data for an electronic device to log in to a computer system, the computer system having one or more login identifiers that identify the user login interface, wherein a login request is created at the user login interface, at least one memory element is configured to store one or more login identifiers of the computer system and user identification data, one or more login identifiers being generated and encrypted by a workflow engine, wherein, in response to encryption, one or more encrypted login identifiers are visually encoded as an authentication image, the authentication image being displayed on the display of the electronic device; an authentication identifier reader is configured to decrypt one or more login identifiers from the authentication image when the authentication identifier reader recognizes the authentication image, wherein, in response to decryption, one or more decrypted login identifiers and user identification data are configured to be verified by the workflow engine to authenticate the user, wherein one or more authenticated decrypted login identifiers are configured to be displayed on the display of the electronic device, and authorization for a login request to access the computer system of the electronic device is configured to be sent to the workflow engine via the electronic device.
[0068] In some aspects, the technology described herein relates to a method for mutual two-factor remote user authentication, comprising: receiving, at a workflow engine, a request from a user login interface to log in to a computer system from a client device, the user login interface being configured to receive user identification data from the client device logging in to the computer system, the computer system having one or more login identifiers that identify the user login interface, wherein a login request is created at the user login interface; in response to the request from the client device, the workflow engine generates one or more login identifiers; encrypts one or more login identifiers via the workflow engine; in response to encryption, visually encodes one or more login identifiers into an authentication image via the workflow engine; decrypts one or more login identifiers from the authentication image using the authentication identifier reader when the authentication identifier reader recognizes the authentication image; in response to decryption, verifies one or more decrypted login identifiers and user identification data via the workflow engine to authenticate the user; and sends authorization for the login request to the workflow engine to access the client device's computer system.
[0069] In some respects, the techniques described herein relate to a method that also includes sending an authorization response, prompting the user to input user identification data into the computer system of the client device to complete the login.
[0070] In some respects, the technology described herein relates to a method that also includes sending an authentication image from a workflow engine to a client device and displaying the authentication image from the client device's display.
[0071] In some respects, the technology described herein relates to a method in which a client device has an authentication identifier reader, and in response to decryption, the client device displays one or more authenticated decrypted login identifiers on the client device's display.
[0072] In some respects, the techniques described herein relate to a method in which authorization of a login request is sent to a workflow engine when one or more authenticated decrypted login identifiers are manually entered by a user into the computer system of a client device.
[0073] In some respects, the techniques described herein relate to a method that also includes sending an authentication image from a workflow engine to an electronic device and displaying the authentication image from the display of the electronic device.
[0074] In some respects, the technology described herein relates to a method in which an electronic device has an authentication identifier reader, and in response to decryption, the electronic device displays one or more authenticated decrypted login identifiers on the display of the electronic device.
[0075] In some respects, the techniques described herein relate to a method in which authorization of a login request is sent to a workflow engine when one or more authenticated decrypted login identifiers are manually entered by a user into the computer system of an electronic device.
[0076] In some aspects, the technology described herein relates to a method for mutual two-factor remote user authentication, comprising: encrypting data via a workflow engine and visually encoding the data into a first authentication image via the workflow engine; providing a second authentication image; providing an electronic device having an authentication identifier reader; decrypting the first authentication image using the authentication identifier reader of the electronic device when the authentication identifier reader recognizes the first authentication image and the second authentication image; verifying one or more decrypted data via the workflow engine to authenticate the user in response to the decryption; and sending authorization for a login request to access the computer system to the workflow engine.
[0077] In some respects, the techniques described herein relate to a method in which decryption is authorized via a decryption key of an electronic device.
[0078] In some respects, the techniques described herein relate to a method in which a second authentication image is encrypted using data used to decrypt a first authentication image for dual second-factor authentication.
[0079] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation is a still image.
[0080] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation is part of a video feed.
[0081] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein capturing a visual representation includes capturing two or more visual representations, and decoding a visual representation includes simultaneously decoding two of the more visual representations.
[0082] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein decrypting the encrypted content further includes decrypting the encrypted content using predetermined key material.
[0083] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation includes one or more formats selected from the group consisting of: QR codes, data matrices, data glyphs, and / or any other related formats.
[0084] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the method further includes displaying part or all of the decrypted content.
[0085] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein displaying the encrypted content further includes overlaying the decrypted content onto one or more objects.
[0086] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the decrypted content is used internally by a computer system to perform one or more tasks.
[0087] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein the file includes multiple visual representations, and the method further includes performing an integrity check on the encrypted content of the multiple visual representations.
[0088] The purpose of this invention is to provide a method for encrypting and decrypting data using visually encoded ciphertext, wherein performing an integrity check further includes generating a hash value for each visual representation in the order in which each visual representation appears in the file, and comparing the hash value with the hash value generated when the encrypted content is encrypted.
[0089] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation is a still image.
[0090] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation is part of a video feed.
[0091] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein capturing a visual representation includes capturing two or more visual representations, and decoding a visual representation includes simultaneously decoding two of the more visual representations.
[0092] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein decrypting the encrypted content further includes decrypting the encrypted content using predetermined key material.
[0093] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein the visual representation includes one or more formats selected from the group consisting of: QR codes, data matrices, data glyphs, and / or any other relevant formats.
[0094] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein the second electronic device further includes a display configured to display part or all of the decrypted content.
[0095] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein the decrypted content is used internally by a computer system to perform one or more tasks.
[0096] The purpose of this invention is to provide a system for encrypting and decrypting data using visually encoded ciphertext, wherein the file includes multiple visual representations, and wherein a second processor is further configured to perform integrity checks on the encrypted content of the multiple visual representations. Attached Figure Description
[0097] Figure 1 An advanced process for converting data into visually encoded ciphertext according to an embodiment of the present invention is illustrated.
[0098] Figures 2A-2B Non-overlay content is shown according to an embodiment of the present invention. Figure 2A ) and overlay content ( Figure 2B ).
[0099] Figure 3 The structure of encrypted content according to an embodiment of the present invention is shown.
[0100] Figure 4 An example of a transaction summary with a PIN is shown according to an embodiment of the present invention.
[0101] Figure 5 A user-decrypted QR code is shown according to an embodiment of the present invention.
[0102] Figure 6 An example of CAPTCHA replacement according to an embodiment of the present invention is shown.
[0103] Figure 7 An example of multi-party decryption according to an embodiment of the present invention is shown.
[0104] Figure 8 An example of a verification service with two approvals is shown according to an embodiment of the present invention.
[0105] Figure 9 This is a block diagram illustrating the system according to some embodiments of the present invention.
[0106] Figure 10 This is further illustrated by some embodiments of the present invention. Figure 9 A block diagram of the system.
[0107] Figure 11 This is a block diagram illustrating the system according to some embodiments of the present invention.
[0108] Figure 12 This is a flowchart illustrating a method according to some embodiments of the present invention.
[0109] Figure 13 This is a flowchart illustrating a method according to some embodiments of the present invention. Detailed Implementation
[0110] Exemplary embodiments of the invention will now be described with reference to the accompanying drawings. The same elements in the drawings are identified by the same reference numerals. These embodiments are provided by way of explanation and are not intended to limit the invention. Indeed, it will be understood by those skilled in the art, upon reading this specification and viewing the drawings, that various modifications and variations can be made therein.
[0111] A system is provided for encrypting and displaying private content in public settings. In embodiments, this is accomplished by utilizing state-of-the-art encryption, image processing, and optional augmented reality user experiences.
[0112] In this embodiment, the system can visually encrypt multiple pieces of sensitive information (e.g., text, images, videos). This sensitive information can be independent or part of a larger file. Most files do not need to be fully encrypted because only some parts are sensitive. Using this invention, users can choose to encrypt only the parts of a file they deem sensitive, and encrypt them visually, making decryption a "click and shoot" user experience. In this embodiment, the encrypted fragment is embedded in the file and placed in the exact same location as its unencrypted copy. In this embodiment, users only need to point their device's camera at the encrypted information fragment to decrypt it in real time, instantly. This new technology supports a large number of new applications and provides a novel solution to a wide range of cybersecurity attacks (e.g., phishing attacks, man-in-the-middle attacks).
[0113] In one embodiment, the system includes one or more electronic devices. The electronic devices may include one or more cameras that can be configured to include an internet connection via a wired and / or wireless link. In one embodiment, the one or more electronic devices include a desktop computer, laptop computer, tablet computer, smartphone, smart glasses, and / or any other suitable electronic device. In one embodiment, the one or more electronic devices include one or more displays.
[0114] In this embodiment, the system encrypts and visually encodes content in the following manner: to decrypt the content, the user needs to use a device equipped with a display and one or more cameras. In this embodiment, the visual representation of the encrypted content is captured by one or more image capture devices, either as still images or as part of a video feed, and is then decoded and decrypted.
[0115] In this embodiment, depending on the specific circumstances, the decrypted content may or may not be displayed to the user. In this embodiment, if the content is displayed to the user, it can be overlaid on and "anchored" to other content (e.g., images, logos, advertisements, etc.). This option of overlaying content on other content provides the user with an augmented reality user experience. According to an alternative embodiment, the decrypted content can be displayed anywhere on the device screen (e.g., at the bottom of the screen).
[0116] If the device's camera captures multiple (adjacent or non-adjacent) visual codes at once, the system can decode and decrypt the content simultaneously. If the decrypted data is to be used by people, the system can simultaneously display that content overlaid on other content or displayed anywhere else on the device screen.
[0117] In this embodiment, in order for the device to decrypt the content, the user equipment needs to have access to the correct key material. In this embodiment, the system supports both symmetric key encryption and asymmetric key encryption.
[0118] In this embodiment, the content is provided by the user. The user-provided content is encrypted and "formatted" to create a visual representation of the encrypted content (an encrypted content image). In this embodiment, while maintaining the spirit of the invention, the encrypted content image may be in the form of one or more QR codes, data matrices, data glyphs, and / or some other suitable visual representation. In this embodiment, a mixture of multiple visual representations may be used for the same encryption code (e.g., a QR code surrounded by data glyphs). In this embodiment, the user may use a graphical user interface coupled to an electronic device to select the content to be encrypted. The electronic device may be, for example, a desktop computer, laptop computer, tablet computer, smartphone, and / or any other suitable electronic device. In this embodiment, there may be one or more electronic devices. The electronic device may include at least a processor, memory, a graphical user interface, a display, one or more cameras, and other related components.
[0119] In this embodiment, the encrypted content encoded in the encrypted content image can be divided into two different types: the actual content and / or a “pointer” to the actual content.
[0120] In this embodiment, the actual content that the user or machine has provided and needs to use is encrypted and visually encoded (“Actual Content”). In this embodiment, one or more pointers to the content to be used are encrypted and visually encoded (“Pointers”). For example, a pointer may be a Uniform Resource Identifier (URI), an alphanumeric identifier (ID), and / or some other representation that redirects to the actual content. In this embodiment, other metadata may also be present as part of the encrypted data. The content to be encrypted may be user-provided or machine-generated, and may or may not be in a human-readable format.
[0121] In this embodiment, multiple operations are performed to encrypt the content; the number of operations depends on the required functionality and user experience. For example, Figure 1 A flowchart illustrating the advanced process for converting data into visually encoded ciphertext is shown.
[0122] According to various embodiments of the present invention, the decrypted content can be "anchored" to a specific location on the device screen, can be displayed anywhere on the device screen, and / or not be displayed to the user at all but is for internal use.
[0123] In this embodiment, if the decrypted content is anchored at a specific location on the device screen, the following may occur:
[0124] 1. Decrypt the encrypted content according to the corresponding encryption code;
[0125] 2. By using various image processing techniques, the encrypted code is erased from the augmented reality view. In this embodiment, logos, images, advertisements, and / or any other suitable visual objects may be placed in its location;
[0126] 3. The decrypted information is placed in the location of the encrypted code, or overlaid on a logo, image, advertisement, and / or any other suitable visual object (in whole or in part) that replaces the encrypted code.
[0127] According to one embodiment of the present invention, Figure 2B An example is depicted where content is overlaid on a business logo "anchored" to a position previously occupied by encrypted code. Non-overlay content, such as... Figure 2A As shown.
[0128] In this embodiment, the operation process may include the following: plaintext → encryption → error correction → visual encoding. Compression may or may not be used in this case.
[0129] In this embodiment, for non-overlay content, plaintext is not anchored to a specific location or overlaid on other content, but can be displayed anywhere on the device screen.
[0130] The workflow used in this scenario may include the following: plaintext → compression → encryption → error correction → visual encoding. In this embodiment, compression can be applied because the size of the visual encoding does not need to match the size of the decrypted content, and therefore it can be smaller.
[0131] In cases of internal use, the ciphertext is decrypted and the corresponding plaintext is not displayed to the user, but is used "internally" by the system. The operational procedures used in this scenario can be the same as in the previous non-overlapping content scenario. For example, this could occur in places such as digital signatures for blockchain transactions, where the encrypted information is the wallet's private key.
[0132] In some embodiments, a hybrid approach may also occur, where, given an encryption code, some decryption elements are displayed to the user, while other elements (e.g., metadata) are used internally.
[0133] In this embodiment, one or more encryption keys may be used. According to various embodiments, encryption may be performed using both asymmetric and symmetric keys. Specifically, according to various embodiments, per-file keys and per-user keys may be used.
[0134] If files will be shared among multiple parties, a per-file key can be used. In this case, each new file will use a different encryption key.
[0135] If the files will remain private and not shared with other parties, a per-user key can be used. In this case, multiple files can use the same encryption key.
[0136] In embodiments, multiple visual codes (whether adjacent or non-adjacent) can be captured and processed simultaneously. This includes cases with multiple visual codes of mixed types (e.g., QR codes and data glyphs). In embodiments, if multiple visual codes (i.e., blocks) exist, these visual codes are completely independent of each other and do not share any type of information with each other; that is, they are independent entities.
[0137] In one embodiment, to view the decrypted content, the user places their device camera over a visually encoded area containing the encrypted content. In this embodiment, the device captures the bits of the ciphertext using the camera by applying various image processing techniques to the visual encoding. Then, if the user's device does not already have a decryption key, the device retrieves the decryption key for the ciphertext from a backend. The ciphertext is then decrypted (i.e., plaintext) and displayed to the user either as an overlay or on another part of the device screen. If the plaintext is not intended for user use, it is not displayed to the user but is instead used internally by the system.
[0138] In embodiments, a visual representation may be, for example, a representation of an encrypted pointer to the content (e.g., a URI, a URL) or an ID that identifies some attribute of the visual representation (e.g., its location in the world, the name of its owner) or other representations. In embodiments, additional metadata may be present.
[0139] In this embodiment, the decrypted data is not the actual content the user needs to view, but rather a pointer to that content or some metadata. In this embodiment, once the pointer to the actual content is decrypted, the user device connects to a backend server and retrieves the appropriate encrypted content using the decrypted pointer and any additional information (e.g., time of day, GPS coordinates of the user device). For example, a URI could point to a (encrypted) image or video. On the other hand, an ID could point to some image or text that may change over time, because the same ID might return different content if queried at different times.
[0140] In this embodiment, content retrieved from the backend can be displayed as an overlay on the device screen or anywhere else (e.g., at the bottom). If the content is not intended for user use, it will not be displayed to the user but will be used internally by the system.
[0141] In this embodiment, to correctly visually decode encrypted content (especially when using unmarked custom visual encoding), it needs to be organized in a specific way to improve the efficiency of the decoding process. Specifically, the encrypted content is organized into a specific structure before visual encoding. Figure 3 One possible structure is shown.
[0142] Generally, the header and body can use different visual encodings. For example, a lower-capacity but more robust visual encoding can be used for the header to make it more resistant to errors. Examples of different visual encodings include: QR codes in the header and data glyphs in the body; one-bit encoding per glyph in the header and two-bit encoding per glyph in the body; and QR codes in the header and data matrices in the body. In the simplest case, the header and body can use the same visual encoding.
[0143] Now examine each field of the structure and its meaning. In the following calculations, assume the header is a 12×12 matrix (one visual code per character).
[0144] Truncated hash value: Calculate the first 24 bits of the hash function (e.g., SHA256, HMAC) over all other fields in the header.
[0145] Version: This field is unencrypted and represents the version number of the block structure (bits: 24-31).
[0146] Line: This field is unencrypted and 8 bits long. It represents the number of lines in the block, including the header; that is, we can have a maximum of 256-12=244 lines of encrypted content. (This field may be removed or reassigned in future versions of the block structure.)
[0147] Column: This field is unencrypted and 8 bits long. It represents the number of columns in the block, including the header; that is, we can have a maximum of 256-12=244 columns in the encrypted content block. (This field may be removed in future versions of the block structure.)
[0148] Control bits: This field may contain special bits (e.g., checksum for error correction, parity byte, MAC, hash value of other fields), and if so, the size of this field can be changed. Currently, it contains a truncated hash of the encrypted content or some error correction bits.
[0149] Encrypted Content: This field contains the actual encrypted content and is N bits long, where N is up to (2^44) bits based on the row / column fields described above. 244 2) Variable number of bits. This means that a single block can contain up to 14,884 ASCII characters of (encrypted) content. If such a field exists, the size of the subsequent optional field (i.e., M bits) must be subtracted from these calculations.
[0150] Additional Data: This field is optional. Additional data can be appended to the body of the text following the encrypted content field if required by the encryption algorithm. This additional data will only be used for decryption and therefore will not be considered part of the encrypted content. Its size is variable. In this embodiment, the encryption algorithm can be any existing encryption algorithm, such as AES256 in GCM mode.
[0151] Given the structure defined above, this paper describes a possible method for searching for valid encrypted blocks using the present invention.
[0152] In this embodiment, when the device searches for a cryptographic block, it first performs various image processing transformations (e.g., converting the image to grayscale, applying Gaussian blur, and other filters). Once the initial image processing is complete, the device begins searching for the beginning of the block. Specifically, it calculates the hash value of the 96+8+8+8 bit field it sees in the header and compares the first 24 bits of that hash value with the 24 bits of the truncated hash value field. If they match, the device has found a valid block. If they do not match, no valid block beginning has been found, and the search needs to continue.
[0153] If a valid block has been found, we first examine the version field to understand what version of the block structure it is. Specifically, the version number tells us how to interpret the individual fields within the block and the specific positions within those fields. For example, different versions can use different header structures, different encryption algorithms, or assign different meanings to control bit fields. Similarly, different versions can define different boundaries, thus defining different sizes for different fields.
[0154] In version 0, the control bit field can contain a truncated hash of the encrypted content. In other versions, however, such a field can contain: a checksum, an error correction code, a truncated hash of the encrypted content field, a Message Authentication Code (MAC), or others. In the case of error correction, this should be performed before attempting decryption. In the case of a truncated hash of the encrypted content, the hash should be verified before attempting decryption to ensure that the correct header has been read for the correct content.
[0155] After examining the version field, we look at the row / column fields to determine how many bits are needed to correctly decrypt the encrypted content. Once we know this, we can continue reading the remaining bits and attempt to decrypt. Specifically, in version 0, the encrypted content to be decrypted can be given in N bits.
[0156] Once the encrypted content has been correctly decrypted, it can be displayed to the user or used "internal" by the system, as described above.
[0157] In this embodiment, multiple encrypted blocks can be scattered throughout the file. It is crucial to ensure that the initial insertion order of these blocks in the file remains unchanged. Furthermore, it is important to ensure that no block is replaced by another block that was not intended to appear in the file. In other words, we need to verify the integrity of the encrypted content.
[0158] To verify integrity, the hash value of all encrypted blocks is calculated when the encrypted blocks are generated. Specifically, the headers of the encrypted blocks (or complete blocks) are collected in the exact order in which they appear in the file, and the hash value (e.g., SHA256) of all these headers is calculated and stored.
[0159] Before performing decryption, if the user wants to verify the integrity of the encrypted portion of the file, the encrypted blocks are captured in the order they appear so that the device can generate hash values. This hash value is then compared to the hash value generated during encryption; if they match, the integrity verification succeeds; otherwise, it fails. In either case, a visual cue can be displayed to the user.
[0160] When capturing blocks for integrity verification, the user can capture all blocks at once or capture them one by one. However, if they are captured in the wrong order, integrity verification will fail. Furthermore, integrity verification will also fail if decryption of any block fails.
[0161] The techniques related to this invention described herein can be used in a variety of novel applications, some of which are described below. However, it should be noted that, while maintaining the spirit of the invention, it can be used in other novel applications not mentioned.
[0162] Verification service: In this use case, users can protect their online accounts on a given website so that even if the website is compromised (i.e., a malicious actor can log into the user's account), the user can still:
[0163] 1. Verify that the transactions / operations they submit are indeed what they intended to submit / do, and that no malicious actors have modified them in any way;
[0164] 2. Ensure that no malicious actors can execute unauthorized transactions / operations from their accounts.
[0165] To do this, the transaction digest (including the transaction ID) is encrypted along with a random PIN / string within the encrypted code. For example, for a transaction to be submitted, the user decrypts the encrypted code as described in the previous section and sees the transaction digest and the random PIN. The user can view and verify the transaction digest to ensure everything is correct and proceed by inserting the random PIN into the opposite field on the website. Once the PIN is verified, the transaction is executed.
[0166] If a malicious actor has modified a user-initiated transaction, they cannot obtain the encryption key and therefore cannot generate a forged cryptographic digest of that transaction. The modified transaction will then be displayed to the user in the cryptographic digest, allowing the user to detect it and decide not to proceed. Similarly, if a malicious actor initiates a new unauthorized transaction, they will not be able to decrypt the digest and read the random PIN to continue the transaction. Furthermore, the cryptographic transaction digest can be used to notify and warn the user so they can take appropriate action. Figure 4 An example of a Bitcoin transaction summary using a verification service is shown.
[0167] Multi-party decryption: In multi-party decryption, multiple parties need to participate in the process to decrypt or unlock certain data. There are two methods to achieve this:
[0168] 1. Multi-party sequential operation; and
[0169] 2. Multi-party parallel operation.
[0170] Furthermore, when operating in parallel, external automata can act as gatekeepers (e.g., multi-signature contracts in the Ethereum blockchain), where two instances (from the same or different users) are required to have decrypted the same content and signed the transaction in order for the transaction to proceed.
[0171] For parallel and sequential operation modes, the method may involve portions of the same key held by different parties, or it may involve keys that create encryption keys for the chain of custody, or it may involve different information required to create or retrieve encryption / decryption keys.
[0172] Here are three examples of how multi-party decryption works. In the first example, for instance, we encrypt some data and encode it in a QR code. Then, we encrypt the entire QR code using different encryption keys. When decryption is needed, one party is given a decryption key to decrypt the QR code, and the other party is given a decryption key to decrypt the contents of the QR code.
[0173] Figure 5 The diagram shows the first user decrypting the QR code. Once decrypted, a second user's device can scan the QR code and decrypt its content. Thus, the device effectively possesses the decryption key to decode the QR code's content.
[0174] It's important to note that QR codes and their encryption can be constructed in a way that prevents the same QR code from being used multiple times. This prevents a second user from taking a picture of the QR code (i.e., after user 1 has decrypted it) and using it whenever he or she wants without the first user's presence. To make this possible, the QR code's encryption could be a URL pointing to a dynamically created encrypted QR code.
[0175] Figure 7 The second example illustrates a scenario where User 1 has access to an encrypted block containing some input data (INPUT 1.1), and User 2 has access to an encrypted block containing a wallet private key or some sensitive data for decryption. In this case, User 1 decrypts the encrypted block containing the input value (INPUT 1.1). He or she then enters the answer to a security question, a password, or similar information (INPUT 1.2). The two inputs, INPUT 1.1 + INPUT 1.2, are then used as input to a PRF or similar function. User 1 then encrypts the output of the PRF [INPUT 2.1] using User 2's public key and encodes it in an encrypted block, a QR code, or other visual encoding (this could be time-limited, one-time use, etc.). User 2 decrypts the encrypted block using their private key and obtains the input (INPUT 2.1). As a second step, User 2 inserts the answer to a security question, a password, or similar information (INPUT 2.2). The two inputs, INPUT 2.1 + INPUT 2.2, are then used as input to a PRF or similar function. The function outputs the encryption key that User 2 needs to use in order to decrypt the encrypted block using User 2's wallet private key or other sensitive data.
[0176] Figure 8 A third example is shown, where the process, as part of the verification service, can reflect a multi-step approval process. Two approvals are described below, but any number of approvals can be used, and there is no limit to the number. Furthermore, although the use of "cyphlens images" (i.e., visual encoding of encrypted content) is described, other forms of encoding can be used, and there is no limitation on the encoding used. Additionally, although beneficiary information is described below, any kind of digital content can be used. The content can also be in any of the many formats that can be submitted, such as text, images, video, or a combination of multiple formats, and the described multi-step approval process can be used or requested advantageously.
[0177] In this example use case, User 1 enters and submits beneficiary information, such as through a website, application, or API (Application Programming Interface). Here, the beneficiary is simply someone who benefits from something. User 1 receives a visually encoded ciphertext (“cyphlens1”) image containing the encrypted beneficiary information they just submitted. User 1 then decrypts the cyphlens1 image using their mobile device or its camera, etc., to obtain the encrypted beneficiary information and verifies it. If the beneficiary information obtained from the cyphlens1 image is correct (i.e., not modified), User 1 approves the use of the cyphlens1 image, for example, by performing an action using a touchscreen, a physical or virtual keyboard, and / or a biometric reader. For example, approval might require actions such as swiping, entering a password, or a PIN. Furthermore, only User 1 can approve the cyphlens1 image for further use.
[0178] Next, the beneficiary information approved by User 1 is encrypted again in a new "cyphlens2" image or a modified cyphlens1 image. The cyphlens2 image can be characterized by at least one of the following:
[0179] Cyphlens 2 images may expire after a predetermined or selected time, or they may not expire at all.
[0180] Only designated user 2 can decrypt the cyphlens2 image.
[0181] The cyphlens2 image includes user 1's email address or other identifiers.
[0182] The cyphlens2 image is then sent to user 2. The image can be sent via email, text message, messaging app, website, printed paper, wired communication system, and wireless communication system.
[0183] User 2 uses their mobile device or its camera, etc., to decrypt the cyphlens2 image to obtain the encrypted information within it and verify it. If the decrypted information is correct, User 2 approves the use of the cyphlens2 image, such as by performing actions using a touchscreen, using a real or virtual keyboard, and / or using a biometric reader.
[0184] Next, the beneficiary information approved by User 1 and User 2 is encrypted again in a new Cyphlens3 image or a modified Cyphlens2 image. The Cyphlens3 image can be characterized by at least one of the following:
[0185] Cyphlens3 images may expire after a predetermined or selected time, or they may not expire at all.
[0186] Cyphlens3 images can only be decrypted by User 1, User 2, and at least one other designated user (User 3).
[0187] Images from cyphlens3 can only be approved for future use by at least one user.
[0188] The cyphlens3 image includes user 1's email address or other identifier, and optionally user 2's email address or other identifier.
[0189] A Cyphlens3 image (or a modified Cyphlens2 image) is sent to a designated user, such as via email, text message, messaging app, website, printed paper, wired communication system, and wireless communication system. The recipient of the new or modified Cyphlens3 image can then decrypt the Cyphlens3 image using their respective mobile device, camera, etc., to obtain the encrypted information contained therein. The recipient can then further process the cipher image and / or the information decrypted from it.
[0190] As described above, User 1 designates the second user (User 2) to approve, and User 2 designates the third user (User 3). However, in other embodiments, User 1 may not know the identity of User 2; the same applies to User 2, User 3, and all other users. An administrator managing this process can configure the user list and their respective roles within the process. The system can then ensure that various encrypted Cyphlens images are progressively forwarded to the correct users.
[0191] Forced Multi-Party Access: As we have seen before, in multi-party decryption involving two users, ideally, user 2 can decrypt encrypted content without user 1 taking any action (e.g., user 2 can take a picture of the QR code decrypted by user 1 and use it at any time without user 1 even noticing). Below, we describe a possible way to force both user 1 and user 2 to be present in order to decrypt content and prevent the aforementioned problem.
[0192] When a QR code is encrypted within an encrypted block, some metadata can be associated with that QR code. This metadata may include: the number of times the QR code can be decrypted (see [link to QR code]). Figure 5 This includes the date when QR code decryption is disabled, the allowed decryption period from the moment the QR code is decrypted, and so on. Specifically, the hash values of the encrypted blocks and the QR codes are stored on the server along with associated metadata.
[0193] In many cases, when user 1 decrypts the QR code (see...) Figure 5 The hash value of the encrypted block is sent to the server, and the decryption event is registered with the server in the backend.
[0194] When User 2 scans the QR code (displayed by User 1) to decrypt its content, his or her device sends the hash value of the QR code to the server. The server will examine the metadata associated with the QR code and will either allow or deny its decryption. For example, decryption of the QR code's content may only be possible for a specific amount of time from the moment User 1 decrypts the QR code. Similarly, decryption of the QR code's content may only be possible a limited number of times, after which decryption attempts will fail.
[0195] It is worth noting that the QR code is used as an example only, and any other visual representation can be used in place of the QR code.
[0196] Ice-Cold Wallet Transactions: An ice-cold wallet is a type of cold wallet where the blockchain private key is encrypted with cryptographic code and printed on paper (i.e., stored offline). Additionally, the decryption key used to decrypt the blockchain private key is also encrypted with a different cryptographic code and printed on paper (i.e., stored offline).
[0197] Such “offline” content can be stored in a bank vault or any other location and can be decrypted using a mobile application or any automaton that follows the protocol specified in this invention.
[0198] When a user needs to sign a transaction, he or she needs to decrypt the encrypted code containing the blockchain's private key. To do this, the following occurs:
[0199] 1. The user device retrieves the decryption key (from the company server) used to decrypt the decryption key of the wallet.
[0200] 2. The user equipment decrypts the decryption key and then continues to decrypt the blockchain private key.
[0201] 3. The user device loads the blockchain private key and signs the transaction on the device.
[0202] 3a. Alternatively, the signing can be done on another server where the key is securely available.
[0203] 4. Signed transactions can be moved "online" to the blockchain or sent to blockchain nodes.
[0204] In this embodiment, when executing a multi-party transaction, there are two operation modes for signing the transaction: parallel and sequential.
[0205] In parallel mode, User 1 signs a transaction and sends it to the (company's) server. Simultaneously, User 2 signs the same transaction and sends it to the company's server independently of User 1. The company's server, interacting with the blockchain, publishes the transaction to the blockchain (such as Ethereum), and once both users have signed, the transaction becomes effective on the blockchain. This verification can be accomplished using another smart contract or some in-memory logic.
[0206] In sequential mode, User 1 and User 2 need to sign the transaction sequentially before it is published to the blockchain. Once User 1 signs the transaction, he or she can send a partially signed portion of the transaction to User 2's device (e.g., via NFC, VPN), allowing User 2 to also sign it. Only after both users have signed the transaction will it be sent to the (company's) server, which will then publish it to the blockchain (e.g., Bitcoin).
[0207] Furthermore, in this use case, we can have both multi-party and single-party operation modes.
[0208] Time-based decryption: In previous use cases, the ability to decrypt encrypted code could be revoked at any time by withdrawing the decryption key associated with the file. For time-based decryption, we enhance this functionality by allowing content creators to specify an expiration date for the encrypted code. This way, anyone with access to such encrypted code can decrypt it before the expiration date. Once the expiration date has passed, the decryption key will be removed and / or erased from all (or some) user devices that have access to the encrypted code. Furthermore, additional steps can be taken to prevent users from decrypting expired encrypted code (e.g., decryption fails if the device lacks internet access).
[0209] CAPTCHA replacement: In this usage scenario, we encrypt the square pattern, such as... Figure 6 As shown. In this embodiment, the squares are colored squares. In this embodiment, the user is then prompted to press all squares of a certain color on the screen (e.g., press all yellow squares). Alternatively, we could prompt the user to follow a more complex pattern, such as alternating between pressing two different colors of squares (e.g., alternating between pressing yellow and red squares) until all squares of both colors have been pressed. Other mechanisms that do not involve color can also be used.
[0210] Mutual authentication: Content can be encrypted using either symmetric or asymmetric key encryption. When using an asymmetric key, the content can be additionally signed by the party encrypting it, and the signature is included in the encrypted content.
[0211] When a user decrypts encrypted content (in the case of an asymmetric key, verifying the signature), it can imply authentication between the two parties.
[0212] Specifically, assuming symmetric key encryption, the encrypted content can include an encrypted timestamp, alphanumeric codes, and any other identifiers from the other party. For a website, this identifier could be the domain name associated with the website, for example:
[0213] On the user's end, by decrypting such encrypted content (or verifying the signature if asymmetric key encryption is used), the user can assume the remote party is legitimate because it possesses the correct key required to perform encryption (or signing). Furthermore, in the case of website authentication, the decrypted domain name can be visually verified by the user and compared to the domain name appearing in the browser's address bar or similar location.
[0214] On the other side (e.g., a web server), the user is authenticated by providing an alphanumeric code as part of the encrypted content. This alphanumeric code can be a one-time code. By providing such a code to the web server, the user proves that they have access to the encrypted material needed to correctly decrypt such code, and therefore are a legitimate user.
[0215] This mutual authentication scheme can be used in various use cases such as website login and multi-factor authentication. Specifically, the user provides his or her username (or any other unique identifier), and the remote party (e.g., a website) responds with the aforementioned encrypted content, which is encrypted using ciphertext assigned to that user.
[0216] Sharing images: Images can be shared by encrypting and encoding the image's URL using some additional metadata. This metadata may include, for example, random alphanumeric codes necessary for downloading and displaying the image to the user.
[0217] Specifically, when a user decrypts the encrypted code pointing to an image, the user's device processes the decrypted URL and provides the decrypted alphanumeric code to the backend. Only if successful will the image be downloaded and displayed to the user.
[0218] In this embodiment, additional metadata (e.g., time of day, location information) may be included in the encrypted content or may be provided by the user's device. When paired with encrypted / decrypted content, this additional information can be used to enable new services (e.g., location-based services) and to provide the user with different content (e.g., store coupon codes).
[0219] For example, an encrypted code with an encrypted URL can be used to display an alphanumeric code to allow access to a restricted area. This decrypted URL, along with the time of day and device location, will return an image of an alphanumeric code for accessing the restricted area at that time. The user can then use such a code to enter the restricted area. Different codes can be displayed for the same encrypted content at different times of day. If the device location does not match the encrypted code location, access to the decrypted image can be denied.
[0220] Paper documents: Encryption codes can be used to encrypt sensitive information segments in paper documents, etc. Examples include: Social Security cards, passports, company ID cards, and tax returns. Additionally, supplementary data that only government or company officials can decrypt can be included in these documents.
[0221] For example, a passport may include encrypted code containing personal information such as full name, date of birth, passport number, validity period, and a photograph of the passport holder. This information can also exist in unencrypted text form. Government officials can verify whether a passport is counterfeit by comparing the text in the passport with the encrypted information in the encrypted code. Furthermore, passports may also contain encrypted information that may include (or point to) sensitive content, such as violation records, police records, or DMV records. This information can only be decrypted by government / company officials, not by the passport holder.
[0222] Mixed Media: A paper (or electronic) card containing encryption blocks needs to be placed in the same camera view as other encryption blocks (electronic or paper). Integrity verification is performed by placing the blocks in the correct order, and if successful, decryption is performed using the key encrypted in the paper card's encryption block as the decryption key.
[0223] In this embodiment, the encrypted password on the paper card is only displayed to the user when the integrity verification operation is successful, depending on the specific scenario.
[0224] In this embodiment, multi / two-factor devices (i.e., hardware or software) may require updates under different circumstances. For example, a user might decide to upgrade their mobile device, or their phone might be stolen. In both cases, the user needs access to their digital assets to take some action.
[0225] In one scenario, for example, if a user upgrades their mobile device, an encrypted challenge is displayed to the user. This challenge can be decrypted on the old device, and its contents (along with other information such as username and password) can be inserted into a form on the new device to trigger a new registration or login on the new device, thus linking the old device / identity to the new device. A second factor is then transferred to the new device.
[0226] In another scenario, for example, to recover from the loss of a second-factor device (software or hardware) without reloading or reinstalling a new second factor, the concept of human second-factor recovery is introduced.
[0227] Figure 9 This is a block diagram illustrating a system 902 according to some embodiments of the present disclosure. In some embodiments, system 902 may include a workflow engine 904, and one or more authenticated decrypted login identifiers 932 may be configured to be displayed on a display 922 of an electronic device 920. System 902 may also include a client device 910, which can communicate with the workflow engine 904 via a network. System 902 may also include an electronic device 920, which can communicate with the workflow engine 904 via a network. System 902 may also include an authorization 934 for login requests to a computer system 936 accessing client device 910, which may be configured to be sent by electronic device 920 to workflow engine 904.
[0228] In some embodiments, workflow engine 904 may include one or more processors 906. Workflow engine 904 may also include at least one memory element 908 configured to store instructions for controlling one or more processors 906, and at least one memory element 908 may store login data. Client device 910 may include one or more processors 912 and a display 916. Client device 910 may also include at least one memory element 914 configured to store instructions for controlling one or more processors 912. Client device 910 may also include a user login interface 918 configured to receive user identification data for client device 910 to log in to computer system 936.
[0229] In some embodiments, the electronic device 920 may include a display 922 and one or more processors 926. The electronic device 920 may also include at least one memory element 928. The at least one memory element stores one or more login identifiers 938 and user identification data of the computer system 936. The electronic device 920 may also include an authentication identifier reader 930, which may be configured to decrypt one or more login identifiers 938 from the authentication image 1040 when the authentication identifier reader 930 recognizes the authentication image 1040.
[0230] In some embodiments, the display 922 may include a graphical user interface 924. In response to decryption, one or more decrypted login identifiers and user identification data may be configured to authenticate the user via workflow engine 904. The computer system 936 may also include one or more login identifiers 938 that identify the user login interface 918, wherein a login request is created at the user login interface 918, and one or more login identifiers 938 may be generated and encrypted by workflow engine 904. In response to encryption, one or more encrypted login identifiers may be visually encoded as an authentication image 1040, which may be displayed on the display 916 of the client device 910.
[0231] In some embodiments, when the authentication identifier reader 930 can identify the authentication image 1040 within a predetermined distance from a predetermined location, the authentication identifier reader 930 can be configured to decrypt one or more login identifiers 938 from the authentication image 1040. In some embodiments, when the authentication identifier reader 930 can identify the authentication image 1040 at a predetermined time, the authentication identifier reader 930 can be configured to decrypt one or more login identifiers 938 from the authentication image 1040.
[0232] In some embodiments, one or more encrypted login identifiers may include encrypted content. In some embodiments, the authentication image 1040 may be a visual representation of one or more encrypted login identifiers. In some embodiments, the electronic device 920 may also include a camera configured to capture the authentication image 1040 of the display 922 of the client device 910.
[0233] In some embodiments, the authentication image 1040 of the display 922 of the client device 910 can be uploaded to the electronic device 920. In some embodiments, user identification data may be at least one of a username, email address, or password. In some embodiments, the electronic device 920 may also include an input sensor disposed on the display 922 of the electronic device 920, the input sensor sensing external input to submit an authorization 934 for a login request to the workflow engine 904.
[0234] In some embodiments, when one or more authenticated decrypted login identifiers 932 can be manually entered by the user into the computer system 936 of the client device 910, the authorization 934 of the login request can be sent to the workflow engine 904. In some embodiments, the computer system 936 of the client device 910 can be configured to prompt the user to enter user identification data into the computer system 936 of the client device 910.
[0235] In some embodiments, a system 902 is used for two-way two-factor remote user authentication. In some embodiments, an authentication image 1040 may be linked to a specific browser session. In some embodiments, the authentication image 1040 may be valid for a configurable duration, and the authentication image 1040 and user identification data may expire after the configurable duration. [The last sentence appears to be incomplete and unrelated to the preceding text.]
[0236] In some embodiments, the authentication image 1040 may be configured to be transmitted to the electronic device 920 at a given time, and the authentication image 1040 may be configured to be decrypted at a given time. In some embodiments, the authentication image 1040 may be configured to decrypt when decryption can be performed within a predetermined range at a predetermined location. In some embodiments, the authentication image 1040 may include geographic data.
[0237] Figure 10 Further description is based on some embodiments of this disclosure. Figure 9 A block diagram of system 902. In some embodiments, authentication image 1040 may include shared authentication image 1042. Shared authentication image 1042 may include decryption key 1044.
[0238] Figure 11 This is a block diagram of system 1102 described according to some embodiments of the present disclosure. In some embodiments, system 1102 may include a workflow engine 1104, and one or more authenticated decrypted login identifiers 1122 may be configured to be displayed on a display 1116 of electronic device 1110. System 1102 may also include electronic device 1110, which can communicate with workflow engine 1104 via a network. System 1102 may also include an authentication identifier reader 1120, which may be configured to decrypt one or more login identifiers 1128 from an authentication image when the authentication identifier reader 1120 recognizes an authentication image. System 1102 may also include an authorization 1124 for login requests to computer system 1126 accessing electronic device 1110, which may be configured to be sent to workflow engine 1104 via electronic device 1110.
[0239] In some embodiments, workflow engine 1104 may include one or more processors 1106. Workflow engine 1104 may also include at least one memory element 1108 configured to store instructions for controlling one or more processors 1106, and at least one memory element 1108 may retain login data. Electronic device 1110 may include one or more processors 1112 and a display 1116. Electronic device 1110 may also include at least one memory element 1114 configured to store instructions for controlling one or more processors 1112. Electronic device 1110 may also include a user login interface 1118 configured to receive user identification data for logging into computer system 1126 by electronic device 1110.
[0240] In some embodiments, in response to encryption, one or more encrypted login identifiers can be visually encoded as an authentication image, which can be displayed on the display 1116 of the electronic device 1110. In response to decryption, one or more decrypted login identifiers and user identification data can be configured to authenticate a user by verification via workflow engine 1104. The computer system 1126 may also include one or more login identifiers 1128 that identify the user login interface 1118, wherein a login request is created at the user login interface 1118, and at least one memory element 1114 can be configured to store one or more login identifiers 1128 and user identification data of the computer system 1126, wherein the one or more login identifiers 1128 may be generated and encrypted by workflow engine 1104.
[0241] Figure 12 This is a flowchart of a method described according to some embodiments of the present disclosure. In some embodiments, at 1210, the method may include receiving a request from a user login interface at a workflow engine to log in to a computer system from a client device. The user login interface may be configured to receive user identification data for the client device to log in to the computer system, which has one or more login identifiers that identify the user login interface, wherein a login request is created at the user login interface.
[0242] In some embodiments, at 1220, the method may include encrypting one or more login identifiers via a workflow engine. At 1230, the method may include, in response to encryption, visually encoding one or more login identifiers as an authentication image via the workflow engine. At 1240, the method may include, when an authentication identifier reader recognizes the authentication image, decrypting one or more login identifiers from the authentication image using an authentication identifier reader. At 1250, the method may include, in response to decryption, verifying one or more decrypted login identifiers and user identification data via the workflow engine to authenticate a user. At 1260, the method may include sending an authorization request to the workflow engine for access to a computer system on a client device. In response to a request from the client device, the workflow engine generates one or more login identifiers.
[0243] In some embodiments, the method may include prompting a user to input user identification data into the computer system of the client device to complete the login in response to sending authorization. In some embodiments, the method may include sending an authentication image from the workflow engine to the client device and displaying the authentication image on the display of the client device.
[0244] In some embodiments, the client device has an authentication identifier reader, and in response to decryption, the client device displays one or more authenticated decrypted login identifiers on its display. In some embodiments, authorization for the login request is sent to the workflow engine when one or more authenticated decrypted login identifiers can be manually entered by the user into the client device's computer system.
[0245] In some embodiments, the method may include sending an authentication image from a workflow engine to an electronic device and displaying the authentication image on a display of the electronic device. In some embodiments, the electronic device has an authentication identifier reader, and in response to decryption, the electronic device displays one or more authenticated decrypted login identifiers on its display. In some embodiments, authorization for a login request is sent to the workflow engine when one or more authenticated decrypted login identifiers can be manually entered by a user into the computer system of the electronic device.
[0246] Figure 13This is a flowchart describing a method according to some embodiments of the present disclosure. In some embodiments, at 1310, the method may include encrypting data via a workflow engine and visually encoding the data into a first authentication image via the workflow engine. At 1320, the method may include providing a second authentication image. At 1330, the method may include providing an electronic device having an authentication identifier reader. At 1350, the method may include verifying one or more decrypted data via the workflow engine to authenticate a user in response to decryption. At 1360, the method may include authorizing a login request for access to the computer system to be sent to the workflow engine. At 1340, providing may include decrypting the first authentication image using the authentication identifier reader of the electronic device when the authentication identifier reader recognizes the first authentication image and the second authentication image. In some embodiments, decryption is authorized via a decryption key of the electronic device. In some embodiments, the second authentication image is encrypted using data used to decrypt the first authentication image for dual second-factor authentication.
[0247] Within the scope of this invention, the authentication image includes any visual representation, such as a data matrix and / or a Cyphlens image.
[0248] In a preferred embodiment, multiple login identifiers are stored in at least one memory element. Within the scope of the invention, authorization is determined by at least one authentication factor, one of which is by using one or more login identifiers in system processing. For example, the system may utilize URLs, alphanumeric codes, logo images, timestamps, locations, one-time passwords, and / or other data to determine authorization.
[0249] Within the scope of this disclosure, user identification data includes, but is not limited to, the password, username, and / or email address of the computer server used to verify 2FA.
[0250] Within the scope of this disclosure, communications, electrical communications, electrical coupling and / or electrical connections include, but are not limited to, wired and / or wireless connections.
[0251] Within the scope of this disclosure, the workflow engine acts as a backend server. The authentication image is displayed on the monitor of the client device. The client device can be any electronic device capable of accessing the login interface of a remote computer system, including but not limited to websites. The electronic device is a user's mobile device, client device, and / or remote user device. The authentication image is read by a reader on the electronic device.
[0252] Within the scope of this disclosure, authorization is determined by a workflow engine based on at least one authentication factor, one of which is by using one or more login identifiers in system processing. For example, the system may use URLs, alphanumeric codes, logo images, timestamps, locations, one-time passwords, and / or other data and / or combinations thereof to determine authorization.
[0253] Within the scope of this invention, if one or more decrypted login identifiers displayed on an electronic device match one or more login identifiers on a client device, the existence of a match is determined by the user.
[0254] Within the scope of this invention, one or more login identifiers include, but are not limited to, any encrypted content such as Uniform Resource Locators (URLs), alphanumeric codes, logo images, timestamps, locations, one-time passwords, and / or other data and / or combinations thereof.
[0255] Additional description
[0256] Within the scope of this invention, the system includes an improved second factor, hereinafter referred to as a bidirectional or bi-directionally operating mutual 2FA, two-way 2FA, and / or bidirectional two-way 2FA, wherein the user proves ownership of the second factor to further authenticate with the server, and the server also provides further proof of its identity to authenticate the user.
[0257] The core of Cyphlens technology lies in the encryption and decryption of data. Content can be encrypted using symmetric keys, asymmetric keys, or a combination of both. When using asymmetric keys, the content can be additionally signed by the party encrypting it, and the signature is included in the encrypted content. When the encrypted content is decrypted by the user (and the signature is verified in the case of asymmetric keys), it can imply authentication between the two parties. Specifically, assuming symmetric key encryption, the encrypted content can include an encrypted timestamp, a unique alphanumeric code, and any other identifier of the encrypting party. For example, for a website, such an identifier could be the domain name associated with that website. When 2FA authentication is required, the following occurs: On the user's end, by decrypting the 2FA image-encrypted content (or verifying the signature if asymmetric key encryption is used), the user can assume that the remote party is legitimate because it has the correct key required to perform encryption (and / or signing). Furthermore, in the case of 2FA authentication for a website, the decrypted domain name can be visually verified by the user and compared with the domain name appearing in the browser's address bar, etc. (This step can also be automated by employing image processing and other technologies). On the other side (e.g., a web server), the user authenticates themselves by providing a unique alphanumeric code as part of the encrypted content. This alphanumeric code can be a one-time code. By providing such a code to the web server, the user proves that they have access to the encrypted material needed to correctly decrypt such code (what you possess), and therefore are a legitimate user.
[0258] In other words, only a legitimate party (e.g., a web server) can encrypt (and / or sign) such content for a user, and only a legitimate user can decrypt such content and provide a unique alphanumeric code as proof of correct decryption. This mutual authentication scheme can be used in various use cases, such as website logins with two-factor authentication. Specifically, for symmetric key encryption, the following may occur: a user provides his or her username (or any other unique identifier) to a remote party (e.g., a website). The remote party (e.g., the website) uses secret cryptographic material specific to that user to encrypt some content using existing cryptographic primitives and algorithms. As mentioned above, the encrypted content may contain a unique alphanumeric code, website URL, logo image, timestamp, and other information associated with the website or user, or both.
[0259] Encrypted content is visually encoded using QR codes, barcodes, data matrices, Cyphlens images, and / or any other visual representation. Any combination of these is also possible. For the current example, assume a Cyphlens image is used in this case. The Cyphlens image is then displayed to the user on the website. The user can decrypt the content using their specific secret cryptographic material, either using their mobile device's camera or by loading the Cyphlens image directly onto their mobile device. If decryption is successful (the user is a legitimate user), the decrypted information is displayed to the user on their mobile device, and the user can verify its correctness (e.g., website URL, logo, etc.). A unique alphanumeric code can also be displayed to the user. If all information appears correct, the user can submit 2FA authentication to the web server using gestures such as swiping on the mobile device's UI. Alternatively, the user can manually enter the unique alphanumeric code into the website page and submit it to the web server from the website.
[0260] In some aspects, the technology described herein relates to a system for two-way, two-factor remote user authentication, wherein the graphical user interface of the display of an electronic device has an input sensor disposed on the display. The input sensor senses external input applied from the outside. External input can include various types of input provided from outside the electronic device. External input can be any of various types of external input, such as through a user's hand and / or through a part of the user's body via a stylus; by way of example, embodiments are not limited thereto. As described above, external input from the user can be provided in various types to activate authorization of a client device's login request to a computer system. For example, user touch input can include, but is not limited to, pressing, swiping, and / or tapping on the display of the electronic device as a controller means of indicating whether the user wishes to continue the authorization process.
[0261] Once the 2FA step is successfully completed, the website prompts the user to enter their password to complete the login process. Many variations of the above sequence of events are possible. The order described above—user specifying username, then completing 2FA authentication, and finally entering their password—has several advantages. Specifically, because Cyphlens 2FA uses encrypted data that only legitimate websites can create, it can prevent all phishing attacks attempting to steal user passwords. Typically, phishing websites ask users for their email address, password, and 2FA code to steal their passwords.
[0262] Because users cannot authenticate the website (normal 2FA is not reciprocal like Cyphlens), they will enter all this information on the fake website, and their password will be stolen without their knowledge. Furthermore, without Cyphlens 2FA, performing a 2FA step before the password is useless, as the result is exactly the same: the password will be stolen. On the other hand, using Cyphlens 2FA, phishing websites will not be able to generate valid encrypted content that users can decrypt; therefore, unless the fake nature of the phishing website is exposed, it will never reach the password step described above.
[0263] In the above description, a Cyphlens 2FA image is displayed to users on the website. However, nothing prevents the Cyphlens 2FA image from being sent to users via SMS, other mobile applications (e.g., WhatsApp), email, or other means to complete the 2FA authentication process. Multiple channels can also be used simultaneously to add a layer of security.
[0264] In addition to the typical 2FA authentication functionality, Cyphlens 2FA also supports other advanced features based on factors such as collaborative positioning, duration, time of day, geolocation, and user sharing. Let's take a look at each of them.
[0265] Co-location: Cyphlens 2FA images can be linked to specific browser sessions. This means that if a user attempts to log in to a website from two different browsers or computers, they cannot authenticate on computer 2 using Cyphlens 2FA information decrypted on computer 1, and vice versa, unless explicitly allowed by the Cyphlens 2FA configuration. Because of this, Cyphlens 2FA also effectively prevents password sharing and 2FA code sharing, which is impossible on other people's computers.
[0266] Duration: The Cyphlens 2FA image is valid for a configurable duration after which the encrypted content becomes invalid and the image can no longer be decrypted. Furthermore, any information associated with the invalidated Cyphlens image becomes invalid as well. This means that if I decrypt a Cyphlens 2FA image before it becomes invalid and then attempt to use the decrypted information after it becomes invalid, the decrypted information will be invalid, and 2FA authentication will fail.
[0267] Time of day: Users can only decrypt Cyphlens 2FA images at specific times of day / before / after. For example, a user may receive a Cyphlens 2FA image via email at time t0, but can only decrypt the image and successfully complete 2FA authentication at time t1. The time of day during which Cyphlens 2FA images can be decrypted is programmable and configurable throughout the entire lifecycle of a Cyphlens 2FA image (even after its creation).
[0268] Geographic Location: A user can only decrypt a Cyphlens 2FA image if they are located at or within a specified distance of that location. This could mean that only a designated user can decrypt the Cyphlens 2FA image and complete 2FA authentication at that location. However, it could also mean that any user at that location can decrypt the Cyphlens 2FA image and complete 2FA authentication. This could represent the first instance of 2FA authentication to prove "where you are." Another approach is to include an identifier of the location directly in the 2FA Cyphlens image. Combinations of both techniques are also possible. The geographic locations from which a Cyphlens 2FA image can be decrypted and by whom is decrypted are programmable and configurable throughout the entire lifecycle of the Cyphlens 2FA image (even after its creation).
[0269] User Sharing: In a typical 2FA scenario, the 2FA authentication step is linked to a single user (the owner of the second factor – something you own). This creates a problem when a single 2FA-enabled account (e.g., an administrator account) needs to be used by multiple users. In this scenario, a user wanting access to the account needs to contact the user who owns the second factor and request a 2FA code or approval. This is a very poor and insecure user experience because the exchange of 2FA codes or authorizations needs to happen in real time when access to the account is needed. With Cyphlens 2FA, a user (owner) can decide to share their 2FA authentication with one or more users in parallel or sequentially over a period of time or a date interval. This allows these users to decrypt the owner's Cyphlens 2FA image and successfully complete 2FA authentication without any direct interaction with the owner. This is achieved by creating a shared image of the Cyphlens 2FA image, where the decryption key is associated with the Cyphlens image, not with a single user. Key distribution handles the rest.
[0270] Printed Paper: In typical 2FA applications, the technology is inherently digital. Cyphlens 2FA, on the other hand, can be extended to physical media (e.g., paper). For example, a 2FA step might be needed to decrypt sensitive information encrypted in a printed Cyphlens image. In this case, the second factor (what you possess) could be a second Cyphlens image printed on paper. To decrypt the first image using a user's mobile device, the user needs to place the second Cyphlens image (the second factor) near the first Cyphlens image they want to decrypt. The mobile device will detect and "read" both printed images, and the content of the first image can only be unlocked and displayed to the user if the second factor image can be decrypted. This allows the 2FA process to be performed offline, without any internet access or network connection. In this scenario, to "unlock" the content of the first Cyphlens image, the user must have physical access to the second factor printed Cyphlens image and must be able to decrypt this second factor Cyphlens image (possessing the decryption key). Dual second-factor authentication.
[0271] For example, this process can be implemented by encrypting the key required to decrypt the first cipher image within the second-factor Cyphlens image. Many other variations of this process are also possible, for example, when the second-factor Cyphlens image is printed and the first Cyphlens image is digital, or when a fully offline user experience is not required and internet access is available.
[0272] When describing elements of this disclosure or embodiments thereof, the articles “a,” “an,” and “the” are intended to indicate the presence of one or more elements. Similarly, the adjective “another,” when used to describe an element, is intended to indicate one or more elements. The terms “including” and “having” are intended to be inclusive, thus allowing for the possibility of additional elements besides those listed.
[0273] Although the present invention has been described in detail to a certain extent, it should be understood that this disclosure is made by way of description only, and various changes can be made to the details of the construction and arrangement of the components without departing from the spirit and scope of the invention.
Claims
1. A system for two-way, two-factor remote user authentication, comprising: Workflow engines, including: One or more processors; and At least one memory element, the at least one memory element being configured to store instructions for controlling the one or more processors, the at least one memory element retaining login data; A client device, which communicates with the workflow engine via a network, includes: One or more processors; At least one memory element, the at least one memory element being configured to store instructions for controlling the one or more processors; Displays; and A user login interface is configured to receive user identification data for the client device to log in to the computer system. The computer system has one or more login identifiers that identify the user login interface. A login request is created at the user login interface. The one or more login identifiers are generated and encrypted by the workflow engine. In response to encryption, one or more encrypted login identifiers are visually encoded as authentication images, which are displayed on the display of the client device; An electronic device, which communicates with the workflow engine via the network, includes: A display with a graphical user interface; One or more processors; At least one memory element storing the one or more login identifiers and user identification data of the computer system; and An authentication identifier reader is configured to decrypt one or more login identifiers from the authentication image when the authentication identifier reader recognizes the authentication image, wherein... In response to decryption, one or more decrypted login identifiers and the user identification data are configured to authenticate the user via the workflow engine, wherein... One or more authenticated decrypted login identifiers are configured to be displayed on the display of the electronic device, and The authorization for the login request to access the computer system of the client device is configured to be sent to the workflow engine via the electronic device.
2. The system for two-way two-factor remote user authentication of claim 1, wherein, The authentication identifier reader is configured to decrypt one or more login identifiers from the authentication image when the authentication identifier reader recognizes the authentication image within a predetermined distance from a predetermined location.
3. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication identifier reader is configured to decrypt one or more login identifiers from the authentication image when the authentication identifier reader recognizes the authentication image at a predetermined time.
4. The system for two-way two-factor remote user authentication according to claim 1, wherein, The one or more encrypted login identifiers have encrypted content.
5. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image is a visual representation of the one or more encrypted login identifiers.
6. The system for two-way two-factor remote user authentication according to claim 1, wherein, The electronic device has a camera configured to capture the authentication image of the display of the client device.
7. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image displayed on the client device is uploaded to the electronic device.
8. The system for two-way two-factor remote user authentication according to claim 1, wherein, The user identification data is at least one of a username, email address, or password.
9. The system for two-way two-factor remote user authentication according to claim 1, wherein, The electronic device has an input sensor disposed on the display of the electronic device, the input sensor sensing external input to submit the authorization for the login request to the workflow engine.
10. The system for two-way two-factor remote user authentication according to claim 1, wherein, When one or more authenticated decrypted login identifiers are manually entered by the user into the computer system of the client device, the authorization for the login request is sent to the workflow engine.
11. The system for two-way two-factor remote user authentication according to claim 1, wherein, The computer system of the client device is configured to prompt the user to input the user identification data into the computer system of the client device.
12. The system for two-way two-factor remote user authentication according to claim 1, further comprising generating a symmetric key during pairing using transport layer security before the authentication image is imported into the electronic device.
13. The system for two-way two-factor remote user authentication according to claim 1, further comprising public key infrastructure encryption of the one or more login identifiers and decryption of the one or more login identifiers from the authentication image.
14. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image is linked to a specific browser session.
15. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image is valid for a configurable duration, and both the authentication image and the user identification data become invalid after the configurable duration has expired.
16. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image is configured to be sent to the electronic device at time t0, and the authentication image is configured to be decrypted at time t1, where t1 t0.
17. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image is configured to be decrypted when decryption is performed within a predetermined range at a predetermined location.
18. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authenticated image contains geographic data.
19. The system for two-way two-factor remote user authentication according to claim 1, wherein, The authentication image includes a shared authentication image with a decryption key.
20. A system for two-way, two-factor remote user authentication, comprising: Workflow engines, including: One or more processors; and At least one memory element, the at least one memory element being configured to store instructions for controlling the one or more processors, the at least one memory element retaining login data; An electronic device that communicates with the workflow engine via a network, the electronic device comprising: One or more processors; At least one memory element, the at least one memory element being configured to store instructions for controlling the one or more processors; Displays; and A user login interface is configured to receive user identification data for the electronic device to log in to a computer system. The computer system has one or more login identifiers that identify the user login interface. A login request is created at the user login interface. At least one memory element is configured to store the one or more login identifiers of the computer system and the user identification data. The one or more login identifiers are generated and encrypted by the workflow engine. In response to encryption, one or more encrypted login identifiers are visually encoded as an authentication image, which is displayed on the display of the electronic device; and An authentication identifier reader is configured to decrypt one or more login identifiers from the authentication image when the authentication identifier reader recognizes the authentication image, wherein... In response to decryption, one or more decrypted login identifiers and the user identification data are configured to authenticate the user via the workflow engine, wherein... One or more authenticated decrypted login identifiers are configured to be displayed on the display of the electronic device, and The authorization for the login request to the computer system accessing the electronic device is configured to be sent to the workflow engine via the electronic device.
21. A method for mutual two-factor remote user authentication, comprising: At the workflow engine, a request for a client device to log in to a computer system is received from a user login interface, the user login interface being configured to receive user identification data for the client device to log in to the computer system, the computer system having one or more login identifiers that identify the user login interface, wherein a login request is created at the user login interface. In response to a request from the client device, the workflow engine generates one or more login identifiers; The workflow engine encrypts one or more login identifiers; In response to encryption, the workflow engine visually encodes the one or more login identifiers as authentication images; When the authentication identifier reader recognizes the authentication image, it uses the authentication identifier reader to decrypt one or more login identifiers from the authentication image; In response to decryption, the workflow engine verifies one or more decrypted login identifiers and the user identification data to authenticate the user; and The authorization for the login request to access the computer system of the client device is sent to the workflow engine.
Citation Information
Patent Citations
Encryption and decryption of visible codes for real time augmented reality views
US20150295715A1
Encryption and decryption of visible codes for real time augmented reality views
US20180167215A1
Context based management for secure augmented reality applications
US9183677B2
Augmented reality based privacy and decryption
US9251366B2
Head-mounted display apparatus with enhanced security and method for accessing encrypted information by the apparatus
US9330272B2