Cognitive Multi-Factor Authentication Without Hardware Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing human-machine authentication methods rely heavily on technology, neglecting the unique cognitive abilities of individuals, leading to increased security risks and complexity, and fail to integrate cryptographic mechanisms effectively for human-based authentication.

Innovation Solution

A method called dopeIN (individual algorithm-based multi-factor authentication) that utilizes the cognitive performance of users, such as perception, attention, and memory, to create a secure authentication process by integrating cryptographic techniques without requiring technical knowledge, allowing for scalable and flexible security enhancement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional hardware components (tokens) and software (2FA, MFA) are integrated into the authentication process, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system allows users to autonomously generate cryptographic key pairs and perform authentication operations using their own devices without requiring centralized token management or additional hardware components. The user's cognitive performance and existing device capabilities serve the authentication function, eliminating the need for external security tokens and reducing system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the authentication functionality from centralized hardware tokens and software systems, distributing it to individual users who perform cryptographic operations locally on their own devices. This removes the dependency on additional hardware components while maintaining security through decentralized cryptographic verification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If the authentication code is transmitted via data transmission (e.g., over the internet), then ease of operation is improved, but security risk increases due to potential decryption

Engineering Contradiction:
Improveauthentication accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two independent components: a public authentication request that can be freely transmitted, and a private cryptographic key pair that remains locally stored on the user's device. Only the public component is transmitted over the network, eliminating the risk of private key interception while maintaining operational accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Cryptographic key pairs serve as an intermediary mechanism that enables secure authentication over untrusted networks. The public key acts as a safe mediator that can be transmitted freely, while the private key remains protected locally, allowing secure communication without exposing sensitive authentication data during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the individual system user's cognitive abilities are utilized for authentication, then security is enhanced, but ease of operation decreases due to cognitive load

Engineering Contradiction:
Improveauthentication securityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual memory-based authentication (where users must memorize and type complex passwords or codes) with cognitive-based cryptographic operations. Users leverage their natural cognitive abilities to perform or verify cryptographic tasks, such as recognizing patterns or solving simple puzzles, which are then transformed into secure authentication credentials through cryptographic functions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If cryptographic techniques are integrated into the authentication process, then security is improved, but device complexity increases due to technical knowledge requirements

Engineering Contradiction:
Improvecryptographic securityVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Users independently generate and manage their own cryptographic key pairs without requiring system administrators or external services to manage complex cryptographic infrastructure. This self-service approach simplifies system implementation while maintaining strong cryptographic security, as each user's device becomes a self-contained security unit.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4409443B1Method for the performance of an authentication process by an individual system user
Publication Date: 2026.04.22 LEIBRECHT UWE
  • EP4409443B1 patent drawingFigure 1
  • EP4409443B1 patent drawingFigure 2
  • EP4409443B1 patent drawingFigure 3

AI summary

The invention relates to a method for the performance of a human-machine authentication process by an individual system user. The object of the invention is to provide an authentication system using technical security systems, comprising hardware and software, for generating, managing and executing an authentication algorithm. According to the invention, this is achieved by virtue of an administrator implementing security fragments in the form of patterns and/or policies and/or algorithm templates, by virtue of the administrator managing the security fragments, by generating the algorithm from implemented security fragments and by linking to an authentication code. The authentication process is carried out by way of credentials and automated generation of temporary authentication data and enables transmission to the individual system user, with a data exchange taking place between the security system and the authentication system through synchronization processes for the purpose of exchanging non-public data. The code is applied by the system user by virtue of the temporary authentication data being converted into a temporary input code and the technical security system carrying out an authentication check.