Dynamic Graphical Authentication with Adaptive Security Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing graphical authentication systems are vulnerable to 'shoulder surfing' and do not effectively adapt security levels based on user access requirements or failed authentication attempts, which can compromise security.

Innovation Solution

A method for graphical authentication that involves generating modified base and overlay images with pre-selected reference points, displaying them overlaid on a display, and requiring users to align these points while increasing security levels after failed attempts, thereby enhancing security through dynamic image manipulation and adaptive authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If graphical authentication systems use static images and fixed security levels, then the system is simple to implement, but the system is vulnerable to shoulder surfing and cannot adapt security based on access requirements or failed attempts

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic image manipulation where the authentication system generates modified base and overlay images with randomized reference points and configurations. The security level adapts dynamically based on access requirements and failed authentication attempts, transforming the static authentication process into a dynamic one that responds to user behavior and security needs

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters including image modifications, reference point positions, overlay configurations, and security levels. These parameter changes occur based on access requirements and authentication attempt history, allowing the system to adapt its complexity and security measures without requiring complete system redesign

Inventive Principle:
Principle #35Parameter changes

Solution Approach 3:

The system performs preliminary actions by pre-selecting reference points in the base image and pre-configuring overlay images before the authentication attempt. This preliminary setup allows for rapid adaptation during authentication while maintaining system complexity at acceptable levels through pre-computation

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system increases security levels after failed authentication attempts, then unauthorized access is reduced, but the authentication process becomes more challenging and time-consuming

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts security levels based on the number of failed authentication attempts. When failures occur, the system increases complexity by generating more challenging modified images with additional transformations, creating a progressive security mechanism that adapts to user behavior in real-time

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where authentication attempt outcomes (success or failure) directly influence subsequent authentication requirements. Failed attempts trigger increased security measures including modified image generation and reference point repositioning, while successful attempts reset the security level, creating a self-regulating authentication process

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If the system uses modified images with pre-selected reference points and overlay manipulation, then shoulder surfing is reduced, but the system complexity and processing requirements increase

Engineering Contradiction:
Improveshoulder surfing vulnerabilityVSAvoidimage processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication image is segmented into multiple components: a base image with pre-selected reference points, an overlay image with additional reference points, and modified versions of both. This segmentation allows the system to manipulate individual components independently, reducing shoulder surfing vulnerability while managing complexity through modular processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates modified copies of the base and overlay images for each authentication attempt. These copies contain randomized transformations including repositioned reference points and altered configurations, allowing the system to protect against shoulder surfing by ensuring each authentication presents a unique visual challenge without requiring complete system redesign

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8650624B2Obscuring visual login
Publication Date: 2014.02.11 MALIKIE INNOVATIONS LTD
  • US8650624B2 patent drawing
  • US8650624B2 patent drawing
  • US8650624B2 patent drawing

AI summary

A method of authenticating a user of a computing device is proposed, together with computing device on which the method is implemented. In the method a modified base image is overlaid with a modified overlay image on a display and either the modified base image or modified overlay image is moved by the user. A security level requirement is assigned and positive authentication is indicated in response to the base image reference point on the modified base image being aligned with the overlay image reference point on the modified overlay image after the moving in a manner that meets the security level requirement.