Dynamic Graphical Authentication with Adaptive Security Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing graphical authentication systems are vulnerable to 'shoulder surfing' and lack adaptive security measures, as they do not effectively prevent unauthorized access or increase security levels after failed authentication attempts.
Innovation Solution
A method for graphical authentication that involves moving a reference point on an overlay image to align with a reference point on a base image, with varying security levels and increased difficulty after failed attempts, using a communication system with a graphical authentication module that adjusts security requirements based on access rights and authentication accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If graphical authentication systems use static passwords or fixed sequences, then ease of operation is improved, but security is worsened due to vulnerability to shoulder surfing and lack of adaptive security measures
Solution Approach 1:
The patent implements dynamic authentication by allowing users to define custom movable paths between reference points rather than fixed sequences. The authentication challenge dynamically generates different base images with randomly positioned reference points, and the user must trace a flexible path that adapts to each challenge, preventing shoulder surfing while maintaining ease of use through intuitive drag-and-drop interaction.
Solution Approach 2:
The system performs preliminary actions by pre-defining multiple reference points on the base image before the authentication challenge begins. Users are presented with a template showing all reference points and their correct connections, allowing them to mentally prepare and understand the authentication pattern before the actual challenge starts, thus improving ease of operation during the authentication moment.
2Ease of operation
If graphical authentication systems allow multiple authentication attempts, then ease of operation is improved, but security is worsened due to lack of adaptive difficulty increase
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting the authentication difficulty based on the number of failed attempts. The system modifies parameters such as increasing the number of reference points, reducing the time limit, decreasing the tolerance threshold for path accuracy, or requiring more complex path patterns as attempts fail, thereby adaptively increasing security while allowing multiple attempts for legitimate users.
Solution Approach 2:
The system implements feedback mechanisms that provide real-time information to users about their authentication progress and performance. After each attempt, the system feedback whether the authentication succeeded or failed, and based on this feedback, dynamically adjusts the difficulty parameters for subsequent attempts, creating an adaptive security system that responds to user behavior.
3Ease of operation
If graphical authentication systems use simple reference point alignment, then ease of operation is improved, but security is worsened due to lack of complexity in authentication challenges
Solution Approach 1:
The patent applies segmentation by dividing the authentication challenge into multiple discrete reference points that must be connected in sequence along a specific path. Instead of a single alignment task, the system segments the authentication into several intermediate steps (reference points), each requiring precise positioning, thereby increasing security through cumulative complexity while maintaining ease of operation through manageable, step-by-step interaction.
Solution Approach 2:
The system transitions from simple 2D point alignment to 3D path tracing by requiring users to define not just the position but also the trajectory between reference points. This adds a temporal and spatial dimension to the authentication, where the path taken matters as much as the destination, significantly increasing security while maintaining intuitive drag-and-drop interaction.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of authenticating a user of a computing device is proposed, together with computing device on which the method is implemented. In the method a modified base image is overlaid with a modified overlay image on a display and either the modified base image or modified overlay image is moved by the user. A security level requirement is assigned and positive authentication is indicated in response to the base image reference point on the modified base image being aligned with the overlay image reference point on the modified overlay image after the moving in a manner that meets the security level requirement.