Dynamic Graphical Authentication with Adaptive Security Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing graphical authentication systems are vulnerable to 'shoulder surfing' and do not effectively adapt security levels based on user access requirements or failed authentication attempts, which can compromise security.
Innovation Solution
A method for graphical authentication that involves generating modified base and overlay images with pre-selected reference points, displaying them overlaid on a display, and requiring users to align these points while increasing security levels after failed attempts, thereby enhancing security through dynamic image manipulation and adaptive authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If graphical authentication systems use static images and fixed security levels, then the system is simple to implement, but the system is vulnerable to shoulder surfing and cannot adapt security based on access requirements or failed attempts
Solution Approach 1:
The patent implements dynamic image manipulation where the authentication system generates modified base and overlay images with randomized reference points and configurations. The security level adapts dynamically based on access requirements and failed authentication attempts, transforming the static authentication process into a dynamic one that responds to user behavior and security needs
Solution Approach 2:
The system changes multiple parameters including image modifications, reference point positions, overlay configurations, and security levels. These parameter changes occur based on access requirements and authentication attempt history, allowing the system to adapt its complexity and security measures without requiring complete system redesign
Solution Approach 3:
The system performs preliminary actions by pre-selecting reference points in the base image and pre-configuring overlay images before the authentication attempt. This preliminary setup allows for rapid adaptation during authentication while maintaining system complexity at acceptable levels through pre-computation
2Reliability
If the system increases security levels after failed authentication attempts, then unauthorized access is reduced, but the authentication process becomes more challenging and time-consuming
Solution Approach 1:
The system dynamically adjusts security levels based on the number of failed authentication attempts. When failures occur, the system increases complexity by generating more challenging modified images with additional transformations, creating a progressive security mechanism that adapts to user behavior in real-time
Solution Approach 2:
The system implements feedback loops where authentication attempt outcomes (success or failure) directly influence subsequent authentication requirements. Failed attempts trigger increased security measures including modified image generation and reference point repositioning, while successful attempts reset the security level, creating a self-regulating authentication process
3Object-affected harmful factors
If the system uses modified images with pre-selected reference points and overlay manipulation, then shoulder surfing is reduced, but the system complexity and processing requirements increase
Solution Approach 1:
The authentication image is segmented into multiple components: a base image with pre-selected reference points, an overlay image with additional reference points, and modified versions of both. This segmentation allows the system to manipulate individual components independently, reducing shoulder surfing vulnerability while managing complexity through modular processing
Solution Approach 2:
The system creates modified copies of the base and overlay images for each authentication attempt. These copies contain randomized transformations including repositioned reference points and altered configurations, allowing the system to protect against shoulder surfing by ensuring each authentication presents a unique visual challenge without requiring complete system redesign
Data Source
AI summary
A method of authenticating a user of a computing device is proposed, together with computing device on which the method is implemented. In the method a modified base image is overlaid with a modified overlay image on a display and either the modified base image or modified overlay image is moved by the user. A security level requirement is assigned and positive authentication is indicated in response to the base image reference point on the modified base image being aligned with the overlay image reference point on the modified overlay image after the moving in a manner that meets the security level requirement.


