Authentication Noise Symbols for Eavesdropping-Resistant Pattern Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional authentication systems requiring exact matches for credentials are vulnerable to eavesdropping attacks, such as shoulder surfing, keylogging, and man-in-the-middle attacks, as they expose the exact credential to potential interception, and systems introducing specified noise symbols are easily compromised by attackers knowing the noise positions.
Innovation Solution
Introduce user-specified noise symbols in credentials that are not known to the authenticator, decompose the submitted symbols into vectors, and use a distance metric to determine authentication, ensuring the authenticator is unaware of noise symbol positions or types, thereby enhancing security against eavesdroppers and attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If exact match authentication is used, then authentication precision is improved, but security against eavesdropping attacks deteriorates
Solution Approach 1:
The patent introduces noise symbols as an intermediary element between the user's credential and the authentication system. These noise symbols mask the actual credential, preventing eavesdroppers from capturing the true password while allowing the authentication system to verify the credential through pattern recognition algorithms that can distinguish signal from noise.
Solution Approach 2:
The patent transforms the authentication parameter from exact character matching to distance-based pattern matching. By changing the verification criterion from precise equality to approximate similarity (using distance metrics), the system can tolerate the presence of noise symbols while still accurately authenticating legitimate users.
2Object-affected harmful factors
If noise symbols are introduced at specified positions, then security against shoulder surfing is improved, but vulnerability to attacks knowing noise positions deteriorates
Solution Approach 1:
The patent makes the noise symbol positions dynamic and unpredictable by allowing users to specify their own positions rather than using fixed predetermined positions. This dynamic approach prevents attackers from learning static patterns of noise placement, as the configuration changes with each user's preferences and can be updated over time.
Solution Approach 2:
The patent performs preliminary action by having users pre-specify noise symbol positions and configurations before authentication attempts occur. This preliminary setup creates a personalized authentication pattern that is unknown to attackers, establishing security before any authentication challenge arises.
3Object-affected harmful factors
If user-specified noise symbols are used, then security against eavesdroppers is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service by allowing users to automatically configure their own noise symbol positions and characteristics without requiring complex system setup. The system provides tools for users to define their preferred noise configurations, and the authentication process automatically handles the integration of these user-defined parameters, reducing the burden on system administrators.
Solution Approach 2:
The patent applies partial action by implementing noise symbols only in the credential entry phase rather than throughout the entire authentication system. The core authentication logic remains relatively simple, adding complexity only where necessary (during credential input) while keeping the rest of the system straightforward.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed in some examples are methods, systems and machine-readable mediums which allow for more secure authentication attempts by implementing authentication systems with credentials that include interspersed noise symbols in positions determined by the user. These systems secure against eavesdroppers such as shoulder-surfers or man-in-the middle attacks as it is difficult for an eavesdropper to separate the noise symbols from legitimate credential symbols.