Cognitive Virtual Keyboard Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing human user authentication systems for electronic devices rely heavily on biometric methods, external objects, or passwords, which are vulnerable to attacks, complex to manage, and pose privacy risks.

Innovation Solution

A cognitive-based authentication system that uses a series of cognitive processes unique to each user, such as inference, recognition, transformation, and calculation, to authenticate users through a virtual keyboard interface, eliminating the need for external elements or biometrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric methods or external devices are used for authentication, then security level is improved, but device complexity and implementation cost increase

Engineering Contradiction:
Improvesecurity levelVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication secret from external devices and biometric systems, placing it entirely within the user's mind through cognitive processes. The system eliminates dependence on fingerprint sensors, facial recognition hardware, tokens, or cryptographic keys, using only the user's cognitive capabilities (inference, recognition, transformation, calculation) to generate and verify authentication values dynamically.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables the user's own cognitive processes to serve as the authentication mechanism. The user's brain performs the authentication function through mental operations on displayed elements, making the human cognitive system itself the authentication device, thereby eliminating the need for separate authentication hardware or external security systems.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If passwords are used for authentication, then ease of operation is improved, but security level deteriorates due to copying and impersonation risks

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static passwords into dynamic authentication values that change with each authentication session. The system displays elements in random positions and requires the user to perform cognitive operations (inference, recognition, transformation, calculation) to determine the correct authentication sequence, making each authentication instance unique and不可复制.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously: the positions of displayed elements, the cognitive operations required, the time constraints, and the verification process. These parameter changes ensure that even if an attacker observes one authentication session, the parameters will be different in subsequent sessions, preventing replay attacks and recording attacks.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple unique passwords are required for different services, then security level is improved, but loss of time and user burden increase

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a universal authentication system that can be applied to any service requiring authentication. The cognitive-based method works across different platforms and services without requiring service-specific implementations, and the system can handle multiple authentication scenarios (single sign-on, multi-factor authentication, phishing-resistant authentication) through the same core mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary setup once during initial configuration, where the user learns their personal cognitive characteristics and authentication patterns. After this preliminary action, subsequent authentications are rapid because the user's brain automatically performs the cognitive operations based on established neural pathways, reducing authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If centralized authentication processes are used, then ease of operation is improved, but loss of information and privacy risks increase

Engineering Contradiction:
ImproveusabilityVSAvoidprivacy risk
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the authentication process into client-side cognitive operations and server-side verification only. The user's cognitive processes and authentication values never leave the user's device, and the server only receives and verifies the final authentication result without accessing or storing sensitive authentication data, thereby protecting user privacy and preventing information leaks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4506839A1Mutual authentication system and method
Publication Date: 2025.02.12 PEREZ GRANDE PEDRO
  • EP4506839A1 patent drawingFigure 1
  • EP4506839A1 patent drawingFigure 2
  • EP4506839A1 patent drawingFigure 3A~3E

AI summary

Method and system for mutual authentication. The system comprises : - a virtual keyboard generation unit (210) for obtaining (110) a keyboard configuration (112) of a user (201), including graphical features (114), arrangements (116) and keyboard generation rules (118); and generating (120) a virtual keyboard (212) formed by keys (214) with combination of graphics features (114) in certain arrangements (116) based on the keyboard generation rules (118 ); - an input interface (230) for receiving (140) a key selection (144) of the virtual keyboard (212); - an authentication unit (240) for applying (160) user authentication rules (152) on the virtual keyboard (212), obtaining at least one correct key sequence (162), and authenticating (170) to the user (201) if the key selection (144) is validated with respect to a correct key sequence (162).