Adaptive Visual Authentication Key Selection for Security Usability Trade-off

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods face challenges in balancing usability and security, particularly when multiple users share similar visually distinguishable objects as authentication keys, leading to potential security imbalances and increased risk of malicious access.

Innovation Solution

An authentication system that registers and manages visually distinguishable objects by determining the degree of freedom in object selection based on the number of users, registration period, and category, limiting the registration of objects with high overlap to prevent security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users select from a fixed list of visually distinguishable objects for authentication, then usability is improved, but security deteriorates due to imbalanced selection patterns

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by making the authentication key selection adaptive rather than static. The system dynamically determines the set of displayable objects based on the user's demographic information and selection history, ensuring that each user receives a customized set of objects that balances usability with security. This dynamic adaptation prevents the formation of predictable selection patterns while maintaining ease of operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by customizing the authentication object selection to individual users based on their specific characteristics. Instead of using a uniform fixed list for all users, the system creates user-specific subsets of objects from the total pool, tailored to each user's demographics and preferences. This ensures that each user's authentication experience is optimized for usability while the overall system maintains high security through diversity.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If the same object is registered as authentication key by multiple users, then usability is improved through object reuse, but security deteriorates due to increased predictability

Engineering Contradiction:
Improveobject reuseVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies feedback by implementing a system that monitors and records which objects have been selected as authentication keys by which users. This feedback mechanism allows the system to determine, for each new user, which objects should be made available based on the feedback from previous user selections. The system uses this feedback to create a balanced distribution of object assignment that prevents over-concentration of specific objects among multiple users, thereby maintaining security while allowing controlled object reuse.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting the parameters of object availability based on usage patterns. The system changes the set of displayable objects for registration based on the current state of object assignment across the user population. By modifying which objects are available for selection in different contexts, the system optimizes both usability (through available object choices) and security (through balanced distribution).

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8683577B2Authentication method, authentication device and computer-readable medium storing instructions for authentication processing capable of ensuring security and usability
Publication Date: 2014.03.25 KONICA MINOLTA INC
  • US8683577B2 patent drawing
  • US8683577B2 patent drawing
  • US8683577B2 patent drawing

AI summary

An authentication method in a system having a display and a storage device is provided. The authentication method includes the steps of registering an object selected for each user from among a plurality of visually distinguishable objects prepared in advance as a key object in the storage device; and presenting the plurality of objects to the display, accepting selection of an object by a user to be authenticated, and performing authentication based on matching/mismatching of the selected object with the key object registered in association with the user. The step of registering includes a step of determining a degree of freedom of selection of the object at the time of registration of the key object according to a degree of overlapping of the key object already registered in the storage device.