Authentication system with image type password and authentication method and program

The authentication system uses semantic information of image components to create secure and memorable passwords, addressing the challenge of balancing ease and security in image-based authentication.

JP2025138897APending Publication Date: 2025-09-25THE JAPAN RES INST
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025118050
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Existing password authentication methods using images face challenges in balancing ease of use and security, particularly when images are displayed in large numbers, making them susceptible to unauthorized access across multiple systems.

Method used

An authentication system that uses semantic information of image components, such as nouns and appearance features, to define passwords, allowing for secure and memorable image-based authentication without requiring numerous images on the screen.

Benefits of technology

The system provides visually appealing and easy-to-remember passwords that enhance security by making it difficult to reuse across systems and protect against social engineering, while reducing the number of displayed images.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025138897000001_ABST
    Figure 2025138897000001_ABST
Patent Text Reader

Abstract

To provide an authentication method that appeals to the human sense of sight and makes passwords easy to remember, while increasing security strength without unnecessarily increasing the number of images displayed on a password input screen.SOLUTION: An authentication system authenticating a user by an image comprises authentication rule setting means for setting an authentication rule for authenticating a user by a combination of an image and image components, image display control means for controlling the display of an image, selected image acceptance means for accepting a selection of a displayed image and image components, semantic information acquisition means for acquiring semantic information of the selected image and image components, and authentication determination means for determining whether the acquired semantic information matches the semantic information contained in the authentication rule.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication system that uses an image as a password. [Background technology]

[0002] Conventionally, authentication methods that require passwords to be entered using images rather than characters have been known. For example, Patent Document 1 describes a method for performing personal authentication of a system user by selecting multiple images assigned to the user from multiple images displayed on a display screen of a display device and determining whether the selected multiple images are authentic, in order to simplify the password entry operation and prevent operational errors. In this method, the multiple images are divided into multiple groups, a GUI for selecting one image for each of the multiple groups is displayed on the display screen, and a combination of the multiple images selected by the GUI is converted into a character string representing a password, and the authenticity of the password is determined. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2001-282738 Summary of the Invention [Problem to be solved by the invention]

[0004] Generally, password authentication uses letters and numbers, and security can be increased by varying the number of digits and character types in the password. While this has the advantage of making it easy to use the same password across multiple systems, it also poses the risk that if a password is leaked from one system, it could potentially be used to access other systems. Even when using images as passwords, increasing security requires displaying many images and requiring users to accurately enter the images registered as passwords.

[0005] Therefore, in consideration of the above-mentioned problems, the present invention aims to provide an image password authentication method that uses images to appeal to the human visual sense, making the password easier to remember, and also increasing security without unnecessarily increasing the number of images displayed on the password input screen. [Means for solving the problem]

[0006] In order to solve the above problems, the present invention provides the following solutions.

[0007] (1) An authentication system that sets authentication rules for authenticating a user using image components that make up an image, comprising: an image display control means that controls the display of the image and image components; a selected image receiving means that receives a selection of the displayed image and image components; a semantic information acquisition means that acquires semantic information set in the image components; and an authentication determination means that determines whether the acquired semantic information matches the semantic information set in the authentication rule, wherein the semantic information set in the image components corresponds to a noun and an appearance feature that defines the noun.

[0008] (2) In the configuration described in (1) above, the image components are automatically decomposed into image components and their semantic information is generated using AI technology within the range that can be recognized by the noun and the appearance characteristics.

[0009] (3) In the configuration described in (1) or (2) above, the image display control means is characterized in that the method of displaying the authentication screen is to select and display an image containing components with the same noun but different appearance characteristics.

[0010] (4) In the configuration of (2) above, the automatically generated semantic information is presented as a term to be used as a password for authentication.

[0011] (blank line)

[0012] (blank line)

[0013] (5) An authentication method for authenticating a user by an image, wherein an authentication server executes the steps of controlling the display of the image and image components, accepting a selection of the displayed image and image components, acquiring semantic information set in the image components, and determining whether the acquired semantic information matches semantic information set in the authentication rule, wherein the semantic information set in the image components corresponds to a noun and an appearance feature that defines the noun.

[0014] (6) A program characterized by causing the steps described in (5) above to be executed in the authentication server or in a combination of the authentication server and a terminal. [Effects of the Invention]

[0015] According to the present invention, it is possible to provide an authentication method using a picture password that is visually appealing and easy to remember, and that can increase security without unnecessarily increasing the number of images displayed on the password input screen. [Brief explanation of the drawings]

[0016] [Figure 1] FIG. 1 is a diagram for explaining an overview of a picture-type password according to the present invention. [Figure 2] 1 is a diagram illustrating a functional configuration of an authentication system according to an embodiment of the present invention. [Figure 3] FIG. 2 is a diagram showing an example of image component data stored in an image library DB of the authentication system. [Figure 4] FIG. 10 is a diagram showing an example of a screen for registering an authentication rule by image. [Figure 5] FIG. 10 is a diagram showing a processing flow for setting an authentication rule by an image. [Figure 6] FIG. 10 is a diagram showing a processing flow of image-based password determination. DETAILED DESCRIPTION OF THE INVENTION

[0017] Hereinafter, embodiments of the present invention (hereinafter referred to as "embodiments") will be described in detail with reference to the accompanying drawings. In the following drawings, the same elements are designated by the same numbers or symbols throughout the description of the embodiments.

[0018] <Summary> FIG. 1 is a diagram for explaining the outline of a picture password according to the present invention. In this invention, password authentication is performed using image information instead of textual passwords. That is, in an authentication system for authenticating individuals, multiple images are displayed on an authentication screen, and authentication (logging in) is achieved by selecting the correct image set as the password. Here, to use an image as a password (sometimes called an "image password"), "semantic information" of the image is used instead of an image identifier (image ID). The "semantic information" of an image is textual information for identifying the "image components" that make up an image.

[0019] For example, images A1 to A6 shown in FIG. 1 share the common semantic information of "person" as a whole, but each image may have its own semantic information, such as "silver-haired young man," "man in suit," "woman with glasses," "girl in red clothes," "man in work clothes," or "man with purple tie." Furthermore, each image component may also have semantic information. As described above, semantic information expresses the characteristics of an image component using text information. For example, the names of the clothing, accessories, and belongings worn by a "person" (e.g., "tee shirt," "suit," "glasses," "ribbon," "tie") constitute the semantic information of each image component. In addition to the name of the component, characteristics such as shape, color, and pattern may also be included. Furthermore, the background of the person may also be a component. In other words, the background color or scenery may also have semantic information as an image component. Furthermore, because the image component to be used as a password is selected using semantic information, which is text information, image components can be defined more flexibly than by assigning identifiers to the image components.

[0020] A specific example of login using a picture password in an authentication system (hereinafter referred to as the present system) according to one embodiment of the present invention and the features of the present system will be described below.

[0021] As shown in "(1) At login" in Figure 1, the login screen of this system displays multiple images, and the user selects from these images the image with the semantic information they wish to enter as the picture password. The images available for selection change randomly on the screen. For example, if the semantic information for the picture password has already been set as "blue tie," then at login time the user will select the tie portion, which is a component of the image shown in A2. In this case, if the user selects the image in A5 and then selects the tie portion, the same "blue tie" will be selected.

[0022] The reason why image components are selected rather than the entire image is that a single image can contain a lot of semantic information, making it possible to create many picture passwords using fewer images. To "select" an image component, if the device displaying the login screen is a PC, simply click on a specific component in the image with the mouse. If the device has a touch panel, such as a smartphone, touch the part of the component you want to select with your finger or pen. In either case, the position information of the image component within the image can be detected, and the image component can be authenticated, including which position within the image was selected.

[0023] As an extreme example, it is also possible to display only one image on the login screen at a time and perform authentication by selecting the components of that single image in the correct order. In the case of a complex image, displaying many images at once on a small screen such as a smartphone makes selecting the image components complicated, so it may be better to display only one image with many components.

[0024] At the next login (or after a certain period of time has passed), as shown in "(2) Next Login" in Figure 1, multiple different images are displayed, and the user selects the image component they want to input from among them. At this time, the system extracts the semantic information of the image component selected on the login screen. This extraction may be performed by analyzing using known image analysis technology or AI (Artificial Intelligence) technology. Then, at the time of authentication, the semantic information of the selected image component is identified, and it is determined whether the sequence of semantic information matches the semantic information of the password registered in association with the user's ID.

[0025] The above-mentioned authentication using a picture password has the following features. (1) Since the image to be selected is provided for each system, it becomes difficult to reuse passwords between systems. In other words, it is possible to force the use of system-specific passwords. (2) A password can be entered from different images that have the same semantic information. For example, images A2 and A5 in Figure 1 are different images, but they share the common image component of "blue tie." Therefore, no matter which image is displayed, "blue tie" can be selected as the picture password. In addition, there is no need to exchange image data between the terminal and the server; instead, the exchange can be done using the image ID. (3) Because the image and password information are in an inclusive relationship, it is impossible to know what the password is just by looking at the input operation on the login screen. In other words, it is impossible to know which component of the image the user focused on when selecting the image in terms of the on-screen operation. Therefore, even if someone peers at the password input operation from the side, they will not know why the image was selected, which also helps prevent social engineering. (4) If the number of images displayed on the login screen is small, the password is more likely to be cracked by random entry. Also, if entire images are selected one by one, the components that do not overlap among multiple images will become the password, making it easier for others to guess. To avoid this, multiple image components are required to be entered consecutively when entering the password. This makes it difficult to narrow down the semantic information contained in a single image to one, making it more difficult to guess the semantic information from the selected image.

[0026] Additionally, as an extension of this system, it is possible to devise a variety of image types. For example, the image used for the password could be a brand character related to the site that runs this system. Password entry screens on sites tend to be clunky, but by using the site's brand character as the image, the brand image of the entire site can be maintained. Also, with the increasing number of multi-step authentications across multiple sites, this makes it easier for users to recognize which site they are currently authenticating to.

[0027] You can also use images used as passwords for public relations activities. For example, if a confectionery company displays an image of a person eating one of their products on the login screen, it can also promote their products. Or, if you log in this month using an image of an anime character, you can promote a tie-up with another company. However, whether or not users set these images as picture passwords is another matter.

[0028] <System functional configuration> 2 is a diagram showing the functional configuration of an authentication system according to one embodiment of the present invention, in which arrows between functional blocks indicate the direction of data flow or the direction of processing flow.

[0029] As shown in the figure, the authentication system of this embodiment is composed of an authentication server 10 and a user terminal 20 connected to the authentication server 10 via a network. The authentication server 10 has, as its functional configuration, an image library DB 11, an authentication rule setting means 12, an image display control means 13, a selected image receiving means 14, an image component detecting means 15, a semantic information acquiring means 16, an authentication rule storage means 17, and an authentication determination means 18. The authentication server 10 may be a real server or a server realized on the cloud.

[0030] The user terminal 20 in this system may be a general PC (personal computer) or a tablet terminal such as a smartphone. Furthermore, the user terminal 20 may be smart glasses, which are glasses-type wearable devices equipped with sensors, a camera, a microphone, a speaker, a display, etc. Using smart glasses, a user can easily select image components by focusing their gaze on a specific point on the screen.

[0031] The functional configuration of the authentication server 10 in FIG. 2 will be explained below in order. The image library DB 11 is a database of images stored in the authentication server 10, and stores image component data 11a for each image. FIG. 3 is a diagram showing an example of the image component data 11a stored in the image library DB 11. The image component data 11a includes the classification of the image group ("person" in this example), the image IDs of multiple images (e.g., image01-06), and semantic information of the image components. As mentioned above, "semantic information" is text information that simply describes the external characteristics of an entire image or each of the image components that make up the image. Images are classified by type using nouns such as "person," "animal," "architecture," and "natural object," and these nouns may be further supplemented with terms that further define the external characteristics of the image, such as adjectives such as "red," "black," or "patterned," or adjectival verbs such as "doing something" or "doing something." The semantic information may consist of a single term or a combination of multiple terms.

[0032] Figure 3 shows how semantic information assigned to the entire image and its image components is stored in a table format. Table 101 stores the image IDs of image01 to image06 displayed on login screen 100 and the semantic information for each image component. Semantic information may be added manually when registering the image in the database. Correct and incorrect images may also be extracted from a group photo or other image based on user-specified rules (semantic information). For example, if a user selects "blue tie," the correct image may be extracted from a person wearing a blue tie. Incorrect images may be extracted from images with intentionally different hair colors or images of people wearing or not wearing hats, so that the correct meaning, "blue tie," cannot be inferred. Furthermore, as mentioned above, image analysis and AI technologies may be used to automatically decompose an image into its components and generate its semantic information.

[0033] Returning to Fig. 2, the authentication rule setting means 12 provides a function for setting an authentication rule by image for each user, i.e., for setting image components to be used as a password. A specific example will be described later, but a user can select multiple image components from an image database registered on the system, or select multiple image components from unique images saved on a user terminal or the like, and register them as a password.

[0034] 4 is a diagram showing an example of a screen for registering this authentication rule in the system. The illustrated authentication rule setting screen 102 shows how the user selects an arbitrary search word (in this example, "walking the dog") and sets (registers) an authentication rule that uses an image component as a password from the group of images image11 to image16 displayed as search results.

[0035] When a user selects an image on screen 102 that they wish to use as a password, a mesh-like rectangle is displayed on the image. The system then determines whether semantic information can be identified from the partial image within each mesh, and if semantic information can be identified, indicates that the mesh (image component) can be used as a password by, for example, changing the color of the mesh. Image components for which semantic information can be identified may be displayed with their outlines emphasized.

[0036] If the semantic information of a mesh cannot be identified, the surrounding meshes are searched, and if the semantic information is identified, the color of the meshes in that range is changed. The display size of the mesh may be changed at this time. It goes without saying that the image component data 103 stored in the image library DB 11 is referenced to identify the semantic information of the image components. To make it easier for the user to find image components, the range containing semantic information may be set to a specific mesh position. For example, when selecting multiple images from a 3x3 or 4x4 array, or a group of three or four images, it is necessary to repeatedly search for the part containing semantic information within the entire image. By doing this, the desired position can be quickly identified.

[0037] Then, by clicking or touching a mesh identified as usable as a password, or by focusing the user's gaze with smart glasses, the user can specify the semantic information of the image components of that mesh as a password. In this example, screen 102 shows the following: (1) "bun hairstyle" is set as semantic information from image 13; (2) "no hairstyle" is set as semantic information from image 16; and (3) "gray background" is set as semantic information from image 15. The semantic information set in this way is saved as an authentication rule along with the setting order.

[0038] Note that image components and semantic information are stored in advance for each registered image in the image library DB11, but if the image components and semantic information cannot be identified for a user's own image, the mesh scale is automatically changed and an attempt is made to identify them again. However, if the image components and semantic information still cannot be identified, the user is prompted to select a different image.

[0039] 2, the image display control means 13 reads out a specific image from the image library DB 11 or the user terminal 20 in response to an operation from the user terminal 20, and displays it on the screen of the user terminal 20. In this example, an image of a person alone is shown as the type of image, but it does not necessarily have to be a single image. For example, any image in which the features are easily distinguishable, such as one or more people and an animal, a person and a landscape, a vehicle and a building or landscape, etc., may be used.

[0040] The selected image receiving means 14 has a function of receiving an image and image components selected by the user from the images displayed by the image display control means 13 .

[0041] The image component detection means 15 detects the image and component analysis of the image accepted by the selected image accepting means 14. This detection uses the position information of the image on the screen or the location of a click or touch within an image. If the user terminal 20 is a pair of smart glasses, the position information of the location on the screen where the user focuses their gaze is used.

[0042] The semantic information acquisition means 16 uses image analysis technology to detect semantic information about images and image components. For example, if the image selected by the user is an entire image, semantic information is extracted from the characteristics of the entire image. For example, if the image is centered around a person, semantic information such as "person," "man," "woman," "child," "young person," and "old person" is first extracted. Furthermore, occupations that can be identified from the person's appearance (e.g., "baseball player," "doctor," "police officer," "singer," etc.) and information about the person's actions (e.g., "person running," "person fishing," "person walking," etc.) are also extracted as semantic information. Furthermore, if the user selects a specific location in the image and it is determined that the location is clothing, the type, shape, color, and pattern of the clothing are also extracted as semantic information. Furthermore, the person's hairstyle, color, accessories worn, and background characteristics are also extracted as semantic information.

[0043] The authentication rule storage means 17 stores the semantic information of the image components set as a password. It is not necessary to store the image data itself as an authentication rule.

[0044] The authentication determination means 18 determines whether the sequence of semantic information of the image components selected on the login screen 100 or the like matches the sequence of semantic information of the image components linked to the user's ID and stored in the authorization rule storage means 17. If the semantic information matches completely, it is determined that the authentication has been properly completed.

[0045] The functional configuration of the present system described above is merely an example. A single functional block (database and functional processing unit) may be divided, or multiple functional blocks may be combined into a single functional block. Each functional processing unit is implemented by a computer program stored in a storage device, such as a central processing unit (CPU) (possibly including a graphic processing unit (GPU)), read-only memory (ROM), flash memory, solid-state drive (SSD), or hard disk, and executed by the CPU. That is, each functional processing unit is implemented by the computer program reading and writing necessary data, such as tables, from a database (DB) stored in a storage device or a memory area in memory, and, in some cases, controlling related hardware (e.g., an input / output device, a display device, or a communication interface device). Furthermore, the database (DB) in the embodiments of the present invention may be a commercial database, but it also refers to a simple collection of tables and files, regardless of the internal structure of the database itself.

[0046] <System processing flow>

[0047] FIG. 5 is a diagram showing the process flow for setting authentication rules using images. In the following process flow diagrams (flowcharts), the order of processing steps may be changed as long as the relationship between input and output at each step is not affected. Also, Y and N below the decision blocks in the diagram represent Yes and No. In the following explanation, the reference symbols for the functional blocks shown in FIG. 2 will be omitted.

[0048] First, in step S10, the user is prompted to select whether or not to use a registered image as a password image. If a registered image is to be used, the process proceeds to step S13. If not, the process acquires image data specified by the user (step S11), analyzes the user's image using image analysis technology and AI technology, and identifies semantic information of the image and image components (step S12), and then proceeds to step S15.

[0049] If a registered image is to be used, the image and image component data are read from the image library DB in step S13. Next, in step S14, a search word is input from the user, and the search result images are displayed. Then, it is determined whether a specific image component has been selected (clicked, touched, etc.) (step S15).

[0050] If a specific image component is selected, the semantic information of that image component is acquired in step S16, and the semantic information of that image component is acquired (step S17). If a specific image component is not selected, the process returns to step S14, and the search word is re-entered.

[0051] Next, in step S17, it is determined whether another image component has been selected, and if Yes, the process returns to step S16, but if No, the process prompts the user in step S18 whether to complete the setting. When the setting is completed, finally, in step S19, the semantic information and the order of the image components selected as the image password are saved as the user's authentication rule.

[0052] FIG. 6 is a diagram showing a processing flow of image password judgment. First, in step S20, information on the position selected (clicked, touched, etc.) on the login screen is acquired.

[0053] Next, in step S21, it is determined whether or not the image component of the position information has semantic information. If No, the process returns to step S20, but if Yes, the semantic information is saved in step S22.

[0054] If it is determined in step S23 that the user has finished selecting location information, the process proceeds to step S24, where the acquired semantic information is compared with the semantic information stored in the authentication rule to determine whether the semantic information matches.

[0055] If the information matches in step S25, authentication is successful (step S26). If the semantic information does not match, authentication is not successful (step S27). In this case, the user is prompted in step S28 to decide whether to reselect the location information (retry). If a retry is desired, the process returns to step S20, but if a retry is not desired, the process ends.

[0056] <Effects of the embodiment> As described above, this system identifies the image components used as passwords for image-based authentication using semantic information, which is text information. This allows for more flexible definition of image components than assigning identifiers to image components. This semantic information can be acquired based on the location information where the user clicks or touches the image on the screen. Furthermore, by using smart glasses, semantic information can be identified by detecting the location information where the user is focusing their gaze, without the user having to click or touch the screen.

[0057] Furthermore, the authentication rule setting can make it easier to select image components of the image by displaying a mesh-like rectangle on the image to be used as a password. Furthermore, if the image is specified by the user and the semantic information of the image components cannot be identified, the semantic information of the components can be identified in a wider range by searching around the mesh.

[0058] Furthermore, the images used in this system can basically be anything, but can also be images of characters or products of a brand related to the site that operates this system. This can be expected to maintain the brand image and have a promotional effect, as well as make it easier for users to recognize which site they are currently authenticating to.

[0059] Although the present invention has been described above using the embodiments, it goes without saying that the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. Furthermore, it is clear from the claims that such modifications and improvements can also be included within the technical scope of the present invention.

[0060] In the above embodiment, the present invention has been described as an invention of an object, that is, an authentication system (authentication server and user terminal), but the present invention can also be understood as an invention of an authentication method or a computer program (a program executed on an authentication system). [Explanation of symbols]

[0061] 10 Authentication Server 11 Image Library DB 11a Image component data 12 Authentication rule setting method 13 Image display control means 14. Selected image receiving means 15 Image component detection means 16 Semantic information acquisition means 17 Authentication rule storage means 18 Authentication Judgment Method 20 User terminal 100 images 101 Tabular image component data 102 Authentication rule setting screen 103 Image component data in tabular format on the authentication rule setting screen

Claims

1. An authentication system that sets authentication rules for authenticating a user using image components that configure an image, comprising: an image display control means for controlling the display of the image and the image components; a selected image receiving means for receiving a selection of the displayed image and the image component; a semantic information acquisition means for acquiring semantic information set for the image component; an authentication determination means for determining whether the acquired semantic information matches semantic information set in the authentication rule; The semantic information set for the image component is associated with a noun and an appearance feature that defines the noun. An authentication system comprising:

2. The authentication system according to claim 1, wherein the image components are automatically decomposed into image components and their semantic information is generated using AI technology within a range that can be recognized by the noun and the appearance characteristics.

3. 3. The authentication system according to claim 1, wherein the image display control means selects and displays an image including components with the same noun but different appearance characteristics as a display method for the authentication screen.

4. 3. The authentication system according to claim 2, wherein the automatically generated semantic information is presented as a term used as a password for authentication.

5. An authentication method for setting authentication rules for authenticating a user using image components that constitute an image, comprising: The authentication server: controlling the display of the image and the image components; accepting the displayed image and a selection of the image components; acquiring semantic information set for the image component; determining whether the acquired semantic information matches semantic information set in the authentication rule; The semantic information set for the image component is associated with a noun and an appearance feature that defines the noun.

1. An authentication method comprising:

6. 6. A program for causing the steps according to claim 5 to be executed in the authentication server or in a combination of the authentication server and a terminal.

Citation Information

Patent Citations

  • Personal authentication method

    JP2001282738A