Cognitive Virtual Keyboard Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing human user authentication systems for electronic devices rely heavily on biometric methods, external objects, or passwords, which are vulnerable to attacks, complex to manage, and pose privacy risks.
Innovation Solution
A cognitive-based authentication system that uses a series of cognitive processes unique to each user, such as inference, recognition, transformation, and calculation, to authenticate users through a virtual keyboard interface, eliminating the need for external elements or biometrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric methods or external devices are used for authentication, then security level is improved, but device complexity and implementation cost increase
Solution Approach 1:
The patent extracts the authentication secret from external devices and biometric systems, placing it entirely within the user's mind through cognitive processes. The system eliminates dependence on fingerprint sensors, facial recognition hardware, tokens, or cryptographic keys, using only the user's cognitive capabilities (inference, recognition, transformation, calculation) to generate and verify authentication values dynamically.
Solution Approach 2:
The system enables the user's own cognitive processes to serve as the authentication mechanism. The user's brain performs the authentication function through mental operations on displayed elements, making the human cognitive system itself the authentication device, thereby eliminating the need for separate authentication hardware or external security systems.
2Ease of operation
If passwords are used for authentication, then ease of operation is improved, but security level deteriorates due to copying and impersonation risks
Solution Approach 1:
The patent transforms static passwords into dynamic authentication values that change with each authentication session. The system displays elements in random positions and requires the user to perform cognitive operations (inference, recognition, transformation, calculation) to determine the correct authentication sequence, making each authentication instance unique and不可复制.
Solution Approach 2:
The system changes multiple parameters simultaneously: the positions of displayed elements, the cognitive operations required, the time constraints, and the verification process. These parameter changes ensure that even if an attacker observes one authentication session, the parameters will be different in subsequent sessions, preventing replay attacks and recording attacks.
3Reliability
If multiple unique passwords are required for different services, then security level is improved, but loss of time and user burden increase
Solution Approach 1:
The patent creates a universal authentication system that can be applied to any service requiring authentication. The cognitive-based method works across different platforms and services without requiring service-specific implementations, and the system can handle multiple authentication scenarios (single sign-on, multi-factor authentication, phishing-resistant authentication) through the same core mechanism.
Solution Approach 2:
The system performs preliminary setup once during initial configuration, where the user learns their personal cognitive characteristics and authentication patterns. After this preliminary action, subsequent authentications are rapid because the user's brain automatically performs the cognitive operations based on established neural pathways, reducing authentication time while maintaining security.
4Ease of operation
If centralized authentication processes are used, then ease of operation is improved, but loss of information and privacy risks increase
Solution Approach 1:
The patent segments the authentication process into client-side cognitive operations and server-side verification only. The user's cognitive processes and authentication values never leave the user's device, and the server only receives and verifies the final authentication result without accessing or storing sensitive authentication data, thereby protecting user privacy and preventing information leaks.
Data Source
Figure 1
Figure 2
Figure 3A~3E
AI summary
Method and system for mutual authentication. The system comprises : - a virtual keyboard generation unit (210) for obtaining (110) a keyboard configuration (112) of a user (201), including graphical features (114), arrangements (116) and keyboard generation rules (118); and generating (120) a virtual keyboard (212) formed by keys (214) with combination of graphics features (114) in certain arrangements (116) based on the keyboard generation rules (118 ); - an input interface (230) for receiving (140) a key selection (144) of the virtual keyboard (212); - an authentication unit (240) for applying (160) user authentication rules (152) on the virtual keyboard (212), obtaining at least one correct key sequence (162), and authenticating (170) to the user (201) if the key selection (144) is validated with respect to a correct key sequence (162).