Mutual authentication system and method

JP2024540207A5Pending Publication Date: 2025-10-29ペドロ ペレス グランデ
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024525805
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-10-26
Filing Date
2022-10-24
Publication Date
2025-10-29

AI Technical Summary

Technical Problem

Existing human user authentication methods, such as those based on fingerprints, facial images, passwords, and external devices, are vulnerable to identity-based desires, easy imitation, and complex installation, leading to security risks and cumbersome management.

Method used

A cognitive authentication system using virtual keyboards with unique graphical features and user-specific rules, allowing users to authenticate through cognitive processes resistant to observation and recording attacks.

Benefits of technology

Provides secure, user-friendly authentication resistant to copying and imitation, reducing the risk of secret disclosure and maintaining security against phishing and recording attacks without requiring complex installations or external factors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method and system for mutual authentication, comprising: a virtual keyboard generation unit (210) for obtaining (110) a keyboard configuration (112) of a user (201) including graphic features (114), an arrangement (116) and keyboard generation rules (118) and for generating (120) a virtual keyboard (212) formed by keys (214) combined with the graphic features (114) in a certain arrangement (116) based on the keyboard generation rules (118); an input interface (230) for receiving (140) key selections (144) of a virtual keyboard (212); an authentication unit (240) for applying (160) user authentication rules (152) to the virtual keyboard (212), obtaining at least one correct key sequence (162), and authenticating (170) the user (201) if the key selection (144) is validated in relation to the correct key sequence (162).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates generally to the sector of network and computer security access, and more specifically to the sector of human user authentication systems on machines, servers or electronic devices of all kinds, without using biometric aspects of the user and without relying on external objects or elements. [Background technology]

[0002] Methods for authenticating human users implemented by computer systems or electronic devices, where the user verifies his or her identity in order to be able to perform some action on the system as a whole, electronic, are insecure for two important reasons, among others, since they are primarily based on a method of identification by the system (fingerprint, face image) and / or a shared secret between the user and the authentication system (password, PIN number, etc.): -For identity-based methods, the user does not necessarily indicate a desire to be authenticated. -Secrets are easily copied and imitated, and storing and managing secrets is cumbersome in terms of information leakage.

[0003] Other authentication systems, such as those based on external devices (tokens, cryptographic keys, disposable key generators, SMS, etc.), require complex installation, high cost of devices, and complex authentication schemes, among other drawbacks.

[0004] Existing inventions in the prior art that do not rely on external factors or biometrics are dominated by the use of passwords, which require the user to remember complex sequences of numbers, letters, and symbols that must be unique for each service that requires authentication. The amount of services of this kind used daily exceeds the capacity of the human brain, so users must use password managers (reliance on external factors) or centralized authentication processes (using the provider's authentication to use other services), practices that have their own set of inherent risks and privacy issues. There are several password alternatives that stand out for their visual convenience and appeal, but at a commercial level they are of very limited use, essentially limited to Android pattern unlock and the selection of a defined point in an image (a concept introduced by Windows 8 under the name "picture password").

[0005] The present invention describes a new authentication system that is easily adaptable to current electronic systems without significant costs, easy for users to use, and resistant to copying and imitation, since it is based on a set of cognitive processes known only to the user (cognitive abilities of estimation, recognition, transformation, and calculation, and automation of intelligent processes).As for the authentication methods using Android pattern unlock or selection of a defined point in an image, the method of the present invention achieves a similar level of convenience with a much better security level.

[0006] The proposed method uses a simple cognitive mechanism adapted to each user (precisely chosen by the user depending on his capabilities and the desired level of security), i.e. a mechanism subject to automated processing, making authentication faster and more secure, and less likely to share secrets. It also provides conscious authentication (a user cannot be authenticated without the desire to authenticate) and mutual authentication (a user clearly identifies the service to which he is authenticated). The proposed method is superior to existing methods, since it is resistant not only to viewing attacks (where the attacker observes the authenticated user) but also to recording attacks (where the attacker has the opportunity to record the various authentication sessions), and it presents a high level of defense against phishing attacks. Summary of the Invention

[0007] The present invention relates to a system and a method for mutual authentication. The invention is based on a mechanism for human user authentication to an electronic device, based on one or more images, typically displayed on a screen. The images show a kind of keyboard, the keys or elements of which have different graphic characteristics, and the user can provide the system with the correct result that allows authentication according to a set of stored rules.

[0008] The nature of the processing performed by the user in the authentication process (computation of a result) makes the mechanism secure not only against observation attacks but also against recording attacks. The dynamic nature of the results and the wide range of possible combinations allow the user to use the same process for different systems without affecting security.

[0009] The graphical nature, mechanical nature of the computations, and the steps performed by the user make the process complex to share with third parties (preventing dangerous sharing), yet easy and fast to use for users after brief training.

[0010] As for other authentication methods, it offers much higher security than numeric PIN numbers and passwords without relying on external factors and does not require high implementation costs (biometrics, location, disposable keys, etc.) Similarly, by not requiring any biometric data, it is completely anonymous and respects the process of identifying data.

[0011] Being a horizontal solution, the possible applications are endless and it can be used in any situation where it is possible to use PIN numbers or passwords without them presenting security issues, either in purely digital environments (e.g. PCs, mobile devices), physical environments (e.g. security entry doors of buildings), virtual environments (e.g. role within roles), or even mixed environments (e.g. augmented reality glasses on touch surfaces or generic keyboards).

[0012] The present invention features a method and system for enabling a user to be authenticated in electronic systems (computers, sales terminals, web pages, mobile devices, public computers, ATMs, etc.) through a single interface using the user's cognitive abilities in the authentication process. To this end, the authentication system displays to the user a sort of keyboard (called a virtual keyboard or virtual body) of small size (e.g., a rectangular array of 2 elements by 5 elements). Each of these composed elements (called keys or parts) represents different variations of a set of symbols or graphic features with different arrangements and rules that the user knows.

[0013] The user observes a virtual keyboard and can first estimate whether the keyboard is trustworthy. The user then selects a sequence of keys that depends on a sequence of transformations for the displayed virtual keyboard, which includes an external element in the computation of this sequence. The system checks whether the entered sequence is correct, thus validating the user's desire to be authenticated by the system. The system can display a certain number of iterations at the beginning of the authentication, or repeat the process, thereby revalidating the user after some time, in order to improve the judgment of the user's veracity.

[0014] A first aspect of the present invention relates to a mutual authentication method, which includes the following steps. - obtaining a keyboard configuration of an authenticated user, the keyboard configuration including a plurality of graphic features, a plurality of variations or arrangements of the graphic features, and a set of keypad generation rules. - generating at least one virtual keyboard, each virtual keyboard being formed by a plurality of keys incorporating a combination of graphic features arranged in a particular arrangement, the graphic features and arrangements used in each key being selected from a user's keypad configuration based on keyboard generation rules. - displaying at least one virtual keyboard to the authenticated user. - receiving a user input corresponding to a key selection of the respective virtual keyboard. The user input may be expected to be received a predetermined maximum time after at least one virtual keyboard is displayed. The key selection of each virtual keyboard may include any one or more keys. For example, if four virtual keyboards are displayed, the user input may consist of a selection of a key of each virtual keyboard, or a selection of two keys of the second and fourth virtual keyboards. - Obtaining user authentication rules. The keyboard configuration and the user authentication rules may be stored in the same entity or device (eg, memory, database) or in different devices / entities. - applying the user's authentication rules to at least one virtual keyboard to obtain at least one correct key sequence. - authenticating the user if the user-entered key selection is validated in relation to the correct key sequence. An example of a validation function is an exact match (where the key selection is validated if it matches the correct key sequence). However, other validation functions may also be used, e.g. a hash resulting from concatenating both sequences is a predefined sequence.

[0015] A second aspect of the invention relates to a mutual authentication system comprising a set of elements arranged to perform a mutual authentication method, the system comprising a virtual keyboard generation unit, an input interface, an authentication unit and optionally an information display device arranged to display at least one virtual keyboard, which may for example comprise one or more screens or projectors for displaying the virtual keyboard to a user.

[0016] A third aspect of the invention relates to a non-transitory computer-readable storage medium including program instructions stored on the medium that, when executed on a processor, cause the processor to perform a method of mutual authentication.

[0017] Since the symbols and rules are preselected by the user, this means protection against masquerading attacks ("masquerading" and "phishing"). Since the combinations of these symbols and rules, and the final selection of that particular user (which may be as specific as selecting two keys out of ten available), are very numerous, this means protection against recording, shoulder-surfing, guessing attacks, etc. Since the process of generating the virtual keyboard and verifying the user input sequence is distributed among different computer systems and can be applied to cryptographic techniques, this means protection against information leakage, data theft, reliance on third parties, etc. Since the user's calculation of the correct sequence (the guessing process) becomes fully intelligent and employs cognitive processes such as automation, this means protection against theft and unintentional disclosure of secrets, resistance to coercion, and prevention of dangerous configurations.

[0018] The present invention can be used in many situations where an authentication system is required and the dynamic ability to generate corresponding virtual keyboard graphics is possible, making it ideal for electronic systems that include a screen, such as personal computers, public use terminals, automated teller machines, etc. The secure nature of this mechanism against viewing and recording attacks makes it unnecessary to introduce results in a protected manner (e.g. while keeping the introduction of a PIN number to a payment terminal secret), and is therefore ideal for this type of environment.

[0019] Unlike other more technically complex systems, the proposal presented here allows for easy adoption and integration with existing solutions by not requiring complex development or substantial changes to the system to be updated. Depending on the measures expected by users in terms of convenience and acceptability, the method can be established as the new standard by replacing the current use of PIN numbers and passwords.

[0020] By introducing a new authentication mechanism, i.e. one that the user can resolve, the method can be considered as a second effective authentication factor for platforms such as payment processing, meeting new legal requirements and replacing more expensive and complex mechanisms such as voice recognition or some biometric measures.

[0021] Being such a horizontal product, the application sectors are practically any sector requiring any level of security in authentication processes, especially in accessing digital platforms, with special attention to banking, purchasing, online credit cards, etc. Likewise, being easily implemented in a purely physical product, the applicable sectors extend to physical security, such as either facility or building access security (today authentication is usually done by a fixed PIN number on a metal keypad or similar mechanism), credit card usage, and all processes requiring secure authentication.

[0022] The present invention offers the following advantages over prior art methods:

[0023] - The risk of disclosure is close to zero, since the number of configurations, graphic features and resulting permutations or variations of graphic features is almost infinite (a very reduced risk compared to other methods).

[0024] - The possibility of choosing between these configurations, graphic features and multiple possible variations (which may be designed by the user) that in some way belong to the secret part.

[0025] -May contain distracting elements (features that are not critical to resolution but which further impede artificial intelligence or violence analysis).

[0026] The user's ability to select all of the -elements provides important anti-phishing protection, since only a valid authentication code system knows (by having the instructions) how to create the correct virtual keyboard that the user can recognize.

[0027] The flexibility of these configurations allows for even different forms of virtual keyboards, for example even 12 keys in the form of a clock arranged around the circumference of a circle or the like.

[0028] - The use of different cognitive mechanisms (not only addition, as the human brain is capable of), and among them visual and spatial mechanisms (color, offset), allows for automation (meaning performing certain steps very quickly after training, without the need to verbalize them), another key aspect of cybersecurity: increasing the difficulty of communicating secrets to others.

[0029] -There are many possibilities for transformations: math, logic, color comparison, translation of position, complementary shapes. Thus, transformation rules can be as simple as color lookup and sum (simpler than, for example, squaring a number), yet more secure (by having a very wide range of possible choices and transformations of underlying principles).

[0030] -The sequence of steps that the user needs to reproduce is stored (in a specific part of the system) so that it can be validated that the user's resolution and the machine-calculated resolution are the same, thus preventing the storage of passwords that would allow a lower risk of being leaked.

[0031] -User input is simple enough that it can be generated by directly selecting keys on a touchscreen (without necessarily having associated numbers), but is also compatible with other methods (traditional keyboard, physical buttons, voice, etc.).

[0032] - By sourcing the key selections of each virtual keyboard to form the final result (e.g., two keys per virtual keyboard), it allows dynamic security levels (e.g., a PIN number may have more or fewer digits at the supermarket than at the cashier).

[0033] -It then becomes possible to incorporate graphic elements / graphical features of the virtual keyboard, which further increases the level of security:

[0034] - Maintains overall security against keylogger and multiple recording attacks, since no external components (e.g. a calculator; some other methods have been proposed to mix the secret with the hash) are required.

[0035] The possibility of maintaining a single instance of the central user's critical parts (authentication unit, virtual keyboard generation unit) as an identity provider allows the rest of the system not to require a high security level.

[0036] This allows the authentication process to be delegated to a third party without security risks (e.g. in a non-secure environment, on a separate web page during a video conference, or in a public display). [Brief description of the drawings]

[0037] Some drawings which are useful for a better understanding of the invention and which relate explicitly to embodiments of the invention will now be described very briefly as non-limiting examples of the invention. [Figure 1] 2 shows a flow diagram of a mutual authentication method according to an embodiment of the present invention. [Diagram 2] 1 illustrates a mutual authentication system according to an illustrative embodiment of the present invention. [Figure 3A] ~ [Figure 3I] 1 shows different implementations of a mutual authentication system. [Figure 4A] ~ [Figure 4M] 4 shows different examples of virtual keyboards used in the authentication process. [Diagram 5] 1 illustrates an authentication process using four virtual keyboards. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0038] 1 shows a flow diagram of a mutual authentication method 100 according to an embodiment of the present invention. The mutual authentication method 100 includes the following steps.

[0039] - Obtaining 110 a keyboard configuration 112 of the authenticated user. The keyboard configuration 112 includes a number of graphic features 114, a number of arrangements 116 of the graphic features 114, and keypad generation rules 118.

[0040] - generating 120 at least one virtual keyboard, each virtual keyboard being formed by a number of keys incorporating a combination of graphic features 114 arranged in a particular arrangement 116. The graphic features 114 and the arrangement 116 used on each key are selected from the user's keypad configuration 112 on the basis of keyboard generation rules 118.

[0041] - displaying 130 at least one virtual keyboard to the authenticated user. The virtual keyboard is preferably displayed in whole or in part on one or more screens (e.g. if the virtual keyboards are shown on a single small sized screen, e.g. the display of a smartwatch, the user may be moved by the display so that he can see one virtual keyboard or different parts of different virtual keyboards). Alternatively, the virtual keyboard may be displayed on paper or projected onto a surface by a projector or any other means of rendering information to a user.

[0042] - receiving 140 a first user input 142 corresponding to a key selection 144 of the respective virtual keyboard made by the authenticated user. Optionally, the process may be repeated as shown in the dashed line to generate 120 and display 130 several virtual keyboards (for example, five virtual keyboards generated and displayed as one) in succession, receiving 140 a first user input 142 corresponding to each iteration, and optionally obtaining 110 a user's keypad configuration 112 in each iteration. With these iterations, the virtual keyboard displayed may depend on the previous input. For example, each virtual keyboard may have two key selections, the first selection (first user input 142 including the key selection) is used to calculate the solution, and the second selection (second user input 106) is used to configure the next keyboard, for example the second selection is selected as red, and the next keyboard generated should have red on the first key. Alternatively, the step 104 of obtaining the second user input 106 may be performed immediately before or after the step 140 of receiving the user input. This strengthens mutual authentication, so that the user can select (by second user input 106) any features that are coupled or incorporated into the keyboard generation rules 118, thereby allowing the user to confirm the validation of the authentication system.

[0043] - Step 150 of obtaining user authentication rules 152 .

[0044] - A step 160 of applying the user authentication rules 152 to at least one virtual keyboard in order to obtain at least one correct key sequence 162 .

[0045] - authenticating 170 the user if the key selection 144 of the first user input 142 is validated in relation to the correct key sequence 162. For example, as shown in the embodiment of Figure 1, the key selection 144 may be validated if it matches the correct key sequence 162.

[0046] In the sequence, some of the steps may be changed with respect to the order shown in the flow diagram of Fig. 1. Thus, for example, the step 150 of obtaining user authentication rules may be performed before, simultaneously with, or after the step 110 of obtaining a user keyboard configuration. For example, if the user keypad configuration 112 and the user authentication rules 152 are stored in the same data storage device, both data can be retrieved simultaneously by accessing such data storage device. Also, the step 160 of applying the user authentication rules 152 to at least one virtual keyboard may be performed before, simultaneously with, or after the step 130 of displaying at least one on-screen virtual keyboard.

[0047] Optionally, the mutual authentication method 100 may include any of the following steps shown within dashed lines.

[0048] - An initial step 102 of obtaining the identity of a user who is authenticated prior to a step 110 of obtaining the user's keypad configuration 112.

[0049] - Step 104 of obtaining a second user input 106 and using said second user input 106 so that at least one of the virtual keyboards 212 is generated based on the keyboard generation rules 118. For example, the keyboard generation rules 118 may specify that the generated virtual keyboard must include the character selected by the user in the second key. In this case, the second user input 106 may include the selection of said character. Thus, if the user selects, for example, the character "B" as the second user input 106, the generated keyboard must include the character "B" in the second key. If not, the user may know that the authentication system is not genuine. The second user input 106 may be provided at any part of the process once or several times (e.g. iteratively) for use in generating any virtual keyboard. For example, the second user input 106 could be provided to the account together with the user identification in step 120 of generating the virtual keyboard (or at a time before or after). Or the second user input 106 may be provided iteratively in each iteration (dashed line) where a different virtual keyboard is generated in succession. In this case, the second user input 106 may correspond to one or more virtual keyboard key selections that will be used to generate the virtual keyboard of each successive iteration (in the previous example, the user would select a key incorporating the letter "B").

[0050] - A step 130 of displaying or presenting at least one virtual keyboard (eg on one or more screens) to the authenticated user.

[0051] A mutual authentication system 200 according to an embodiment of the present invention is shown in Fig. 2. The mutual authentication system 200 includes a virtual keyboard generating unit 210, an input interface 230, and an authentication unit 240. In one embodiment, the mutual authentication system 200 further includes an information display device. The information display device may include at least one display 220, for example.

[0052] The virtual keyboard generation unit 210 is configured to obtain the keyboard configuration 112 of the authenticated user 201 as described in steps 110 and 120 of FIG. 1 to generate at least one virtual keyboard 212 .

[0053] At least one display 220 is configured to display at least one virtual keyboard 212 as described in step 130 of Fig. 1, with each virtual keyboard 212 being formed by a plurality of keys 214. In the example of Fig. 2, the mutual authentication system 200 utilizes a single display on which two virtual keyboards are displayed. However, the mutual authentication system 200 may include any number of displays 220, and each display 220 may in turn display any number (1 to n) of virtual keyboards 212.

[0054] The input interface 230 is configured to receive a first user input 142 corresponding to a key selection 144 of the respective virtual keyboard 212 made by the user 201 as described in step 140 of FIG. 1. In one embodiment, the display 220 (or displays) may be a touch screen and the input interface 230 would comprise such a touch screen. In this case, the key selection 144 is made by the user 201 touching / pulsing on the touch screen 220 a selected key 214 from the respective virtual keyboard 212 displayed to authenticate the system. In other embodiments, the input interface may include a physical keyboard to input the key selection, a microphone using voice recognition software to input a spoken user selection, or almost any type of interface capable of receiving a selection of a key 144 by the user 201.

[0055] The user keys 144 may be selected in a number of ways, i.e. by directly selecting the keys themselves or affine elements (e.g., keys on a physical keyboard that represent some property, such as letters, numbers, or colors), by removing keys, by reordering keys, by merging / combining keys, or by other processes that result in a sequence of keys or values ​​of some property defined in a particular order. Keys may also be selected using other kinds of interfaces, for example using gestures (e.g., by pointing at a selected key identified by an image recognition camera), or using a voice interface (by voice recognition where the user verbally utters a key selection 144), among other interfaces.

[0056] Based on the configuration of the authentication rules 152 , the user may be required to select one, two, or more keys 214 of each virtual keyboard 212 displayed on the display 220 .

[0057] For example, the user 201 may press keys "2" and "8" on the upper virtual keyboard 212 (i.e., keys on which the numbers 2 and 8 are displayed) and "5" and "0" on the upper virtual keyboard 212 (i.e., two keys 214 on each virtual keyboard 212 need to be selected). Based on the authentication rules 152, the order of selection of the keys 214 may be taken into consideration for authentication. In this case, it would not be the same to first select key "2" on the upper virtual keyboard 212, then select key "8", then first select key "8", then select key "2".

[0058] The authentication unit 240 is configured to perform steps related to user authentication upon receiving the key selection 144 of the user 201 (steps 150, 160, and 170 in FIG. 1). Specifically, the authentication unit 240 obtains the authentication rules 152 from the user 201, and obtains at least one correct key sequence 162 by applying such authentication rules 152 of the user 201 to at least one virtual keyboard 212 generated by the virtual keyboard generating unit 210. Finally, the authentication unit 240 authenticates the user 201 if the key selection 144 of the first user input 142 is validated in relation to the correct key sequence 162 (e.g., the first user input 142 completely matches the correct key sequence 162). If the key selection 144 is not correctly validated (e.g., the key selection 144 does not match the correct key sequence 162 at all), the user 201 is not authenticated (similar to not introducing the correct PIN number expected of the user). Finally, it is responsible for outputting the authentication result 242. The result can be positive (correct authentication) or negative (failed authentication).

[0059] The mutual authentication system 200 may comprise a user identification unit 202 configured to obtain 102 an identification 204 of a user 201 to be authenticated. For example, the identification 204 may include the user 201 entering a username and / or a password by means of a keyboard. Using the username and / or the password, the mutual authentication system 200 may identify the user 201. The identification 204 of the user 201 is received by the user identification unit 202. The user identification unit 202 transmits the identification 204 to the virtual keyboard generation unit 210 and the authentication unit 240.

[0060] The virtual keyboard generation unit 210, once conveniently identified, may be configured to obtain the keyboard configuration 112 of the user 201 by accessing an external database 211 (e.g. on a remote server) or an internal memory 213 (a memory or data storage medium forming part of the mutual authentication system 200) to obtain the identified user's keyboard configuration 112. The database 211 or memory 213 may contain multiple keypad configurations 112 corresponding to different users. In this way, user identification allows access to the appropriate entries in the database or memory 213 corresponding to the identified user.

[0061] Once identified, the authentication unit 240 may be configured to retrieve the authentication rules 152 of the user 201 by accessing an external database 241 (e.g., on a remote server) or a memory 243 (e.g., flash memory, hard drive, or any other data storage medium) internal to the system. The data storage medium (e.g., database 211 or memory 213) utilized to store the keyboard configuration 112 may be the same storage medium in which the authentication rules 152 are stored. For example, the keyboard configuration 112 and the multi-user authentication rules 152 may be stored in a single memory or database either external to the system (e.g., located on a remote server) or internal to the system.

[0062] The elements constituting the system may form part of the same electronic device or may be distributed in different electronic devices. In the first case, the mutual authentication system 200 may be implemented in any electronic device including an input interface 230, a control unit or processor capable of processing data (e.g. a mobile device, a computer, an electronic tablet, a smartphone, a processor integrated in any electronic circuit, etc.), and optionally a display 220 (or any other physical or virtual support on which a user is shown to authenticate a set of keyboards). Thus, the different components of the system (such as the user identification unit 202, the virtual keyboard generation unit 210, and the authentication unit 240) may be logical units integrated in a processor or controller of the electronic device.

[0063] For example, as shown in Fig. 3A, the mutual authentication system 200 may be implemented in a computer 310. The computer 310 comprises a monitor 312 (having a display function 220), a keyboard 314, and / or a mouse (having an input interface function 230), a processor (including a user identification unit 202, a virtual keyboard generating unit 210, and an authentication unit 240), and a hard disk on which the keyboard configuration 112 and authentication rules 152 of the user 201 (and optionally other users) are stored. Alternatively, the keyboard configuration 112 and the authentication rules 152 may be stored in a remote storage medium, such as a database in an external server, and accessed by the computer via a communication unit, whether wired or wireless.

[0064] 3B shows an example where the mutual authentication system 200 is implemented in a smartphone 320. In this case, a touch screen 322 of the smartphone 304 has a display function 220 and an input interface 230. In this case, the authentication result 242 obtained by the mutual authentication system 200 may be used, for example, to unlock the smartphone, or in general for any operation performed on the smartphone that requires authentication of the user 201.

[0065] The mutual authentication system 200 may also be implemented in many other electronic devices, such as a smartwatch 323 (FIG. 3C) for authenticating user actions, an automated teller machine 324 (FIG. 3D) for withdrawing cash, a point-of-sale terminal for card payments (FIG. 3E), or an access control system 326 (FIG. 3F) for accessing public / private spaces or for opening cabinets or lockers (e.g. in a gym).

[0066] The electronic devices (310, 320, 323, 324, 325) shown in Figures 3A-3E include a display 220 for displaying a virtual keyboard 212 (or multiple virtual keyboards).

[0067] However, the electronic device, the access control system 326, shown in FIG. 3F does not have a display 220. In this case, it shows a virtual keyboard 212 (or multiple virtual keyboards, if there are several), printed, for example, on a cardboard or paper sheet 327. The virtual keyboard generation unit 210 of the mutual authentication system 200 generates the virtual keyboard 212. The virtual keyboard 212 is printed on a sheet 327 using a printer and placed adjacent to the access control system 326 or a door 328 controlled by the access control system 326, for example glued to a wall. The virtual keyboard 212 will indicate one or more correct key sequences 162 that a user needs to enter using an input interface 230 (for example a keyboard) to open the door 328. This virtual keyboard 327 could be periodically replaced, for example printed with a new virtual keyboard instance 327 to broadcast a third-party observation attack every day or at a specific time. In this embodiment, the mutual authentication system 200 could be easily implemented in an already existing access control system 326 that does not have a display 220.

[0068] The authentication unit 240 may be configured to obtain a number of correct key sequences 162 by applying the authentication rules 152 of the user 201 to at least one virtual keyboard 212 .

[0069] When there are multiple correct key sequences 162, each correct key sequence 162 may be associated with a different identity, i.e., a different user. In this manner, authentication unit 240 may be configured to identify a user within a set of users based on the correct key sequence 162 that the user entered as his or her key selection 144.

[0070] In the example of FIG. 3F, each user may have a different associated authentication rule 152 such that application of the authentication rules 152 of different users of the same virtual keyboard arrives at different correct key sequences 162. In this way, the correct specific key sequence 162 entered has not only the user authorized to open the door but also the user identified in the user group. Thus, assuming for example that the correct key sequence 162 is keys {5,2,8} for user 1 and keys {7,3,1} for user 2, if an unauthorized user authenticated with the access control system 326 does not know which key to select because the authentication rule 152 to be applied is unknown, the system will not allow access. If an authorized user enters keys {7,3,1}, the mutual authentication system 200 will open the door 328 because the key selection 144 was validated in association with one of the correct key sequences 162, i.e., the correct key sequence 162 corresponding to user 2. Furthermore, the system can identify which user has access, in this case user 2. This dual authentication and identification feature may be useful, for example, to control worker access to a work area (e.g., a laboratory); authentication would ensure that the user is an approved worker for access to the material, and identification would be able to identify the particular user who has gained access.

[0071] Having multiple correct key sequences 162 may also be utilized for the authentication unit 240 to authenticate the user 201 based on the correct key sequence 162 based on different authentication levels, with the key selection 144 being validated in relation to the correct key sequence 162. For example, the first authentication level may be correct authentication and the second authentication level may be warning authentication. Authentication with different levels may be useful in situations where additional aspects require the authentication itself to be known, such as when a dangerous or warning situation exists. Thus, the cashier may allow access to the safe with a first authentication level (first correct key sequence 162) or with a second authentication level (second correct key sequence 162), with the first authentication level including correct authentication and the second authentication level including warning authentication. Warning authentication could be utilized in cases where the user is threatened.

[0072] In the example shown in Figure 3G, the mutual authentication system 200 is implemented in an electronic device 329 that includes a virtual keyboard 212 and multiple displays 220. Specifically, each screen 220 displays the keys 214 of the virtual keyboard 212. The keys 214 are arranged in an array of three rows and three columns to form the virtual keyboard 212. The displays 220 of the electronic device 329 are tactile, thus forming an input interface function 230. A user makes a key selection 144 by interacting (e.g., pulsing) with the displays 220 on which the keys 214 are displayed, thereby minimizing the hardware components required for authentication.

[0073] In the example shown in Fig. 3A-3G, the elements of the mutual authentication system 200 may form part of a single electronic device. However, the elements of the mutual authentication system 200 may be distributed in different entities or electronic devices. For example, as shown in Fig. 3H, the mutual authentication system may comprise a client device 330 and an entity (e.g. one or more servers) external to the client device 330, connected for example via the Internet. The client device 330 is an electronic device or entity that seeks to authenticate a user 202, for example a computer or a smartphone (authentication may be requested by an application running on the electronic device). According to the example of Fig. 3H, the client device 330 receives a user identification 204 and requests a virtual keyboard generation server 340 (having the functionality of the virtual keyboard generation unit 210) to generate at least one virtual keyboard 212. Upon reception, the client device 330 is displayed on a display 220 (for example a display of a device on which a web application is running). When the client device 330 receives the key selection 144 from the user 201, the client device 330 transmits at least one generated virtual keyboard 212, the user identification 204, and the key selection 144 by requesting authentication of the user 201 to the authentication server 350. The authentication server 350 (having the functionality of the authentication unit 240) transmits a result 242 of the authentication to the client device 330. The client device 330 acts based on the result 242 of the authentication, for example blocking access to the user in case of a failed authentication.

[0074] In this way, the client device 330 authenticates the user without storing locally any information from the user 201 that may be compromised. Such information (e.g., keyboard generation rules or authentication rules 152 defined for the user 201) is securely stored in the remote servers 340 and 350. Thus, the authentication is secure without possible theft of the compromised information of the user 201 even if the client device 330 is attacked. In other possible embodiments, the system may be implemented in a greater or lesser number of entities or devices. For example, the display 220 may be located in a separate device outside the client device 330. In another example, the client device 330 may communicate with a single server having virtual keyboard generation and authentication functions (i.e., the virtual keyboard generation server 340 and the authentication server 350 may be the same entity).

[0075] The different functions of the authentication unit 240 may be distributed among various devices, for example a first device responsible for applying the authentication rules to obtain the correct key sequence, and a second device responsible for validating the key selection in relation to the correct key sequence to authenticate the user. Thus, in the example of Fig. 3I (very similar to the example of Fig. 3H), the client device 330 transmits to the authentication server the user identification 204 to be authenticated and the virtual keyboard 212, but may not transmit the user key selection 144. The client device 330 receives the correct key sequence 162 generated by the authentication server 350 and validates the key selection 144 in relation to the correct key sequence 162 to authenticate the user 201.

[0076] Several examples are shown showing various generated virtual keyboards utilizing different graphic features 114, arrangements 116, and keyboard generation rules 118. The authentication process is based on one or more images (virtual keyboard 212) displayed on one or more displays 220. Each image shows several pieces (keys 214) with similar but different visual characteristics, each piece showing a different graphic feature, and the user 201 may set rules to arrive at a result using the graphic features. The result is entered by the user 201 using the same display (if tactile), keyboard, or other data entry system arranged for input.

[0077] 4A, for example, the virtual keyboard 212 is formed by a set of ten keys 214, but the virtual keyboard 212 may be composed of any number N of keys 214, where N≧2. In this example, the keys 214 are grouped into a rectangular array of two rows and five columns. However, the keys 214 may be grouped in a number of shapes (e.g., circular, rectangular, freeform) as defined by the keyboard generation rules 118 of the keypad configuration 112 of the corresponding user 201. In this example, the keys 214 could be arranged in, for example, a circle, a matrix of five rows and two columns, or any other suitable arrangement.

[0078] Each key 214 is configured according to its combination of graphic features 114 and arrangements 116. In the example of Figure 4A, the following graphic features 114 and arrangements 116 are considered: -Graphic Features: ~Number 402 (0~9) ~Vowel 404 (a, e, i, o, u) ~Consonants 406 (b, c, d, f, g, h, j, k, l, m, n, p, q, r, s, t, v, w, x, z) ~Colors (five colors: red, blue, green, yellow, black). The graphic feature blue is indicated using a slanting beam on the right hand side (e.g. numbers 2 and 7), yellow is indicated using a right-hand upward beam (e.g. numbers 1 and 6), red is indicated by vertical scratching, black is indicated by horizontal scratching, and green is indicated by a filled-in dot. Each key 214 may have two different arrangements 116 of graphic features 114: ~The left side shall be two-thirds of the total height and width of the key, and the right third shall be vertically arranged with three intervals of one-third of the height each, and shall contain three letters of a prescribed shape (one vowel above and two consonants below). ~The same proportions on the right side, and three intervals on the left side.

[0079] Some graphical features may include sub-features of the graphical feature, such as size and color. Thus, the graphical feature 114 may be formed by a primary feature that defines the shape of the graphical feature 114, and secondary features or sub-features that define characteristics of the primary feature, such as the size or color of the primary feature. Thus, in the example of Figure 4A, the primary feature "9" has the color black as a secondary feature. If the primary feature "9" could be displayed on a key 214 having a variety of different sizes, each of the possible sizes would be a secondary feature of the primary feature.

[0080] The arrangements 116 may be considered individually at the graphic feature level 114. Thus, rather than considering two different key arrangements in the example of Figure 4A, each graphic feature 114 may be considered as having several different arrangements.

[0081] The numbers 402 have two possible arrangements within the key 214, either to the right or to the left of the key 214.

[0082] - The vowels 404 have two possible arrangements within the key 214: at the top right or at the top left of the key 214.

[0083] - The consonant 406 has four possible arrangements within the key 214: center right, center left, bottom right, and bottom left of the key 214.

[0084] Another possible virtual keyboard 212 is shown in Figures 4B-4M.

[0085] The virtual keyboard 212 of Fig. 4B consists of ten keys 214 grouped into two rows and five columns. Each key 214 is formed by a number 402 and two letters 408 (vowels or consonants). The number 402 occupies the entire height and half the width of the key, and the two letters 408 are arranged with the right side positioned in two vertically positioned half-height holes.

[0086] In Fig. 4C, the virtual keyboard 212 is formed by a number of keys 214. Each key 214 includes several graphic features 114, namely a numerical element 412 contained in a rectangle of a certain color (e.g., green background shown with dashed rays), four edges 414 (represented by rectangles) and four vertices 416 (represented by smaller squares). The numerical elements 412 are arranged in a certain arrangement 116 in the key 214 out of several possible arrangements (e.g., centered arrangement, arrangement in the upper left corner, arrangement on the left side). The edges 414 and the vertices 416 may also have multiple arrangements as seen in Fig. 4C, and the arrangement may include a rotation of the graphic features 114 (e.g., two edges 414 are shown in a horizontal arrangement and two edges 414 are shown in a vertical arrangement shown rotated by 90°). Furthermore, the edges 414 and the vertices 416 may take different colors as a secondary feature. In this example, considering that the numbers are shown in white and black, the color red is shown with vertically slanted rays, the color yellow is shown with slanted rays to the bottom right, the color cyan is shown with horizontal rays, and the color blue is shown with vertical scratching.

[0087] In the virtual keyboard 212 of FIG. 4D, the key 214 includes two numeric elements 412 ("7" and "3" having different sizes and different colors, respectively), two text elements 418 (letters "A" and "Z" having a background of a given color), and two rectangles 420. The numeric elements 412 are positioned in any of the corners, so that they assume 12 different configurations (considering only the numeric elements 412). Similarly, the rectangles 420 and the text elements 418 may have multiple arrangements within the key, which increases the number of possible combinations of the graphic features 114 to generate the key 214. Within the arrangement, the rectangles 420 are also considered rotated (some rectangles are displayed in a horizontal arrangement, others vertically).

[0088] In the example of FIG. 4E, the virtual keyboard 212 is composed of ten keys 214 arranged in two rows and five columns. Each key 214 incorporates a number element 402 contained within a rectangle with a white rectangular border 422 and a black background (primary graphic feature), which may require different secondary features, i.e., one of five possible colors in even-odd pairs, and one of two available sizes (again depending on the color). The numbers 402 may be arranged differently in relation to the border 422 (e.g., centered, corner, or side). Thus, there are numerous graphic feature combinations 114 (including primary and secondary features) and arrangements 116 for generating the virtual keyboard 212.

[0089] The virtual keyboard 212 of FIG. 4F is composed of four keys 214 arranged in a row. Each key 214 includes a core element composed of a number 402 (in this example showing the number "7") arranged similarly to the first key 214 of the virtual keyboard 212 in the example of FIG. 4A, and three letters 408 (in this example "A", "J", and "X"). The central element may be arranged in ten different ways relative to a set of edges 424 (rectangles arranged horizontally or vertically on the sides of the key 214) and vertices 426 (small squares in the corners). This example shows the central element overlaying the edges (first key), off the lower edge at the upper left corner towards the right (second key), centrally located at the top, off both the side edges and the bottom horizontal edges at the opposite position (third key), and centrally located (fourth key). Thus, there are ten variations of the central element in this type of arrangement relative to the edges 424 and vertices 426.

[0090] FIG. 4G shows a black and white example of the virtual keyboard 212. As in the example of FIG. 4A, the graphic features 114 of each key 214 include a number 402, a vowel 404, and two consonants 406, but in this case they are black and do not include as many colors as secondary features. The graphic features 114 also include four rectangular side edges 430 (located on each side of the key 214) and four square vertices 432 (located on each corner of the key 214), which themselves include color as secondary features, because each of the side edges 430 and vertices 432 may be filled with white or black. This increases the possible number of combinations of graphic features and arrangements. The numbers 402 and letters (404, 406) may be located on the left or right side. Each key 214 of the virtual keyboard 212 utilizes a different number 402. Five different pairs of vowels 404 are utilized in pairs depending on the right / left side arrangement, and 20 consonants 406 are utilized in the virtual keyboard 212. Thus, the number of possible combinations of the graphical features 114 and arrangements 116 that form the virtual keyboard 212 is enormous.

[0091] Another example of a virtual keyboard 212 based on the keyboard of FIG. 4G but including five colors as secondary features for each graphical feature (numbers 402, vowels 404, consonants 406, side edges 430, and apex 432) is shown in FIG. 4H. The graphical features 114, i.e., the side edges 430 and apex 432 or corners of the rows (top / bottom), and the numbers 402 and vowels 404 of the right-hand / left-hand arrays, are colored independently. The numbers and letters and their respective colors match those shown in FIG. 4A. In this example, the consonants are colored randomly without being considered as character features, i.e., data that is unknown to a potential attacker and would add more complexity to an analysis attempt. Further arrangements, namely the position of the main element formed by the number 402 and the three letters (404, 406) in relation to the fine edge 434 separating the main lateral edges 430 of the colors, are included in this virtual keyboard 212 with ten possible variations of arrangements, thereby further increasing the total number of graphic features 114 and available arrangements 116.

[0092] FIG. 4I shows the above example of FIG. 4H, but with the number of colors expanded to 10, increasing the total number of graphic features 114 and available sequences 116. Since there are 10 keys and 10 colors, the same graphic feature 114 color is not repeated in the virtual keyboard 212 (with the exception of consonants 406, whose color is selected randomly). FIG. 4J shows the same example as FIG. 4H, but on a black background, with the numbers and letters and their respective colors matching those shown in FIG. 4A. Using a white background (FIG. 4H) or a black background (FIG. 4J) may be another graphic feature (secondary feature) considered in the generation of the virtual keyboard 212. The generation of the virtual keyboard 212 may be based on external factors (e.g., considering the even or odd day of the current date), which would allow for additional security against spoofing and phishing. For example, if a user 201 is presented with a virtual keyboard 212 with a black background, and the user 201 knows that it is an even day of the month based on knowledge of the keyboard generation rules 118, the virtual keyboard 212 should have a white background, the user can detect that the virtual keyboard 212 is incorrect and there has been some attack on the security of the authentication process.

[0093] The examples of Figures 4A-4J use a relatively simple configuration of the virtual keyboard 212. However, the configuration of the virtual keyboard 212 may be more complex (e.g., 24 keys 214 arranged in 4 rows and 6 columns). Other possible virtual keyboards 212 having different graphic configurations and features are shown in Figures 4K-4M.

[0094] As can be seen in the different embodiments of the virtual keyboard 212, a wide variety of graphical features 114 may be utilized. The graphical features may include, for example, any of the following elements: numbers 402, vowels 404, consonants 406, side edges 430, vertices 432, fine edges 434, different symbols (e.g., circles, stars, triangles, deck petals, etc.), colors, font sources, user created graphics, and padding patterns, among others.

[0095] Returning now to Fig. 2, the mutual authentication system 200 generates one virtual keyboard 212 (or multiple virtual keyboards) based on the previous configuration according to the keyboard generation rules 118. The mutual authentication system 200 computes, on the one hand, a result that is deemed correct (correct key sequence 162) according to the authentication rules 152, and on the other hand displays a display 220 to the user 201 of the generated one virtual keyboard 212 (or multiple virtual keyboards) for the user 201 to compute his result and select the appropriate key 214 (key selection 144). Finally, the mutual authentication system 200 validates the user key selection 144 in relation to the correct key sequence 162 and authenticates the user (e.g., if there is a match) or not (e.g., if there is no match).

[0096] The virtual keyboard 212 is generated by the combination of the graphic features 114 and their arrangement on each key 214 according to the predefined keyboard generation rules 118. The keyboard arrangement 112 of the user 201 is predefined in a keyboard configuration step which may be mediated by the user 201 or may be performed automatically by the computer system. The configuration process specific to the user 201 is performed by the selection of the graphic features 114 and arrangements 116 such that each key 214 results in a predefined number of variations of the graphic features 114 and graphic features 116, resulting in a constant statistical probability, thereby avoiding attacks by probability analysis.

[0097] In the configuration process, the graphical features 114 are selected from a set of available graphical features, which may include primary features related to the shape and secondary features, e.g. size and color. Such a selection may involve user intervention. Alternatively, the selection may be made automatically, e.g. randomly. For each graphical feature, several secondary features may be selected, e.g. two possible sizes or five possible colors. Some graphical features may be defined only by the primary feature without secondary features. The graphical features 114 may include, among other options, other graphical elements such as symbols instead of letters or numbers, different font sources or font sizes, simple geometric shapes such as squares or rectangles, specific defined zones of each key, color patterns within these geometric shapes, larger or smaller numbers that affect not only the above elements but also the edges, or backgrounds of the elements.

[0098] In the configuration process, a possible arrangement 116 of each graphic feature is also selected from a set of available arrangements. For example, for some graphic features, no arrangement is selected, and for other graphic features, a different arrangement is selected in relation to the position and / or orientation of the graphic feature 114 in the key 214 (e.g., the graphic feature may be located on the right or left side of the key, the graphic feature may be rotated 0° or 90°, etc.). Different arrangements may be combined with each other (e.g., different positions are combined with different possible orientations), which increases the possible combinations of graphic features and arrangements for generating each key 214. The selection of the arrangement 116 may involve user intervention, or the selection may be made automatically (e.g., randomly). The arrangement may be more complex and have more parameters (e.g., the arrangement of numbers may be arranged in 10 different ways in relation to an edge of a given width: centered, above / below / right / left, on all four corners, or covering most of it).

[0099] The configuration process also defines keyboard generation rules 118 that take into account the graphical features 114 and the selected arrangement 116 and incorporate general rules that determine how each keyboard is generated using the graphical features 114 and the selected arrangement 116. The keyboard generation rules 118 include instructions for determining the number of keys 214 to be generated per keyboard, instructions for how to arrange the keys of the virtual keyboard 212 (e.g., circular, a matrix of five rows and two columns, etc.), and instructions for how to determine the content (graphical features 114 and arrangement 116) of each key 214. For example, the keyboard generation rules 118 utilized in generating the virtual keyboard 212 of FIG. 4A may include the following rules:

[0100] · The 10 keys 214 are randomly arranged by selecting 5 left arrays and 5 right arrays.

[0101] Each of the keys 214 has a randomly placed set of non-repeating numbers 402 after the decimal point (so a different number 402 on each key 214).

[0102] The numbers 402 in the top row are randomly colored with each of the five available non-repeating colors, as are the numbers in the bottom row.

[0103] With left / right alignment in mind, five pairs of vowels 404 (two "A", two "B", etc.) are randomly colored and placed in a small space above so that each vowel 402 covers both options (e.g., two "A" vowels are placed, one on the right side of the key and one on the left side of the key).

[0104] · 20 consonant letters 406 are uniformly colored with the five available colors (i.e., four of each color) and randomly placed in the small middle hole and the small lower hole.

[0105] Thus, the number of possible combinations of the virtual keyboard 212 in this particular configuration would be the result of all possible combinations of sequences, numbers, colors, numbers, etc.

[0106] Each virtual keyboard configuration is unique to a particular user, and there may be configurations that are very similar and indistinguishable to an outsider (e.g., vowels spaced with respect to top / bottom rows rather than right / left alignment).

[0107] The keyboard generation rules 118 may also include instructions for determining the number of virtual keyboards 212 to generate, each of which may be generated using the same or different generation rules (e.g., generating two virtual keyboards 212 using a first generation rule for a first virtual keyboard and a second generation rule for a second virtual keyboard). The number of keyboards generated may be used to configure the difficulty level of the authentication (for a particular user, authentication using a single virtual keyboard may be simpler than authentication using two virtual keyboards).

[0108] In the configuration process, authentication rules 152 of the user 201 are also defined. These rules define the criteria used for the selection of specific keys 214 from one or more virtual keyboards 212. The authentication rules 152 may also define how many keys need to be selected and how the key selections 144 are used to make the first user input 142. For example, compared to entering a four-digit PIN number, authentication may consist of selecting two keys 214 of the first virtual keyboard 212 (as the first two digits of the PIN number) and two other keys 214 of the second virtual keyboard 212 (as the last two digits of the PIN number). The first and second virtual keyboards may be displayed at once or consecutively one after the other (in the latter case authentication would consist of two consecutive steps where two different instances of the virtual keyboard 212 are used).

[0109] The authentication rules 152 allow a given concrete result to be obtained taking into account an instance of the virtual keyboard 212 generated according to the keyboard generation rules 118. The authentication rules 152 are individual for each user 201 and constitute the only secret the user 201 needs to know. Depending on the desired complexity, the authentication rules 152 may be of different nature, such as:

[0110] - Selecting a key 214 or a sequence of keys 214 based on one or more graphic features 114 or an arrangement 116 of features of the graphic features 114.

[0111] - Extraction of features or values ​​of selected keys 214.

[0112] - Changing / transforming the characteristics or value of another key.

[0113] - Referencing another key 214 based on the features / values / position or other characteristics of the selected key 214.

[0114] Next, one of the infinite number of authentication rule sequences 152 that the user 201 can select as an authentication mechanism mode is illustrated, for example, using the virtual keyboard 212 of FIG. 4J.

[0115] - Select a key 214 that contains the graphic feature 114 of the number 5 and annotates the vowel it contains (in the example of FIG. 4J, the selected key 214 is the key in the first row and first column, and the selected vowel is "I").

[0116] - Select another key 214 on the virtual keyboard 212 containing the same vowel graphic feature 114 as the first result (in this example, the other key 201 containing the vowel "I" is the key having the numerical feature "8" located in the fourth column of the lower row).

[0117] - Select the key 214 in the opposite row with a blue number (in this case the opposite row is the top row, and the key in the top row with a blue number is the 5th column key 214 with the blue number "2"). The colors of the letters and numbers of the virtual keyboard 212 of FIG. 4J match the colors shown in FIG. 4A with different types of scratching.

[0118] - Select the key 214 in the same column on the opposite row (i.e. the 5th column of the lower row in which the key has the number "6"), extract the consonant letter ("Z") located in the lower hole of the key, and calculate the next letter (thus obtaining the vowel letter "A").

[0119] - Select the key 214 bearing this latter letter as the second result (the key bearing the vowel "A" is the key bearing the number "1" found in the fourth column of the top row).

[0120] - Select a first result and a second result (in this example, the user enters key "8" followed by key "1"). The results may be introduced by successive pulses of a virtual keyboard 212, for example if such a key is displayed on a touch screen. Alternatively, the results may be introduced by other types of interfaces (e.g. a physical keyboard, voice commands, etc.).

[0121] In this example of an authentication process, the user 201 selects a pair of keys 214 resulting from a virtual keyboard instance 212 generated for such purpose. External elements may be included in the authentication rules 152, such as the first two letters of the day of the month and the city where the authentication takes place. Thus, if the authentication takes place on the 24th of the month from Madrid ("MA"), the following rules are negotiated:

[0122] - Select as the first result the key 214 that contains the first occurrence of the city's first letter (in this example the consonant "M") to the right of key 214. If the key with the consonant "M" appears in the fifth column, the resulting key will be located in the first column of the same row of the virtual keyboard 212. For example, the key selected using the keyboard of Figure 4J would be key "6" because the key located to the right of key "8" contains the consonant "M".

[0123] - Select the key 214 with the first occurrence of the second letter of the city (in this example "A") located to the right of key 214 as the second result. The virtual keyboard 212 proceeds from left to right and top to bottom. The key selected using the keyboard of Fig. 4J would be key "2" because it is the key located to the right of key "1" that contains the first occurrence of the vowel "A".

[0124] - The first result and the second result are introduced consecutively.

[0125] The authentication rules 152 may increase in complexity based on other external factors, such as parts of the service identifier for which the authentication process is taking place, the incorporation of an OTP message specific to the authentication process, more complex mathematical calculations (multiplication, exponentiation, etc.), more complex position transformations such as horse movements, logical comparisons (e.g. if the first "E" in the sequence is on the left, select value 7, if the first "E" in the sequence is on the right, select value 4, or depending on the even / odd value of the numeric characteristic of the particular key), conversions between letters, numbers, and positions (e.g. add 1 for "A", add 2 for "E", etc.).

[0126] In the authentication rules 152, the result may include selecting a single key or multiple keys (e.g., four keys). If the result includes several selected keys, the order of key selection made by the user 201 may or may not be relevant to the authentication based on the authentication configuration. For example, if the user follows the authentication rules 152 and the result is keys "2", "8", and "5", the result 242 of the authentication may be considered positive when the user enters the keys in the same order as instructed by the authentication rules 152 but not in any other order. Alternatively, it may be allowed to introduce the keys in any other order (e.g., "2", "5", "8"). The authentication process using four virtual keyboards (212a, 212b, 212c, 212d) generated by the virtual keyboard generation unit 210 is shown in FIG. 5. The virtual keyboards may be displayed in different ways. For example, one keyboard after the other (with the user selecting one or more keys 214 as the result for each virtual keyboard displayed), or several virtual keyboards 212 may be displayed at once (e.g., all virtual keyboards are displayed and the user is required to select one or more keys 214 as the result using a particular authentication rule 152).

[0127] Each of the four virtual keyboards (212a, 212b, 212c, 212d) is generated according to the following keyboard generation rules 118 similar to those used in FIG. 4I.

[0128] Each virtual keyboard is formed by 10 keys 214 arranged in 5 columns and 2 rows with a palette of 10 colors (blue, cyan, yellow, green, mint, red, pink, orange, purple and grey) for 108 security configurations (8-digit PIN numbers) implemented 2 at each of the 2 locations.

[0129] Each key 214 consists of: ~ A central element formed by numbers 402 occupying two thirds horizontally, and one vowel 404 and two consonants 406 vertically occupying one third horizontally. In the virtual keyboard, the numbers 402 are placed five times on the left side, and the other numbers 402 are placed five times on the right side. The vowels 404 are placed in the upper positions, reserving the other two positions (middle and lower) for the consonants 406. The edge element, in turn, includes two different graphic features: four side edges 430 and four vertices 432 or corners.

[0130] - the position of the central element is determined by a graphic position feature with ten variations (top, bottom, right, left, each of the four corners, center and extended, i.e. no fine edges 434) indicated by thin edges 434 around the central element. For example, for each key 214 illustrated by the numbers shown in the first virtual keyboard 212a in Fig. 5, the key "3" has a center variation by having four fine edges 434, the key "9" has an extended variation by not having fine edges 434, the key "6" has a right variation by not having fine edges 434 on the right side, and the key "1" has a vertical variation by not having thin edges 434 on the right and top sides.

[0131] The graphic features on the four side edges 430 of each key 214 are colored in one of ten available colors.

[0132] The graphic features on the four side edges 430 of each key 214 have colored patterns with ten possible variations, and are different for each key 214.

[0133] In the four variations of "C," the beginning is on the top (e.g., key 4 on the first virtual keyboard 212a), the bottom (e.g., key 2 on the first virtual keyboard 212a), the right side (e.g., key 7 on the first virtual keyboard 212a), and the left side (e.g., key 3 on the first virtual keyboard 212a).

[0134] ~Four variations in which "L" points to each of the four corners (e.g., keys "1", "9", "0", and "5" of the first virtual keyboard 212a).

[0135] Only the vertical side edges 430 are colored (eg, key 6 of the first virtual keyboard 212a).

[0136] Only the horizontal side edges 430 are colored (eg, key 8 of the first virtual keyboard 212a).

[0137] The graphical features of the four vertices 432 of each key 214 are colored in one of ten available colors.

[0138] The graphic features of the four vertices 432 of each key 214 show colored patterns of ten possible variations, which are different for each key 214 .

[0139] .about.three colored vertices 432 are left with the fourth vertex of each corner uncolored.

[0140] ~The top, bottom, right and left two vertices 432 are colored.

[0141] ~Two vertices 432 at diametrically opposed corners are colored.

[0142] - On each key 214, a set of the first ten natural, non-repeated digits 402 is included, each of which is coloured in one of ten possible colours.

[0143] In each virtual keyboard, five vowels 404 are randomly displayed in the right-hand column and also in the left-hand column. Each vowel is colored in one of ten randomly available colors.

[0144] -There are 20 different consonant features 406 (i.e., 20 different consonants are used). The features 406 are randomly distributed across the 20 available locations of the 10 keys 214. The centrally located consonant features 406 are colored with each of the 10 randomly available colors. Similarly, the lower located consonants 406 are colored with each of the 10 randomly available colors.

[0145] With this configuration, the act of selecting one or more keys for an authentication process may be defined by, among other variables: -Depending on the position of key 214 by the color of the four vertices 432 of the four side edges 430 of the number 402, the vowel 404, the central consonant 406, or the lower consonant 406; - by colored patterns on the four vertices 432 or the four side edges 430 - 404 vowels and their right or left arrangement -Consonant 406 - by the value of digit 402 in key 214

[0146] This operation of key selection may be combined with extraction operations such as modification, transformation, and lookup, among others (e.g., an extract operation of key X to extract the value of feature Y) to form key selection 144 as first user input 142. Key selection 144 may include any number of selection keys (e.g., one selection key, two selection keys, etc.) depending on the configuration.

[0147] Some possible authentication rules 152 for a user 201 might be the following: - Select the two keys 214 on the virtual keyboard 212 that contain the vowel "A". - Extract the numeric value of the key (0 is interpreted as 10). -Multiply these values -Add the value of the number 402 shown in cyan on the virtual keyboard 212. - As a result, select the key 214 to the right of each digit in this result (the one to the right of the key located in the 5th column is considered to be the key in the first column of the same row).

[0148] Applying these authentication rules to the four virtual keyboards (212a, 212b, 212c, 212d) of FIG.

[0149] - On the first virtual keyboard 212a (identifying keys by numerical values). ~The keys with "A" are "0" and "3", and the multiplication result is 30. ~The cyan number 402 is "6", which when added to 30 gives the number 36. The resulting keys selected were those located to the right of the numbers "3" and "6", That is, keys "8" and "1", respectively.

[0150] - Regarding the second virtual keyboard 212b. The keys with ~'A' are '4' and '6', and the multiplication result is 24. ~The cyan number 402 is "5", which when added to 24 gives the number 29. The resulting keys selected were those located to the right of the numbers "2" and "9", respectively. That is, keys "3" and "2", respectively.

[0151] - Regarding the third virtual keyboard 212c. ~The keys with "A" are "0" and "9", and the multiplication result is 90 ("0" is considered to have a value of 10). ~The cyan number 402 is "9", which when added to 90 results in 99. The resulting keys selected were the digits "9" and "9" located to the right of each other, That is, key "1" is selected twice.

[0152] - Regarding the fourth virtual keyboard 212d. ~The keys that have "A" are "0" and "8", and the sum is 80. ~The cyan number 402 is "1" and when added to 80 the result is 81. The resulting keys selected were those located to the right of the numbers "8" and "1", respectively. That is, keys "6" and "7", respectively.

[0153] Thus forming the final result, the value is "81321167". This result may be introduced in multiple forms, for example by voice or keyboard. If a touch screen 220 is utilized to display a virtual keyboard, as shown in the example of FIG. 5, the user 201 may be communicated to input a key selection 144 from the respective virtual keyboard (212a, 212b, 212c, 212d) by pulsing a selected key on the respective virtual keyboard. Advantageously, the graphical representation of the virtual keyboard 212 may be utilized as a user input means for authentication without requiring additional input means (such as a physical keyboard or an additional graphical interface).

[0154] The authentication process of the present invention can be considered as a mutual authentication method, since on the one hand the authentication system 240 is responsible for authenticating the user 201, but the user 201 can also authenticate the authentication system, since the user 201 knows not only the authentication rules 152, but also the graphic features 114 and arrangement 116 that the virtual keyboard 212 can adopt, as well as the keyboard generation rules 118 to be used (in fact, the user 201 can also intervene throughout the virtual keyboard configuration process or generate new graphic features other than those proposed by the system). Thus, even if a computer system masquerades as an authorized authentication system, the user 201 can detect this fraudulent situation by verifying that the displayed virtual keyboard 212 does not correspond to the graphic features 114, arrangement 116, or keyboard generation rules 118 previously adopted in the keyboard configuration 112 of the user 201. To carry out such an attack, the attacker would reproduce in detail the keyboard generation rules 118 stored in a secure location (e.g., on a server). The keyboard generation rules 118 may also take into account external factors (such as the date of the month, using one type of graphical features 114 and sequences 116 on odd days and a different set of the other on even days). Thus, the user authentication process performed by the present invention adds an additional layer of security, since it allows the user to authenticate the authentication system itself (i.e., to ensure that the authentication system is not masquerading as an idiom).

[0155] The authentication process of the present invention can be used in any application that requires authenticating a user, such as, but not limited to: -Access to an application or web page. A method for unlocking an electronic device (e.g. a smartphone), wherein both the virtual keyboard generation unit 210 and the authentication unit 240 are within the device itself (either in memory, a dedicated chip, etc.). -A method for unlocking an encrypted compressed code file (similar to unlocking a device, but at the software level where the keypad is rather self-contained within the file). -Authentication using progressive levels of security in apps (e.g. a banking app that accesses a pair of virtual keyboards and checks handover operations to resolve one or more other virtual keyboards). - Use of ATMs, point-of-sale terminal (POS) payments, etc. where authentication is required to enable certain payment operations. - Access control (e.g. high security access control to building doors). -It can function like easily understood verbal instructions, but is too complicated for a machine to do automatically, so a captcha mechanism is used. - As a session token (if a unique paired keyboard solution is used it may be used as a session token by creating a unique key with substantially negligible collision risk).

Claims

1. A step (110) of obtaining a keyboard configuration (112) of a user (201) to be authenticated, said keyboard configuration (112) comprising: a plurality of graphic features (114); a plurality of arrays (116) of said graphic features (114); a step (110) including keyboard generation rules (118); a step (120) of generating at least one virtual keyboard (212), each virtual keyboard (212) formed from a plurality of keys (214) incorporating a combination of graphic features (114) arranged in a particular arrangement (116), the graphic features (114) and the arrangement (116) used in each key (214) being selected from the keyboard configuration (112) of the user (201) based on the keyboard generation rules (118); displaying (130) said at least one virtual keyboard (212) to said user; receiving (140) a first user input (142) corresponding to a key selection (144) on a respective virtual keyboard (212); Obtaining (150) authentication rules (152) of the user (201); applying (160) the authentication rules (152) of the user (201) to the at least one virtual keyboard (212) to obtain at least one correct key sequence (162); and authenticating (170) said user (201) if said key selection (144) of said first user input (142) is validated in association with a correct key sequence (162).

2. 2. The method of claim 1, further comprising the step of obtaining (102) an identity (204) of the authenticating user (201) prior to the step of obtaining (110) the keyboard configuration (112).

3. 2. The method of claim 1, further comprising obtaining a second user input, wherein at least one virtual keyboard is generated based on the keyboard generation rules combined with the second user input.

4. The method of claim 1 , wherein the at least one virtual keyboard is displayed on at least one display.

5. 5. The method of claim 4, wherein the at least one display is touch-enabled and the key selection is performed by pulsing the selected key on a respective virtual keyboard displayed on the at least one touchscreen.

6. The method of claim 1, wherein the keyboard configuration (112) of the user (201) is obtained by accessing a database (211) or a memory (213).

7. 2. The method of claim 1, wherein the authentication rules (152) of the user (201) are obtained by accessing a database (241) or a memory (243).

8. 2. The method of claim 1, wherein a plurality of correct key sequences are obtained by applying the authentication rules of the user to the at least one virtual keyboard.

9. 9. The method of claim 8, wherein the user authentication includes different authentication levels based on the correct key sequence, and the key selection is validated in association with the correct key sequence.

10. 9. The method of claim 8, further comprising identifying the user from a set of users based on the correct key sequence, wherein the key selection is validated in association with the correct key sequence.

11. The method of claim 1 , wherein the arrangement (116) of the graphic features (114) within each key (214) defines a position and / or orientation of the graphic features (114) within the key (214).

12. The graphic feature (114) a main feature defining the shape of said graphic feature (114); Secondary features that define characteristics of the primary features; The method of claim 1 , wherein the polymer is formed by

13. Obtaining (110) a keyboard configuration (112) of a user (201) to be authenticated, said keyboard configuration (112) comprising: a plurality of graphic features (114); a plurality of arrays (116) of said graphic features (114); and Acquisition (110) including keyboard generation rules (118); generating (120) at least one virtual keyboard (212), each virtual keyboard (212) formed from a plurality of keys (214) incorporating a combination of graphic features (114) arranged in a particular arrangement (116), the graphic features (114) and the arrangement (116) used in each key (214) being selected from the keyboard configuration (112) of the user (201) based on the keyboard generation rules (118); a virtual keyboard generation unit (210) configured to: an input interface (230) configured to receive (140) a first user input (142) corresponding to a key selection (144) of a respective virtual keyboard (212); - obtaining (150) the authentication rules (152) of said user (201); applying (160) the authentication rules (152) of the user (201) to the at least one virtual keyboard (212) to obtain at least one correct key sequence (162); and Authenticating (170) the user (201) if the key selection (144) of the first user input (142) is validated in conjunction with a correct key sequence (162). an authentication unit (240) configured to: A mutual authentication system comprising:

14. The system according to claim 13, comprising a user identification unit (202) configured to obtain (102) an identification (204) of the user (201) to be authenticated.

15. 14. The system of claim 13, wherein the input interface is configured to acquire a second user input, and the virtual keyboard generation unit is configured to generate at least one virtual keyboard based on the keyboard generation rules combined with the second user input.

16. The system of claim 13 , further comprising an information display device configured to display (130) the at least one virtual keyboard (212).

17. 17. The system of claim 16, wherein the information display device comprises at least one touch screen (220), the input interface (230) comprises at least one touch screen (220), and the key selection (144) is made by the user (201) pulsing the key (214) selected from a respective displayed virtual keyboard (212).

18. 14. The system of claim 13, wherein the virtual keyboard generation unit (210) is configured to obtain (110) the keyboard configuration (112) of the user (201) by accessing an external database (211) or an internal memory (213).

19. The system of claim 13, wherein the authentication unit (240) is configured to obtain the authentication rules (152) of the user (201) by accessing an external database (241) or an internal memory (243).

20. 14. The system of claim 13, wherein the authentication unit (240) is configured to obtain a plurality of correct key sequences (162) by applying the authentication rules (152) of the user (201) to the at least one virtual keyboard (212).

21. 21. The system of claim 20, wherein the authentication unit (240) is configured to authenticate the user (201) based on the correct authentication key sequence (162) based on different authentication levels, and the key selection (144) is validated in association with the correct authentication key sequence (162).

22. 21. The system of claim 20, wherein the authentication unit is configured to identify the user from a set of users based on the correct key sequence, and the key selection is validated in association with the correct key sequence.

23. The system of claim 13 , wherein the elements of the system are configured as part of the same electronic device.

24. The system of claim 13 , wherein the elements of the system are distributed across different electronic devices.

25. 10. A non-transitory computer-readable medium comprising program instructions stored on the medium, the program instructions, when executed by a processor, causing the processor to perform the method of claim 1.