Secure multifactor authentication with user interaction
The authentication method addresses inefficiencies and security issues in traditional username-password systems by employing clue-secret combinations, offering a secure, user-friendly, and inclusive solution that enhances account security and usability for all users.
Patent Information
- Application Number
- PCT/FI2024/050502
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-24
- Filing Date
- 2024-09-26
- Publication Date
- 2025-05-30
AI Technical Summary
Conventional username-password combinations are inefficient and insecure, leading to users adopting weak or reused passwords, which compromises account security and privacy. Additionally, multifactor authentication solutions often lack usability for individuals with disabilities and may not provide adequate security in all contexts.
A secure multifactor authentication method using clue-secret combinations, where users receive an authentication request with a clue related to a previously registered secret, enhancing security and usability by eliminating the need for traditional password management and accommodating various user abilities.
The method provides a secure, user-friendly, and inclusive authentication process that enhances security by leveraging memorable clues and securely stored secrets, while reducing the burden on system resources and improving accessibility for diverse user groups.
Smart Images

Figure FI2024050502_30052025_PF_FP_ABST
Abstract
Description
[0001] SECURE MULTIFACTOR AUTHENTICATION WITH USER INTERACTION
[0002] TECHNICAL FIELD
[0003] The present disclosure relates to method for authentication. Moreover, the present disclosure relates to system for authentication.
[0004] BACKGROUND
[0005] In today's digital era, the need for robust, secure and user-centric authentication process is evident. Such authentication processes provide strong and user-friendly ways to ensure that only authorized people can access their accounts.
[0006] A conventional method of authentication is by means of username and password combinations. This process involves the user creating a username and password for the purpose of registering on a service platform. However, this can be a time-consuming and inefficient process when the user has to create multiple accounts for different service platforms. Many users struggle with managing multiple strong passwords, leading to many users hating them and feel overwhelmed, which in turn can result in users choosing insecure behaviors and practices for convenience-sake. These insecure behaviors include creating weak passwords and reusing passwords to cope. Such behaviours make it increasingly challenging to ensure the security and privacy of user accounts. Password alternatives and solutions to help with the password problems have not managed to solve the key issues, and due to the usability, convenience, and questionable security, they have not replaced passwords.
[0007] To address the aforementioned challenges associated with the conventional username-password combinations, multifactor authentication methods have been introduced in the recent years. Typically, the multifactor authentication methods require the users to provide multiple forms of verification to access a desired account. In this regard, the multifactor authentication typically involves usernames and passwords combined with tokens or biometrics. While multifactor authentication greatly enhances security, it does not necessarily replace the traditional password method. This is in part due to multifactor authentication solutions being used in limited contexts, e.g., users may use these solutions at work, but cannot use the same solution within their personal lives. Furthermore, as the user can potentially be anyone nowadays, e.g., the elderly, people with disabilities, etc., many multifactor authentication solutions are not easily used by people with specific needs and disabilities, and often if usability is improved, the security is often reduced. Moreover, in some cases, even multifactor authentication methods can be vulnerable to attacks, especially if it is not properly implemented.
[0008] Therefore, in light of the foregoing discussion, there exists a need to overcome the aforementioned drawbacks.
[0009] SUMMARY
[0010] The aim of the present disclosure is to provide an authentication system and method to provide secure and user-friendly authentication that enhances security. The aim of the present disclosure is achieved by a system and method for authentication as defined in the appended independent claims to which reference is made to. Advantageous features are set out in the appended dependent claims.
[0011] Throughout the description and claims of this specification, the words "comprise" , "include", "have", and "contain" and variations of these words, for example "comprising" and "comprises" , mean "including but not limited to", and do not exclude other components, items, integers or steps not explicitly disclosed also to be present. Moreover, the singular encompasses the plural unless the context otherwise requires. In particular, where the indefinite article is used, the specification is to be understood as contemplating plurality as well as singularity, unless the context requires otherwise.
[0012] BRIEF DESCRIPTION OF THE DRAWINGS
[0013] FIG. 1 is a flowchart of steps of a method for authentication, in accordance with an embodiment of the present disclosure;
[0014] FIG. 2 is a pictorial representation of a process flow of a method for authentication, in accordance with an embodiment of the present disclosure;
[0015] FIG. 3 is an exemplary flowchart of a successful login to a service provider, in accordance with an embodiment of the present disclosure;
[0016] FIG. 4 is an illustration of an environment of a system for authentication, in accordance with an embodiment of the present disclosure;
[0017] FIGs. 5-9 are illustrations of exemplary clue-secret combinations, in accordance with various embodiment of the present disclosure; and
[0018] FIG. 10 is a pictorial representation of providing a user input for a presented clue, in accordance with an embodiment of the present disclosure.
[0019] DETAILED DESCRIPTION OF EMBODIMENTS
[0020] The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of carrying out the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for carrying out or practising the present disclosure are also possible.
[0021] In a first aspect, the present disclosure provides a method for authentication, the method comprising:
[0022] (a) receiving an access request for accessing a service platform; (b) providing an authentication request, wherein the authentication request comprises a clue of a clue-secret combination;
[0023] (c) receiving a user input corresponding to the authentication request;
[0024] (d) determining whether the user input matches a secret of the cluesecret combination; and
[0025] (e) when it is determined that the user input matches the secret of the clue-secret combination, authenticating access to the service platform.
[0026] The method provides a novel, multifaceted, multifactor, multilayered digital authentication solution that seamlessly authenticates users across multiple systems and services. In this regard, the method offers a consistent authentication process for accessing online services or organizational systems using a clue-secret combination. The clue-secret combination provides a relatable (easy to remember) clue (namely, memory cue) to the user for which a corresponding secret is securely created by the user based on a personal memory of details relating to the clue. The said clue-secret combination brings additional secrecy level as such a combination can be selected randomly by the authentication system and are easy to remember by the user. Thereby providing a user- friendly way of authentication without requiring to memorize usernamepassword combinations for multiple service providers or eliminating the need for regeneration of a new password in an event of forgetting the password thus saving system recourses, data capacity and power. Moreover, the method also provides user-friendliness, inclusivity, and adaptability to different contexts and user abilities.
[0027] As an example, an access request for accessing the service platform is received from a user device. This access request is typically a login attempt to the service platform. In one example the implementation login screen of the service platform comprises a login button via which information is sent (directly or via the service platform) to the authentication system. As response for the login attempt (access request) the authentication request is provided to the user device from the authentication system (the system or system for authentication). The authentication request comprises a clue of a clue-secret combination. The clue can be for example a digital file (such as an image). This clue is displayed to the user and user makes a user input (the secret) corresponding to the authentication request (i.e. to the clue). This user input is received by the authentication system. The authentication system determines if the user input matches the secret of the clue-secret combination. If there is a match then the user device is authenticated to access the service platform. Technically the authentication can be done by the authentication system by sending encrypted code to the service platform or to the user device which provides that to the service platform. Synergistic effect of this method is to provide additional layers of security or an alternative to "traditional" password method.
[0028] Herein, in an implementation, the present disclosure provides a method for authentication, the method comprising:
[0029] (a) receiving an access request for accessing a service platform;
[0030] (b) creating a dynamic linking code or an authentication code, and a message authentication code (MAC), and providing an authentication request to a user device, wherein the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), wherein the clue of the clue-secret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of messages, and wherein the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the clue-secret combination;
[0031] (c) receiving a user input corresponding to the authentication request and the message authentication code (MAC), wherein prior to step (c) the user is authenticated to use the user device using a biometric authentication;
[0032] (d) determining whether the user input matches a secret of the cluesecret combination; and
[0033] (e) when it is determined that the user input matches the secret of the clue-secret combination, authenticating access to the service platform, wherein the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction.
[0034] In a second aspect, the present disclosure provides an authentication system, the authentication system configured to:
[0035] (a) receive an access request from a user device for accessing a service platform;
[0036] (b) provide an authentication request to the user device, wherein the authentication request comprises a clue of a clue-secret combination;
[0037] (c) receive a user input corresponding to the authentication request from the user device;
[0038] (d) determine whether the user input matches a secret of the clue-secret combination; and
[0039] (e) when it is determined that the user input matches the secret of the clue-secret combination, authenticate access for the user device to the service platform.
[0040] The authentication system, also referred as "the system" or "system for authenticating", is a multifactor authentication system designed to replace the traditional password-based authentication process. The authentication system provides an enhanced authentication process for users using a clue-secret combination that makes the authentication process more secure, robust and easier for the user. Moreover, the authentication system saves system resources, data capacity and calculation power by using the same authentication system across multiple different services and employing multiple data storage means. Furthermore, the method reduces "new password"-requests when accessing a service.
[0041] Herein, in an implementation, the present disclosure provides an authentication system, the authentication system configured to:
[0042] (a) receive an access request from a user device for accessing a service platform;
[0043] (b) create a dynamic linking code or an authentication code, and a message authentication code (MAC), and provide an authentication request to the user device, wherein the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), and wherein the clue of the clue-secret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of messages, and the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the clue secret combination;
[0044] (c) receive a user input corresponding to the authentication request from the user device and the message authentication code (MAC), wherein prior to step (c) the user is authenticated to use the user device using a biometric authentication;
[0045] (d) determine whether the user input matches a secret of the clue-secret combination; and
[0046] (e) when it is determined that the user input matches the secret of the clue-secret combination, authenticate access for the user device to the service platform, wherein the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction.
[0047] The present disclosure provides the method for authentication. Herein the term "authentication" refers to the process of verifying and confirming the identity of a user before granting them access, upon receiving an access request, to a service platform (such as an online service, an organizational setting, an offline application (e.g., a vault door, a mobile application), and so on) through the aforementioned authentication system.
[0048] The method comprises receiving an access request for accessing a service platform. The term "access request" as used herein refers to a user's request to access the service platform. The access request typically involves initiating the user's login or entry into a digital service platform, for using their account or access specific resources on the service platform.
[0049] Optionally, the access request comprises at least one of: providing a username associated with the service platform, providing a username password pair associated with the service platform. Typically, the user, when initiating an access request to the service platform, can opt to authenticate solely by providing a valid username associated with the service platform, or a valid username-password pair. The username is verified for its authenticity against the registered usernames within a database of the service platform. If a match is found, an additional security check, such as by means of a password corresponding to the username, is subjected to a subsequent verification. In such doubleverification process, the user is granted access when both the username and the corresponding password are verified by the service platform. Optionally, a secure authentication algorithm is employed by the method to verify the correctness of the provided credentials. The technical benefit is the flexibility to accommodate various access request formats, including the presence or absence of a username and password. This allows the authentication system to adapt to different service platforms and access request methods.
[0050] Moreover, the method comprises of providing the authentication request, wherein the authentication request comprises the clue of the clue-secret combination. Herein the term "authentication request" refers to a digital message or signal sent from the authentication system to the user, upon receiving the access request, during a first-time login or any subsequent access processes for a given service provider. It may be appreciated that authentication is an important security measure used to protect user accounts and sensitive information from unauthorized access to the service platform. In this regard, the authentication of a user ensures that the user is who they claim to be, and they have the appropriate permission to access the requested service.
[0051] It may be appreciated that the authentication process begins with the initial requirement for the user to complete a registration process on the authentication platform. During the registration process (to the authentication platform) or anytime before an authentication process is initiated, the user is required to provide a unique identifier (e.g., username or email address) and create at least one clue-secret combination, preferably, at least two clue-secret combination, which will be used during the authentication process to authenticate user on the service platform thereafter.
[0052] During authentication to a service platform the user provides the unique identifier to the service platform. Thereafter, the authentication request, that includes a clue, is provided to the user to recognize or confirm or associate the same with the corresponding secret as defined during the registration process or anytime before the authentication process is initiated. The user receives the authentication request on their user device from which the user initiated the access request. The user device is typically a computer, smartphone, tablet, or any device they are using to access the service platform or authentication system. Provision of the authentication request is triggered by user providing the unique identifier directly to the service platform from the user device or the unique identifier is provided to the authentication system (for example via the web site, web page or an application on the user device).
[0053] Beneficially, the authentication process of the present disclosure is a multifactor, multi-layered authentication process, which includes (i) a biometric authentication verified using a device, and (ii) a questionresponse (namely, clue-secret combination) verification by means of the disclosed authentication system configured to present a clue to which the user responds with a secret only known to them to verify the user.
[0054] Herein, the term "clue-secret combination" refers to a set of information comprising two components, i.e., a clue and a secret.
[0055] The term "clue" refers to a memory cue that could be personally relatable by the user. The clue is implemented as a digital object, such as an image, a haptic feedback (like vibrations), an audio, a video, or any other digital information used as a personalized and memorable trigger during the authentication process. Therefore, the clue acts as a personalized reminder, that has personal meaning or significance to them. It may be appreciated that clues are presented using the authentication system in a secure manner (i.e., a clue is only presented to the user and no one else). Such as, the clues that are for example, images or photos are displayed on a screen associated with the authentication system, and the haptic clues (e.g., vibrations) are presented via a suitable device associated with the authentication system.
[0056] Moreover, an auditory clue is provided in the authentication process when there is an in-ear device (e.g., earbuds, headset, headphones, etc.) included in the process and associated with the authentication system. In this regard, the authentication system, particularly, a user device associated with the aforementioned authentication system, can use auditory clues only when there is information available to said user device that an in-ear device is in use and in the ear. Beneficially, the in-ear devices provides improved security for the auditory clues so that the people in the surrounding area of the user may not be able to hear the auditory clue. Moreover, the in-ear devices dampen any environmental noise to enable the user to hear the auditory clue without any external interruption during the authentication process.
[0057] Herein, the term "secret" refers to a psychological response created by the user associated with a specific clue. The secret is a confidential piece of information that the user creates during the registration process (or anytime before an authentication process is initiated) to be used during the authentication process when they attempt to access a service platform.
[0058] Typically, the secret is secure in terms of complexity, length, and hard to guess by other people. Optionally, the secret includes a text-based code, a series of vibrations, eye movements, brainwaves (EEG), or other secure and unique identifiers, depending on the technology and user preferences. Optionally, the secret includes fingerprint scans, ECG data, retina scans, or other physical biometrics. Optionally, the text-based secret includes at least one letter, at least one number, at least one special character, spaces and emojis. Optionally, the secret includes 6- 64 characters. Optionally, the secret includes a combination of upper- and lower-case characters for added security. Optionally, the emojis include faces presenting emotions and are distinctly different from each other to reduce the possibility of interference. It may be appreciated that emoji, e.g., fruit, may provide criminals with a clue to the text part of the secret and therefore should be avoided from use in the secret. Moreover, it will be appreciated that auditory secrets may be heard by others within the environment and therefore should be avoided for security reasons. Alternatively, optionally, the secret is an auditory input.
[0059] Typically, the clue inspires the user to create a corresponding suitable secret during the registration process, anytime before an authentication process is initiated, or during an updating process, and aid the user in recalling the corresponding secret during subsequent accesses to the service provider. In this regard, when the user encounters the clue, it triggers their memory, helping them to recall the corresponding secret. This approach enhances the security and convenience of the authentication process, as users are less likely to forget their secrets when they are associated with meaningful clues. For example, if the user chooses a photo of their pet as a clue, it's something that is easy for them to recognize and remember, and provide a secret corresponding thereto, such as at least one of: a name of the pet, number of years of association, a memory therewith, and so on.
[0060] Optionally, a limited number of clue-secret combinations are created at one time before the authentication process is initiated. Optionally, the user is required to create a minimum of two clue-secret combinations. Optionally, the user is required to create 5-9 clue-secret combinations at a time. Indeed, it has been found that 5-9 is particularly useful as it is optimum for memorability. Optionally, the user is required to create six clue-secret combinations. It will be appreciated that all the clue-secret combinations are discrete and unique from each other. Beneficially, such clue and secret combination bring higher levels of security.
[0061] Optionally, the clue-secret combination is created by: providing a digital information; using the provided digital information as the clue; creating the secret corresponding to the clue; and using the digital content and the secret as the clue-secret combination. In this regard, the digital information is provided to the user via a suitable input / output (IO) device, such as a user device, associated with the user. The user is required to select one or more digital information to be used as one or more clues during registration for the authentication service. The user may choose from a predefined set of digital information provided / presented to the user, typically by initiating a search amongst the provided / presented predefined set of digital information. Alternatively, the user may use a search engine or browse through their own image collection to find pictures or any digital information that can be used as a clue. For each of the selected one or more clues, the user is subsequently required to create a corresponding secret. The secret may be generated by the authentication system at the time of user registration (or anytime before an authentication process is initiated). After storing the one of multiple clues and their corresponding secrets, the authentication system creates combinations of clues and secrets, namely clue-secret combination. Such clue-secret combination is used by the user for a potential authentication thereof.
[0062] Optionally, the digital information comprises at least one of: an image, a set of images, a video, an audio, a text, a data that triggers haptic output on a user's device. The users can select or create digital content using for example an image, a short video, an audio clip, a piece of text, a specific data pattern, or any suitable combination thereof, that is meaningful and relatable to them. The technical benefit of selecting from a variety of digital information is that it allows the users to select clues that suit their individual needs and preferences, which are meaningful and can be memorized for a long-term.
[0063] Optionally, the two or more secrets are allocated to a single clue. Herein, instead of having just one secret corresponding to that clue, multiple secrets may be linked to the same clue and these secrets are usually discrete and unique from each other for a given clue. In an example, if the clue is user's favourite song "Quit Playing Games", the user might have multiple secrets such as song title (Quit Playing Games), singer (Backstreet Boys), an album or movie, a memory (basketball court), etc. associated with it. The user may then choose the two or more secrets corresponding to that clue, such as QPL+BB+BBC. Thus, clue and its corresponding secret are combined to form the clue-secret combination for use in a potential authentication process.
[0064] Optionally, the one or more secrets are allocated to a single clue. In this regard, just one secret corresponding to that clue. In this regard, either one single secret is allocated to a given clue, providing an easy cluesecret combination; or multiple secrets are allocated to a given clue, thus ensuring enhanced security of the clue-secret combination.
[0065] Furthermore, the method comprises of receiving the user input corresponding to the authentication request. The user responds to the authentication request, received on their user device, by providing the necessary input in response to the clue, by means of the corresponding secret to the clue. For example, text-based input is provided as the secret to the clue using the keyboard on the user device.
[0066] Moreover, the method comprises receiving the user input corresponding to the authentication request and the message authentication code (MAC), wherein prior to receiving the user input, the user is authenticated to use the user device using the biometric authentication. It may be appreciated that the user input does not include MAC, it includes the response from the user, namely the user input, only based on the authentication request. Notably, user input is received by the authentication system from the user that provides his / her response of the user device. The MAC is separately received, wherein the MAC is combined with the user input for authentication of the user. In other words, before a user can proceed with the authentication process, they must first undergo a preliminary biometric authentication on the user device being used for accessing the service platform.
[0067] In this context, the "user device" typically refers to a digital device owned and used by an individual, namely, the user, for accessing the service platform. The user device may include smartphones often equipped with biometric features like fingerprint sensors or facial recognition for user authentication, smartwatches, tablets, laptops, computers and other personal digital devices, which can include a wide range of personal devices like e-readers, digital assistants (e.g., Amazon Echo, Google Home), or even specialized devices designed for specific tasks (e.g., a dedicated device for accessing a particular service). Optionally, the user device comprises a first user device and a second user device, wherein at least one of the first user device, the second user device has biometric authentication (or verification) capabilities. Optionally, the first user device and the second user device may be the same device, for example, a mobile phone, compatible for biometric authentication. Optionally, the first user device and the second user device may be separate devices, wherein at least one of them being compatible for biometric authentication. Herein, for example, optionally, the first user device is implemented as a laptop, and is not compatible for biometric authentication, and the second user device is implemented as a mobile phone or a watch-style user device, and is compatible for biometric authentication. Notably, the user device when implemented as the mobile phone, is configured to be used to enter a web address of the service provider as well as for biometric authentication. However, the user device when implemented as a laptop, is configured to be used to enter a web address of the service provider but not for biometric authentication. Similarly, the user device when implemented as a watch-style user device, is configured to be used for biometric authentication but not to enter a web address of the service provider. Optionally, the user device is a software application on a smart mobile device, for example, mobile phone or smartwatch device. Alternatively, optionally, the user device is a separate device used solely for the purpose of authentication with the aforementioned method and authentication system, and / or authentication for physical access e.g., opening doors authorized through the aforementioned method and authentication system. It may be appreciated that the user device is configured to present an image, a sound or a haptic (vibrate) digital information. Moreover, the user device is compatible with an isolated means, such as earbuds, headphones, headset, or microphone, if the clue and / or the secret is in the form of a sound. Moreover, the user device is configured to communicate with the aforementioned authentication system via a safe communication interface. It may be appreciated that the user may be associated with more than one user device. However, no more than one user device can be activated at one time by one user, wherein the activation is by using one or more physical biometrics belonging to the user. Moreover, the user device is configured to receive a power supply from an external charging mechanism, such as plugging a USB cable into any port. However, the charging mechanism should not allow any security breaches. Furthermore, the user device is configured to receive any notifications of authentication requests and / or dynamic linking codes or equivalent authentication codes and / or MAC / s and presents such notifications and / or dynamic linking codes or equivalent authentication codes to sign-in to a specific service.
[0068] Optionally, for increased security purposes, the user input with the corresponding secret is provided by a separate device which is then sent to the aforementioned authentication system for confirmation.
[0069] The user typically needs to prove their identity using biometric features on at least one of the user devices configured for accessing the service platform. Notably, biometric authentication is a method of verifying an individual's, namely, user's, identity based on unique physiological or behavioral characteristics. Optionally, the biometric authentication is based on physiological biometric, such as fingerprints recognition, iris or retina scans, facial recognition, DNA matching, ECG waves, brainwaves (EEG), etc., and behavioural biometrics, such as voice recognition, keystroke dynamics, gait analysis, etc. Optionally, the biometrics of the user are stored on a storage medium associated with the user device, and nowhere else, for privacy purpose. Beneficially, the biometric authentication helps maintain user privacy and confidentiality, as only the authorized user can initiate the authentication process on the user device. Once the user device confirms the user's identity through biometric authentication, the user is then allowed to proceed with the authentication process, which includes the presentation of a clue and the user input comprising the corresponding secret. In other words, the user input is received from user associated with a verified or biometric- authenticated user device.
[0070] The main technical benefit of biometric authentication of the user device is that it provides a strong initial layer of identity verification. It ensures that the user who initiates the authentication process is indeed the authorized user of the device, reducing the risk of unauthorized access.
[0071] Furthermore, the method comprises determining whether the user input matches a secret of the clue-secret combination; and when it is determined that the user input matches the secret of the clue-secret combination, authenticating access to the service platform. In other words, it is determined that the secret provided by the user, namely the user input, is same as the secret that was associated with the clue during the clue-secret combination creation i.e., during the registration process or anytime before an authentication process is initiated. In this regard, each character or element in the user input corresponding to the authentication request is matched to each character or element (such as emojis in a text-based or text-image-based secret, etc.) of the stored secret of the clue-secret combination, and subsequently the user input is confirmed or verified if it matches character-by-character (or element- by-element) with the stored secret. Moreover, when every character or element in the users input corresponds precisely with the characters or elements in the stored secret, then a match of the user input to the stored secret of the clue-secret combination is confirmed, and the user is recognized as the authorized account holder and user access to the service platform is authenticated. In cases where the secret is an auditory secret, then the method comprises comparing elements selected from at least one: user's voice (depth, pitch), compositions (lyrics and notes) of the auditory secret. Beneficially, such refined matching process is essential for maintaining the security and integrity of the authentication process. Optionally, the method comprises generating a notification, for the service provider and the user, that authentication was successful.
[0072] Optionally, the method further comprises a step (f) of denying the access to the service platform, if the user input does not match with the secret of the clue-secret combination. Herein, if any of the characters or elements of the user input and the secret of the clue-secret combination do not match, the said user input is regarded incorrect. Optionally, the method comprises generating a prompt for the user that the user input is incorrect. The purpose of this matching process is to ensure that only the authorized user, who possesses the correct secret associated with a particular clue, gains access to the service platform. It serves as a security measure to prevent unauthorized access and protect sensitive information or resources.
[0073] Optionally, the method further comprises providing an updated authentication request, wherein the updated authentication request comprises a clue of another clue-secret combination, and repeating steps (c) to (f) of the method using the updated authentication request. Herein, the "updated authentication request" refers to a new or modified authentication request which is provided to the user during the authentication process, if a given user input fails to match with the corresponding secret of a given clue-secret combination. The updated authentication request typically includes a new clue that is different from a given clue for which the user input did not match a given secret of said clue-secret combination. In other words, the new clue is associated with a new clue-secret combination, namely, the another clue-secret combination. It may be appreciated that the new clue may be of same or different form as the previous clue.
[0074] Optionally, the another clue-secret combination is selected randomly from a set of clue-secret combinations. When the user makes another access attempt, the method employs a randomization algorithm to select a new clue-secret combination from the pre-stored set of clue-secret combinations. The randomly selected new clue from another clue-secret combination is included in the new, updated authentication request that is presented to the user upon the next access request generated via the user device. If the new users input comprising a secret corresponding to the new clue of another clue-secret combination matches the pre-stored secret should match the secret associated with this randomly chosen clue of another clue-secret combination, the user is granted access to the service platform, in a similar manner as discussed above. Beneficially, such random selection ensures that the selection is entirely unpredictable and not influenced by any pattern. Moreover, the randomness of the selection process is essential for security, as it prevents attackers from predicting or guessing which clue-secret combination will be used next. Such unpredictability adds an extra layer of security to the authentication method.
[0075] However, if the new user input does not match with the pre-stored secret of another clue-secret combination, the user is provided with another updated authentication request iteratively, until a successful match is achieved or until a predetermined limit of such authentication request generation is reached. Optionally, the predetermined limit of such authentication request is at least 2, preferably 3. In such case, if at least two clue-secret combinations have been unsuccessfully attempted, then the authentication request fails, and the user's account is locked for requiring a further user action to unlock the locked account. In an example, after three unsuccessful attempts, the clue-secret combination is locked for future authentication requests until there has been a successful attempt, and a new clue-secret combination is selected, and the clue is sent to the user device.
[0076] Optionally, besides the clue-secret combination, the authentication request further comprises dynamic linking code or equivalent authentication code. The method for authentication comprises sending the dynamic linking code or equivalent authentication code, along with the clue in which the user first confirms the dynamic linking code before being presented with the clue.
[0077] Moreover, the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction. The dynamic linking code (e.g., Payment Service Directive 2) is typically an authentication code that is unique to each transaction, that is linked to a user transaction, or in the case of the method for authentication, unique to each authentication request. The dynamic linking code may be or comprises a random code of letters and numbers, however, it can also take the form of the notification request itself, as it can identify the action the user wants to complete, e.g., asking to sign-in to a specific service. The dynamic linking code may include financial information of the transaction.
[0078] For the purpose of the method for authentication, the authentication system will create an authentication code unique to the authentication request (initiated by the user requesting to authenticate themselves with a service), and will send the authentication code to the device (registered to the user for use with the authentication system) along with the preselected clue by means of encrypted communication. The user will access the authentication request once biometric authentication has authenticated the user with the device. The user will be presented with the authentication request on the device, in the form of e.g., asking to sign-in to a specific service, and the user is requested to either confirm the authentication request is their choice or not. Once the user has confirmed they request to sign-in with the service, then the Clue is presented to them. The user will then respond to the Clue in the form of the Secret. The device then creates an authentication code based on the user responding to the authentication request and the user responding to the clue, and by means of encrypted communication, the two responses are transmitted back to the authentication system.
[0079] It may be appreciated that, optionally, the dynamic linking code is required to be accepted by the user before the clue of the clue-secret combination is revealed to the user. Moreover, optionally, the dynamic linking code and clue should only be visible to the user after the biometric authentication step.
[0080] As mentioned above, the authentication request comprises the message authentication code (MAC). MAC is a short piece of data / information used for checking the authenticity and integrity of the message. This can confirm that the message came from the expected sender and has not been tampered with during the transmission. MAC is used for confirming the security and integrity of messages, and wherein the MAC is sent with all communications during stages of the authentication process. In this regard, MAC is used for example with authentication request, user input, or notification messages. MAC allows verifiers to detect any changes to the message and its content. For the purpose of the method of authentication, the MAC will be created by the authentication system (and potentially, the device (dependent on the device)), and are sent with all communications during all the stages of the authentication process to ensure the integrity of all communication. Optionally, the secret is hashed and salted before it is received by the aforementioned authentication system from the user device. Moreover, the method comprises identifying that the integrity of the MAC communication is intact, i.e., not tampered with or intercepted. With a correct secret confirmed, notification is sent to service platform and the user is made aware that authentication was successful.
[0081] The present disclosure also relates to the authentication system as described above. Various embodiments and variants disclosed above, with respect to the aforementioned method, apply mutatis mutandis to the authentication system.
[0082] In general, the term "authentication system" refers to a structure and / or module that include programmable and / or non-programmable components configured to store, process and / or share information for authentication. Optionally, the authentication system includes any arrangement of physical or virtual computational entities capable of enhancing information to perform various computational tasks. Furthermore, it will be appreciated that the authentication system may be implemented as a hardware server and / or plurality of hardware servers operating in a parallel or in a distributed architecture. In an example, the authentication system may include components such as a memory, multiple processors, a data communication interface, a network adapter, and the like, to store, process and / or share information with other computing devices.
[0083] Moreover, the term "authentication system" as used herein refers to a set of algorithms, a software application, a software product, a computer program, a process, or a computing device that responds to requests for information or services by another application, program, process or device (such as the external device, or the user device) via a network interface. Optionally, the authentication system also encompasses software that makes an act of serving information or providing services possible. A communication means of an external device (such as the user device) may be compatible with a communication means of the authentication system, in order to facilitate communication therebetween.
[0084] The authentication system is configured to perform the steps of the aforementioned method for authorization, comprising:
[0085] (a) receiving an access request for accessing a service platform;
[0086] (b) providing an authentication request, wherein the authentication request comprises a clue of a clue-secret combination;
[0087] (c) receiving a user input corresponding to the authentication request;
[0088] (d) determining whether the user input matches a secret of the cluesecret combination; and
[0089] (e) when it is determined that the user input matches the secret of the clue-secret combination, authenticating access to the service platform.
[0090] Herein, the authentication system is configured to perform the steps of the aforementioned method for authorization. In this regard, the authentication system is configured to receive an access request from a user device for accessing a service platform, as mentioned above. Moreover, the authentication system is configured to create a dynamic linking code or an authentication code, and a message authentication code (MAC), and provide an authentication request to a user device, wherein the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), and wherein the clue of the clue-secret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of messages, and the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the cluesecret combination. Notably, the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction.
[0091] Furthermore, the authentication system is configured to receive a user input corresponding to the authentication request from the user device and the message authentication code (MAC), wherein prior to the step of receiving a user input, the user is authenticated to use the user device using a biometric authentication.
[0092] Furthermore, the authentication system is configured to determine whether the user input matches a secret of the clue-secret combination; and when it is determined that the user input matches the secret of the clue-secret combination, authentication system is configured to authenticate access for the user device to the service platform.
[0093] Optionally, the authentication system is configured to notify the user and / or the service platform in cases where authentication was successful as well as unsuccessful. This notification is also securely communicated by incorporating additional security measures, such as Message Authentication Codes (MAC) for confirming the integrity of communications.
[0094] In an embodiment, the authentication system is further configured to perform a step (f) of denying the access to the service platform, if the user input does not match the secret of the clue-secret combination.
[0095] In an embodiment, the authentication system is further configured to provide an updated authentication request, wherein the updated authentication request comprises a clue of another clue-secret combination, and repeating steps (c) to (f) using the updated authentication request, wherein the another clue-secret combination is selected randomly from a set of clue-secret combinations.
[0096] In an embodiment, the authentication system is configured to create the clue-secret combination by: providing a digital information, wherein the digital information comprises at least one of: an image, a set of images, a video, an audio, a text, a data to cause a user terminal to provide haptic output; using the provided digital information as the clue; creating the secret corresponding to the clue; and using the digital content and the secret as the clue-secret combination, wherein one or more secrets are allocated to a single clue.
[0097] In an embodiment, the access request comprises at least one of: providing a username associated with the service platform, or providing a username password pair associated with the service platform.
[0098] Optionally, the authentication system further comprises a database configured to securely store therein at least one of: one or more cluesecret combinations, including another clue-secret combination; user information provided by the user during registration process or anytime before an authentication process is initiated. It may be appreciated that as little information as possible should be collected from the user and stored on the database for privacy reasons. Beneficially, storing the one or more clue-secret combinations on the database, and not on a user device, saves system recourses, data capacity and power, and increases security in the circumstance that the user device is lost or stolen.
[0099] Optionally, the authentication system is implemented as a backend system and a frontend system, wherein the frontend system is configured for allowing the user to change any clue and / or secret. The backend system is configured for generation and storing of the clue-secret combinations, the another clue-secret combinations, etc.
[0100] In an embodiment, the method for authentication is a multifactor and multi-layered authentication solution including locally stored biometrics, secure communication and a trusted device. The device can be the user's mobile phone, or another smart device with biometric capabilities. Prior to the authentication process, there is a registration process in which the user creates an account and provides their email address, and the Clues and Secrets that they wish to use in the authentication process. The Clues are memory cues to help the user remember their Secret codes. These can include personal images that the user chooses and uploads in the registration process. From these Clues, the user will create Secret codes also within the registration process. The user will create only six Secrets from the six Clues they upload. But will only use one Secret for each authentication request. Within the authentication process, when authentication to a system or services is required, the authentication system will choose one of the six Clues and will require the user to respond to the selected Clue with the corresponding Secret. Authentication process in one embodiment, involves the user will:
[0101] 1. Click on the login with button authentication method button on the service / system website;
[0102] 2. Type / input their email address;
[0103] 3. Use their biometrics to identify themselves with their registered device;
[0104] 4. a) confirm they want to authenticate with the service (Authentication request);
[0105] 4. b) be presented with Clue (Authentication request);
[0106] 5. Enter the correct Secret in response to the Clue;
[0107] 6. Be granted access to the service / system if Secret is correct. In addition to the use of biometrics used to identify the user to the device, dynamic linking codes are communicated and used to confirm the authentication request. All data within the authentication process is encrypted before transmission and message authentication codes (MAC) is used to ensure the integrity of the communication.
[0108] EXPERIMENTAL PART
[0109] In an example, a visually impaired user successfully logged-in to his organization Y's IT-system (information technology), using a separate watch-style or mobile phone-type user device (hereafter, referred to as the user device for this example) that was adapted for visually impaired users. The user had already created a user account supplying his email address for the IT-system. For authentication, on his subsequent access to the organization Y's IT-system, the user went to organization Y's IT- system, using assistive technology, the user entered email address / username and clicked login / selected authentication process login button. An authentication request was sent to the authentication system. The user activated his user device, and verified himself using biometric(s), e.g., a fingerprint. The authentication system recognized the user device activation and the user had been verified to use the user device. The authentication system randomly selected one clue-secret combination, and sent the authentication request to the user device including the clue. The user device read aloud: "Would you like to authenticate with Organization Y?". As a response, the user clicked or indicated with the user device, his response, that is "yes". The clue was revealed which took the form of a vibration. The user entered the corresponding secret, by spinning the bezel on the watch face or drawing a pattern on the mobile device's screen and it indicated characters through vibrations for the user to select. The secret was sent back to the authentication system. The authentication system confirmed the secret is correct. The authentication system notified the user and the Organization Y that the authentication was successful. The user gained access to his Organization Y's IT-system.
[0110] In another example, a user (e.g., doctor / nurse) successfully logged in to her organization's (e.g., hospital) IT-systems (work: highly time- critical / essential context), using a separate watch-style device. The doctor / nurse has already created a user account supplying their email address. When entering the ward, the doctor / nurse went to the hospital IT-system on a hospital terminal and entered her email address / username and clicked login using the disclosed authentication solution's (authentication system's) login button. The access request was sent to the authentication system, which checked for the activation of the user device activated by the user, and verified themselves using biometrics authentication, e.g., a fingerprint. The authentication system recognized the user device activation and user verification and randomly selected one clue-secret combination. The authentication system sent an authentication request: "Would you like to authenticate with hospital?" with the clue of the clue-secret combination to the user device. The user device displayed the notification. The user clicked "yes" and the clue was revealed. The user entered the corresponding secret. The secret is sent back to the authentication system for confirmation whether the secret is correct or not. The authentication system notified the user and the hospital that authentication was successful. The user (doctor / nurse) gained access to their hospital X's IT-systems. When the user walked away from the ward terminal that they are logged into, it was locked. To gain access quickly to the IT-systems on the ward terminal, the user needed to only activate the user device and use biometrics verification to gain access. A time limit was set for the two latter steps depending on working hours (time required to have access to specific essential systems). DETAILED DESCRIPTION OF THE DRAWINGS
[0111] Referring to FIG. 1, illustrated is a flowchart 100 of steps of a method for authentication, in accordance with an embodiment of the present disclosure. At step 102, an access request is received for accessing a service platform. At step 104, an authentication request is provided, wherein the authentication request comprises a clue of clue-secret combination. Herein, at step 104, a dynamic linking code or an authentication code, and a message authentication code (MAC) is created, and an authentication request is provided to a user device, wherein the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), and wherein the clue of the cluesecret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of the messages, and wherein the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the cluesecret combination. At step 106, a user input corresponding to the authentication request and the message authentication code (MAC) is received. Herein, the user input is accompanied by a message authentication code (MAC). Herein, prior to step 106, the user is authenticated to use the user device using a biometric authentication. It may be appreciated that the clue, the dynamic linking code and / or the authentication code is revealed to the user only after the biometric authentication thereof. At step 108, it is determined whether the user input matches a secret of the clue-secret combination. At step 110, when it is determined that the user input matches the secret of the clue-secret combination, access to the service platform is authenticated or granted. Notably, the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction.
[0112] Optionally, at step 112, a double-authentication may be initiated, when it is determined that the user input matches the secret of the clue-secret combination, access to the service platform is authenticated. Optionally, at step 114, an updated authentication request is provided, wherein the updated authentication request comprises a clue of another clue-secret combination, and repeating steps 106 to 112 using the updated authentication request.
[0113] Referring to FIG. 2, illustrated is a pictorial representation of a process flow 200 of a method for authentication, in accordance with an embodiment of the present disclosure. A user wants to access a service platform 206 with a user device 202 having a display 203. Herein, the user device may be configured for biometric authentication, namely a first user device, or may be configured for biometric authentication, namely a second user device. User enters web address of the service platform 206 using a first or second user device, and receives a code, such as a dynamic linking code or an authentication code, and the message authentication code (MAC), and provides an authentication request to the user device, for rendering a web page 202 related to the service platform 206. Herein, the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), wherein the clue of the cluesecret combination is provided along with the dynamic linking code or with the authentication code as the authentication request, and wherein the MAC is used for confirming the security and integrity of messages, and wherein the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the clue-secret combination. The user enters an email address, for example user@example.com, and clicks login button 204 on the user interface of the user device 202, the first user device or the second user device, to access the service platform 206. An access request is sent to the authentication system 208 by the user device 202 (alternatively, the access request is sent to the authentication system 208 via the service platform 206.). Upon, receiving the access request, the authentication system 208, sends an authentication request, comprising a clue 210 (the clue in this example is image of two persons and some objects) of the clue-secret combination, and the dynamic linking code or the authentication code, and wherein the clue of the cluesecret combination is provided along with the dynamic linking code or with the authentication code as the authentication request, to the user device 202, namely, the first user device or the second user device. Moreover, the MAC is used for confirming the security and integrity of messages, and wherein the MAC is sent with all communications during stages of the authentication request, wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the clue-secret combination. The user receives the notification of the authentication request via web page (for example as a pop up) or application on the user device 202, namely, the first user device or the second user device, and is required to enter a corresponding secret 212 of the clue-secret combination on the user interface of the user device 202. Herein, prior to entering the corresponding secret 212, the user is authenticated to use the first or the second user device using a biometric authentication. It may be appreciated that the clue, dynamic linking code and / or the authentication code is revealed to the user only after the biometric authentication thereof. The secret 212 is sent back to the authentication system 208. The authentication system 208 compares the received user input with the pre-stored secret of the cluesecret combination, and / or the dynamic linking code or the authentication code, and / or the MAC, in a database 214, and confirms that the secret 212 and / or the dynamic linking code or the authentication code, and / or MAC is correct by giving notification (such as "OK") 216 to the user device 202 and gives access to their account on the service platform 206.
[0114] Referring to FIG. 3, illustrated is an exemplary flowchart 300 of a successful login to a service platform 302, such as an online shopping account, using a user device 304 associated with the user 306, in accordance with an embodiment of the present disclosure. Herein, the user device 304 may be implemented as a first user device, that may not be compatible for biometric authentication, but only sending access request. Herein, the first user device may be a laptop or a computer. Alternatively, the user device 304 may be implemented as a second user device, that may be compatible for biometric authentication, but not sending access request. Herein, the second user device is for example, a smart-phone or a watch-style user device. Optionally the second user device may be communicably or operatively coupled to the first user device. Alternatively, the user device 304 may be implemented as a user device that is compatible for biometric authentication as well as sending an access request. At step 1, the user 306 requests access to visit a webpage of the service platform 302, via the user device 304. At step 2, the user 306 enters email address and clicks a login button or simply selects the login button provided on the webpage of the service platform 302. At step 3, the access request is transmitted to the authentication system 308. Steps 3A and 3B are optional additional security steps that seek from the service platform 306 the user email or another user login detail to be provided to the authentication system 308 to look up associated details of the user in its database 310 to recognize at step 3C, that the user account exists. At step 4, the user 306 activates the user device 304, and verifies themselves, by using the user device 304, implemented as the second user device or the separate user device, using biometric authentication, e.g., a fingerprint, upon receiving a request, from the authentication system 308, for user device 304 authentication at step 4A. At step 4B, the authentication system 308 recognizes that the user device 304 is activated by the user and the user is authenticated or verified, namely, by the biometric authentication of the user 306. At step 4C, the authentication system 308 matches the data corresponding to the user device 304 with the database 310 which stores a list of user devices, such as the user device 304, and the ID thereof. At step 5, the authentication system 308 accesses the database 310 to randomly select one clue-secret combination stored in the database 310 that is received at step 5A, and creates a dynamic linking code or an equivalent authentication code at step 5B. At step 6, a clue of the clue-secret combination, along with a dynamic linking code or the equivalent authentication code is sent as an authentication request: "Would you like to authenticate with online shopping customer Y?" to the user device 304, wherein the dynamic linking code or the equivalent authentication code is shared prior to revealing the clue to the user 306 on their user device 304. At step 6A, the user device 304 notifies the user 306 of the authentication request and asks the user 306 to confirm the dynamic linking code or the equivalent authentication code.
[0115] At step 7, user 306 clicks "yes" to confirm the dynamic linking code or the equivalent authentication code and that is provided to the user device 304. At step 8, the clue is revealed / presented to the user 306 for their user input comprising a secret corresponding to the clue, once the dynamic linking code or the equivalent authentication code is confirmed by the user 306. At step 9, the user 306 enters the corresponding secret of the clue-secret combination to the user device 304. At step 10, the secret is sent back to the authentication system 308 for confirmation or validation. At step 11, the authentication system 308 confirms whether the secret is correct or not, by comparing the user input secret with the stored secret of the clue-secret combination stored within the database 310, and at 11A, the authentication system 308 receives confirmation from the database 310 that the user input matches the stored secret. At step 12, the authentication system 308 notifies the service platform 302 that the login of the user 306 was successful via the device 304, and at step 12A, the service platform 302 notifies the user 306 via the user device 304 that authentication was successful. At step 13, the user 306 gains access to their account on the service platform 302.
[0116] Referring to FIG. 4, illustrated is an environment 400 in which the authentication system 402 for authentication operates, in accordance with an embodiment of the present disclosure. The authentication system 402 is implemented as a backend system 402A, and a frontend system 402B. The authentication system 402 further comprises a database 404. The authentication system 402 is communicably coupled to a service platform 406 and with a user device 408 associated with a user 410 over a cloud server 412 which also connects the user device 408 with the service platform 406. The backend system 402A is configured to receive an access request for accessing the service platform 406; create a dynamic linking code or an authentication code, and a message authentication code (MAC), and provide an authentication request to a user device, wherein the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), and wherein the clue of the clue-secret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of messages, and wherein the MAC is sent with all communications during stages of the authentication request, wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the cluesecret combination; receive a user input corresponding to the authentication request and the message authentication code (MAC), wherein prior to step (c) the user is authenticated to use the user device using a biometric authentication; determine whether the user input matches a secret of the clue-secret combination; and when it is determined that the user input matches the secret of the clue-secret combination, authenticate access to the service platform 406. Notably, the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction. Specifically, the user 410 requesting access to the service platform 406 is required to activate their user device 408 to verify their identity using biometric authentication such as fingerprint, facial recognition, retina scan, voice recognition or similar. It may be appreciated that the user device 408 is compatible for both generating the access request for accessing the service platform 406 as well as biometric authentication of the user 410. The access request is sent to the service platform 406 via cloud server 412. The service platform 406 then sends the access request to the backend system 402A. The backend system 402A recognizes the access request and randomly selects a clue form a clue-secret combination which is stored in the database 404 by the user during the registration process or anytime before an authentication process is initiated. The backend system 402A configures the frontend system 402B to present the clue to the user 410, via the cloud server 412 and the user device 408, for the user 410 to provide a user input, i.e., secret based on the presented clue, to the user device 408 and eventually to the frontend system 402B. The frontend system 402B receives the user input, and securely transmits this response to the backend system 402A for verification. The backend system 402A verifies the user input by matching it with secret of cluesecret combination stored in the database 404. The frontend system 402B receives notification from the backend system 402A, indicating whether authentication was successful or unsuccessful and communicates this information to the user device 408. The user device 408 displays this notification to the user 410.
[0117] Referring to FIGs. 5, 6, 7, 8, 9, and 10, illustrated are exemplary cluesecret combinations, in accordance with various embodiments of the present disclosure. As shown, a clue is in the form of a digital information represented as any of: a visual clue (e.g., an image), an audio clue, a haptic clue. A corresponding secret to such clue is in form of a digital information represented as any of: a text-based code, an audio code, a haptic feedback, eye movements, brainwaves (EEG).
[0118] In FIG. 5, the digital information is presented as complete images (clues A, C and D), or a complete audio segment (B), the corresponding secrets for all of which are defined as text-based codes. For example, in clue A, an image of a father is shown, for which the user has created a secret 'Father64#' associated with his memory of that picture being 'father's 64thbirthday'. Similarly, in clues C and D, images of a bike and car is shown, for which the user has created a secret 'My 1stbike' and 'My 2ndcar', respectively, associated with his memory of that picture being his 1stbike and 2ndcar used. For clue B, an audio clip is presented to the user, upon hearing which the user has created a secret 'Cha Cha Cha 2#' associated with his memory of that song that ranked at number 2 globally upon its release.
[0119] In FIG. 6, only a partial clue, by means of a partial image or a partial audio piece, as depicted in black colour, is presented to the user during the authentication process and user provides with the created secret associated with it. For example, in clue A, a partial image of a father, with just eyes and one cheek, is shown, for which the user has created a secret 'Father64#' associated with his memory of that picture being 'father's 64thbirthday'. Similarly, in clues C and D, images of a most remarkable part of a bike and a registration plate of a car is shown, respectively, for which the user has created a secret 'My 1stbike' and 'My 2ndcar', respectively, associated with his memory of that picture being his 1stbike and 2ndcar used which has a certain design of the seat and registration number, respectively. For clue B, only beginning of a song of only 3 seconds is presented as an audio clip to the user, upon hearing which the user has created a secret 'Cha Cha Cha 2#' associated with his memory of that song that ranked at number 2 globally upon its release.
[0120] In FIG. 7, it is depicted that a clue (such as an image clue or an audio clue) may comprise two objects (clues A, C and D) with the corresponding secret that may have two parts. For example, the clue A is an image of the user's father and mother aged 64 and 68 respectively, and thus the corresponding secret "Father64#" #Mother68#" associated with his memory of that picture being 'father's 64thbirthday with mother aged 68'. Similarly, next image clue C comprising a bike and a football, and the secret is " My first bike" "football". And the next image clue D comprises of two images a car and a bullet train and the corresponding secret is "My 2nd car" "fast train". An audio clue is an audio clip which comprises of two songs and the corresponding secret is "Cha Cha Cha 2#" "Waterloo!.#" associated with the user's memory of the first song 'Cha Cha Cha' that ranked at number 2 and the second song 'Waterloo' that ranked at number 1 globally upon their release.
[0121] Now referring to FIGs. 8A and 8B, illustrated are different types of clues and their corresponding secrets, in accordance with an embodiment of the present disclosure. As show, the clues are in for example, the form of visual clues, haptic clues and audio clues, and the corresponding secrets are in for example, the form of text-based codes, brainwaves (EEG), haptic feedback. In clue A, the user selects visual clue to create clue-secret combination from a family photo from user's Mum and Dad's 40th Anniversary. The memory that is associated with the user for this image is that "Aunt Sara fell while dancing and broke all the wine glasses" and user creates the secret as "Allbrokenglasses:40thanniversary". The user can also create haptic clue as well as audio clue from songs. In clue B, for a haptic clue with a certain pattern being formed on a haptic user interface, the memory being the song 'Another one bites the dust - derived from beat', has the corresponding secret "BestQueensongever! 1980" that comprises a haptic feedback when interacting with the device (when entering / selecting the characters of the secret on the device) In clue C, for an audio clue selected by user that is a song by Kaarija and the memory associated with this clue is "My favorite song by Kaarija: Cha Cha Cha which came 2nd at Eurovision". The user creates secret "IVCCC2nd@EV". In clue D, a visual clue selected by the user of Kaarija at the Eurovision Song Contest singing Cha Cha Cha, and the memory of the traditional Cuban dance, the Cha Cha Cha used to create the secret as EEG recording of brainwaves. EEG records brainwaves from the specific areas of the primary motor cortex in a specific order, when these areas are activated while thinking about the steps (Cuban dance moves) to the Cha Cha Cha dance.
[0122] As shown in FIG. 9 (A), the user selects an image and recalls the memories related to that image for e.g., "Sun, Sea, Sand and Love: best holiday ever! 2022 and sunbathing on that beach all day long" and creates a secret code i.e., "S,S,S+V:bhe!22" or a story i.e., "Sunbathing in the Maldives: April2022".
[0123] Similarly, as shown in FIG. 9 (B), the user selects an image of a movie as a clue and recalls the memories related to that image for e.g., "we named the dog Indiana!" 3rdIndiana Jones Movie and Quote from the 3rdmovie: and "X" never, ever marks the spot" and creates a secret code based on the memory i.e., "wntdI!"3rdIJM" or a story i.e., "3rd:and"X"never,evermarksthe spot".
[0124] Referring to FIG. 10, illustrated is a pictorial representation of providing a user input 1102 for a presented clue 1104, in accordance with an embodiment of the present disclosure. The user 1106 is presented with the clue 1104 on their device 1108, the clue 1104 consists of an image selected by the user 1106 at the time of the creation of clue-secret combination. The user 1106 recalls their memory 1110 by seeing the image and responds with a secret by means of the user input 1102, based on the memory 1110 associated with the image, from famous movie, the user 1106 recalls their memory 1110 as a "Quote from the 3rdmovie: and "X" never, ever marks the spot" and gives user input 1102 as "3rd:and"X"never,evermarksthe spot".
Claims
CLAIMS1. A method for authentication, the method comprising:(a) receiving an access request for accessing a service platform;(b) creating a dynamic linking code or an authentication code, and a message authentication code (MAC), and providing an authentication request to a user device, wherein the authentication request comprises a clue of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), and wherein the clue of the clue-secret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of messages, and wherein the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the clue-secret combination;(c) receiving a user input corresponding to the authentication request and the message authentication code (MAC), wherein prior to step (c) the user is authenticated to use the user device using a biometric authentication;(d) determining whether the user input matches a secret of the cluesecret combination; and(e) when it is determined that the user input matches the secret of the clue-secret combination, authenticating access to the service platform, wherein the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction.
2. A method according to claim 1, further comprising (f) if the user input does not match the secret of the clue-secret combination, denying the access to the service platform.
3. A method according to claim 2, wherein the method further comprises providing an updated authentication request, wherein the updated authentication request comprises a clue of another clue-secret combination, and repeating steps (c) to (f) using the updated authentication request.
4. A method according to claim 3, wherein the another clue-secret combination is selected randomly from a set of clue-secret combinations.
5. A method according to any of the preceding claims, wherein the clue-secret combination is created by: providing a digital information; using the provided digital information as the clue; creating the secret corresponding to the clue; and using the digital content and the secret as the clue-secret combination.
6. A method according to any of the preceding claims, wherein one or more secrets are allocated to a single clue.
7. A method according to claim 5 or 6, wherein the digital information comprises at least one of: an image, a set of images, a video, an audio, a text, a data to cause a user terminal to provide haptic output.
8. A method according to any of the preceding claims, wherein the access request comprises at least one of: providing a username associated with the service platform, providing a username password pair associated with the service platform.
9. An authentication system (208, 308, 402), the authentication system configured to:(a) receive an access request from a user device (202, 304) for accessing a service platform (206, 302, 406);(b) create a dynamic linking code or an authentication code, and a message authentication code (MAC), and provide an authentication request (210) to the user device, wherein the authentication request comprises a clue (210, 1104) of a clue-secret combination, the dynamic linking code or the authentication code, and the message authentication code (MAC), and wherein the clue of the clue-secret combination is provided along with the dynamic linking code or with the authentication code, and wherein the MAC is used for confirming the security and integrity of messages, and the MAC is sent with all communications during stages of the authentication request, and wherein the user first confirms the dynamic linking code or the authentication code before being presented with the clue of the clue secret combination;(c) receive a user input (1102) corresponding to the authentication request from the user device and the message authentication code (MAC), wherein prior to step (c) the user (306, 410, 1106) is authenticated to use the user device (202, 304, 408, 1108) using a biometric authentication;(d) determine whether the user input matches a secret (212) of the cluesecret combination; and(e) when it is determined that the user input matches the secret of the clue-secret combination, authenticate access for the user device to the service platform, wherein the dynamic linking code comprises a random code of letters and numbers or a notification request, and wherein the dynamic linking code is unique to each transaction.
10. An authentication system (208, 308, 402) according to claim 9, wherein the authentication system is further configured to deny access to the service platform if the user input (1102) does not match the secret11. An authentication system (208, 308, 402) according to claim 9 or 10, wherein the authentication system is further configured to provide an updated authentication request (210), wherein the updated authentication request comprises a clue of another clue-secret combination, and repeating steps (c) to (f) using the updated authentication request, wherein the another clue-secret combination is selected randomly from a set of clue-secret combinations.
12. An authentication system (208, 308, 402) according to any of the claims 9-11, authentication system is configured to create the clue-secret combination by: providing a digital information, wherein the digital information comprises at least one of: an image, a set of images, a video, an audio, a text, a data to cause a user terminal to provide haptic output; using the provided digital information as the clue (1104); creating the secret (212) corresponding to the clue; and using the digital content and the secret as the clue-secret combination, wherein one or more secrets are allocated to a single clue.
13. An authentication system (208, 308, 402) according to any of the claims 9-12, wherein the access request comprises at least one of: providing a username associated with the service platform (206, 302, 406), providing a username password pair associated with the service platform.
Citation Information
Patent Citations
Systems and methods for trustworthy electronic authentication using a computing device
US11405189B1
Three-factor user authentication method for generating OTP using iris information and secure mutual authentication system using OTP authentication module of wireless communication terminal
US20130268444A1
Real time biometric recording, information analytics, and monitoring systems and methods
US20210106265A1
Methods and systems for augmenting security of biometric user authentication
WO2018009692A1