Dynamic Graphical Authentication with Adaptive Security Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing graphical authentication systems are vulnerable to 'shoulder surfing' and lack adaptive security measures, as they do not effectively prevent unauthorized access or increase security levels after failed authentication attempts.

Innovation Solution

A method for graphical authentication that involves moving a reference point on an overlay image to align with a reference point on a base image, with varying security levels and increased difficulty after failed attempts, using a communication system with a graphical authentication module that adjusts security requirements based on access rights and authentication accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If graphical authentication systems use static passwords or fixed sequences, then ease of operation is improved, but security is worsened due to vulnerability to shoulder surfing and lack of adaptive security measures

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication by allowing users to define custom movable paths between reference points rather than fixed sequences. The authentication challenge dynamically generates different base images with randomly positioned reference points, and the user must trace a flexible path that adapts to each challenge, preventing shoulder surfing while maintaining ease of use through intuitive drag-and-drop interaction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-defining multiple reference points on the base image before the authentication challenge begins. Users are presented with a template showing all reference points and their correct connections, allowing them to mentally prepare and understand the authentication pattern before the actual challenge starts, thus improving ease of operation during the authentication moment.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If graphical authentication systems allow multiple authentication attempts, then ease of operation is improved, but security is worsened due to lack of adaptive difficulty increase

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidadaptive security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting the authentication difficulty based on the number of failed attempts. The system modifies parameters such as increasing the number of reference points, reducing the time limit, decreasing the tolerance threshold for path accuracy, or requiring more complex path patterns as attempts fail, thereby adaptively increasing security while allowing multiple attempts for legitimate users.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms that provide real-time information to users about their authentication progress and performance. After each attempt, the system feedback whether the authentication succeeded or failed, and based on this feedback, dynamically adjusts the difficulty parameters for subsequent attempts, creating an adaptive security system that responds to user behavior.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If graphical authentication systems use simple reference point alignment, then ease of operation is improved, but security is worsened due to lack of complexity in authentication challenges

Engineering Contradiction:
Improvesimplicity of interactionVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the authentication challenge into multiple discrete reference points that must be connected in sequence along a specific path. Instead of a single alignment task, the system segments the authentication into several intermediate steps (reference points), each requiring precise positioning, thereby increasing security through cumulative complexity while maintaining ease of operation through manageable, step-by-step interaction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from simple 2D point alignment to 3D path tracing by requiring users to define not just the position but also the trajectory between reference points. This adds a temporal and spatial dimension to the authentication, where the path taken matters as much as the destination, significantly increasing security while maintaining intuitive drag-and-drop interaction.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2466521B1Obscuring visual login
Publication Date: 2018.11.21 BLACKBERRY LTD
  • EP2466521B1 patent drawingFigure 1
  • EP2466521B1 patent drawingFigure 2
  • EP2466521B1 patent drawingFigure 3

AI summary

A method of authenticating a user of a computing device is proposed, together with computing device on which the method is implemented. In the method a modified base image is overlaid with a modified overlay image on a display and either the modified base image or modified overlay image is moved by the user. A security level requirement is assigned and positive authentication is indicated in response to the base image reference point on the modified base image being aligned with the overlay image reference point on the modified overlay image after the moving in a manner that meets the security level requirement.