Credential Obfuscation via Mixed String Sequences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication systems are vulnerable to hacking as they rely on recognizable image sequences, which can be easily compromised, lacking robustness in credential obfuscation.

Innovation Solution

A system that generates string sequences with mixed prompt and noise characters, where users input credentials among random characters, making it difficult for intruders to hack, and these sequences are updated periodically for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If image sequences are used for credential obfuscation, then user authentication can be performed, but the system becomes vulnerable to hacking

Engineering Contradiction:
Improveauthentication securityVSAvoidhacking vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the visual image-based authentication system with a text-based string sequence system. Instead of displaying images that users must recognize and type, the system now displays strings of characters where the password is interspersed with random noise characters. This substitution of the authentication medium (from visual to textual) fundamentally changes the attack surface and eliminates vulnerabilities associated with image recognition and manipulation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of credential presentation from visual images to text strings with embedded noise. By transforming the authentication interface from displaying recognizable images to displaying randomized character sequences, the system alters the interaction paradigm and security model, making traditional image-based attacks ineffective while maintaining authentication functionality.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If string sequences with noise characters are used, then credential obfuscation is enhanced, but system complexity increases

Engineering Contradiction:
Improvecredential obfuscation strengthVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the password credential into individual characters and intersperses them with noise characters to create a string sequence. This segmentation approach allows the system to maintain the original password integrity while adding layers of obfuscation through random character insertion, achieving enhanced security without requiring complex cryptographic transformations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces noise characters as an intermediary element between the system and the user's password. These noise characters serve as a mediator that obscures the actual credential while allowing the authentication system to still extract and verify the underlying password, thereby enhancing security without fundamentally changing the authentication mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If image sequences are updated, then security can be improved, but cost and complexity increase

Engineering Contradiction:
Improvesecurity strengthVSAvoidupdate cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent employs disposable, easily generated string sequences that can be rapidly created and discarded. Each authentication attempt uses a newly generated string sequence with random noise characters, eliminating the need for expensive, long-lived image assets. This approach allows frequent, cost-effective updates of authentication credentials without the overhead of managing complex image libraries.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10284547B2Facilitating users to obfuscate user credentials in credential responses for user authentication
Publication Date: 2019.05.07 ELECTRONIC ARTS INC
  • US10284547B2 patent drawing
  • US10284547B2 patent drawing
  • US10284547B2 patent drawing

AI summary

A system and method for facilitating users to obfuscate user credentials in credential responses for user authentication are disclosed. A string sequence may be presented to a user for prompting the user to input credential characters sequentially but not continuously. The string sequence may comprise a set of prompt strings containing a prompt character sequence associated with the user and a set of noise strings that do not contain the prompt character sequence. The individual prompt strings in the set of prompt strings may be composed by obfuscating the prompt sequence among noise characters. A user credential response may be received and a user provided credential may be extracted from the received user credential for user authentication.