Cross-device Authentication via Optical Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cross-device authentication techniques are difficult to use, insecure, and prone to attacks such as shoulder surfing and man-in-the-middle attacks, with low adoption rates due to user discomfort and vulnerabilities in two-factor authentication methods.
Innovation Solution
The implementation of sensors on mobile devices to validate the legitimacy of user interfaces, augmented reality-based authentication inputs, and the use of public key infrastructure (PKI) or one-time passwords (OTP) to securely bind web and mobile applications, providing dynamic and camouflaged user interfaces to enhance security and user insight.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional two-factor authentication methods are used, then security is improved, but ease of operation deteriorates due to user discomfort and difficulty in use
Solution Approach 1:
The patent replaces traditional mechanical authentication methods (typing passwords, entering verification codes) with optical recognition technology. Users simply position their device to capture an image, and the system automatically recognizes and verifies their identity, eliminating the need for manual input while maintaining security.
Solution Approach 2:
The authentication system performs automatic image recognition and verification without requiring user intervention beyond capturing the initial image. The system self-verifys the user's identity by recognizing features in subsequent images, making the process as easy as taking a photo.
2Reliability
If traditional authentication methods are used, then security is improved, but device complexity increases due to multiple authentication factors required
Solution Approach 1:
The patent makes the mobile device's camera serve multiple functions: it captures both the initial authentication image and subsequent verification images. This single component performs what would traditionally require multiple separate authentication devices, simplifying the overall system while maintaining security.
Solution Approach 2:
The patent combines the authentication verification process with the device's existing camera functionality. Instead of requiring separate authentication hardware, the system merges security verification into the regular camera operation, reducing device complexity.
3Reliability
If traditional authentication interfaces are used, then security is improved, but object-affected harmful factors increase due to vulnerability to shoulder surfing and man-in-the-middle attacks
Solution Approach 1:
The patent transforms authentication from text-based input (vulnerable to shoulder surfing) to image-based recognition. The visual nature of the authentication images, combined with automatic processing, makes it difficult for attackers to intercept or replicate the authentication process.
Solution Approach 2:
The patent replaces manual authentication interactions (typing, code entry) with automated image recognition. This substitution eliminates the vulnerable intermediate steps where attackers could intercept information, as the system directly processes visual data without requiring user input that could be observed or manipulated.
Data Source
AI summary
Provided is a process, including: receiving a request to authenticate a user to access resources from a first computing device; in response to receiving the request, sending, with one or more processors, instructions that cause the first computing device to display a machine readable image, wherein: the machine readable image is configured to, upon being sensed with a camera of a second computing device, cause the second computing device to present, with a display of the second computing device, a user interface with a user-credential input configured based on the machine readable image displayed by the first computing device; receiving from the second computing device, a value demonstrating possession of a user credential and an identifier of the second computing device, the user credential being entered into the second computing device via the user interface configured based on the machine readable image displayed by the first computing device.


