Dynamic Authentication System Using Seed-Based Password Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password protection methods are inadequate as they rely on single data strings that are difficult to remember, easily guessable, and vulnerable to hacking, leading to security concerns such as identity theft and computer fraud, especially in an era of fast networks and public hotspots.
Innovation Solution
A dynamic graphic user interface (GUI) system that generates a unique password for each authentication session based on pre-defined user criteria, using a sequence of personalized objects and sounds, making it difficult for hackers to discern the password, and employing broadcast communication encryption to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional single data string passwords are used, then the authentication process is simple and quick, but the security is weak and passwords are easily guessable or captured
Solution Approach 1:
The patent implements dynamic passwords that change with each authentication session. The password is generated based on a seed value and timestamp, creating a unique password for each login attempt. This resolves the contradiction by making passwords dynamic rather than static, enhancing security without requiring users to remember multiple complex passwords.
Solution Approach 2:
The patent introduces a password generation algorithm as an intermediary between the user and the authentication system. This algorithm takes a simple seed value and transforms it into a complex, session-specific password. The intermediary handles the complexity while the user only needs to remember the simple seed, resolving the contradiction between security and ease of operation.
2Ease of operation
If users choose simple memorable passwords, then ease of remembering is improved, but security protection against theft is weakened
Solution Approach 1:
The patent segments the password into two parts: a simple, memorable seed value that the user chooses and remembers, and a complex, session-specific component generated by the system algorithm. This segmentation allows users to maintain memorability while the system provides enhanced security through the algorithmic generation of unique passwords for each session.
Solution Approach 2:
The user performs preliminary action by selecting a simple seed value in advance that is easy to remember. The system then uses this seed to generate secure, session-specific passwords automatically. This preliminary action by the user enables both memorability and security without requiring the user to manually create complex passwords.
3Reliability
If passwords are continuously changed to maintain security, then security against hackers is improved, but the risk of user forgetfulness and authentication failure increases
Solution Approach 1:
The patent implements self-service password generation where the system automatically creates secure, session-specific passwords based on the user's seed value and the current timestamp. The user does not need to manually change passwords or go through recovery procedures. The system handles password generation and validation automatically, resolving the contradiction by eliminating the need for manual password changes while maintaining continuous security.
Solution Approach 2:
The patent implements periodic password generation where a new password is automatically created for each authentication session based on the timestamp and seed value. This periodic generation of unique passwords maintains continuous security without requiring manual intervention from the user, eliminating both security risks and forgetfulness issues.
4Reliability
If dynamic session-specific passwords are implemented, then security is enhanced and captured passwords become useless, but the device complexity and computational requirements increase
Solution Approach 1:
The patent replaces complex mechanical or manual password management systems with an algorithmic approach. Instead of using complex hardware tokens or manual password changes, the system uses a computational algorithm that generates session-specific passwords based on simple inputs (seed and timestamp). This substitution reduces device complexity while maintaining enhanced security against captured passwords.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A method for generating a changing authentication input or password generation and input for a user is provided for allowing access to a computing device such as a smartphone or computer or using the computing device to communicate over a network to a server. Using objects displayed in positions on a graphic display, and input strings of text or alphanumeric characters the user has related to each object, or are randomly assigned, a password can be generated by combining the input strings related to paired objects. The password can be varied easily for each access attempt by changing the objects displayed and/or the sequence.