Dynamic Grid Authentication for Phishing Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Static grid-based authentication systems are vulnerable to attacks such as phishing, shoulder surfing, and card cloning, as they rely on fixed PINs and grids that can be stolen or memorized, leading to security concerns and increased risk of fraud.
Innovation Solution
A dynamic grid-based authentication system that generates a random authentication grid for each transaction, encrypted with a shared secret, which is decrypted only by the intended user after a challenge is signed, reducing the need for physical cards and enhancing security by requiring user input based on a machine-readable code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static grid-based authentication system is used, then the system is simple to implement and operate, but it is vulnerable to security attacks such as phishing, shoulder surfing, and card cloning
Solution Approach 1:
The patent applies dynamics by transitioning from a static authentication grid to a dynamic one that is generated randomly for each transaction. The grid changes every time a new authentication is needed, making it impossible for attackers to use stolen or memorized grids for repeated attacks. This dynamic generation resolves the contradiction by enhancing security through variability while maintaining operational simplicity.
Solution Approach 2:
The patent changes the parameter of grid stability from fixed to variable. Instead of using a permanent static grid, the system generates new grids with different character mappings for each authentication transaction. This parameter change ensures that even if one grid is compromised, it cannot be reused, thereby improving security without requiring complex physical card management.
2Reliability
If a static PIN and grid are used, then the system is easy to operate, but the PIN can be stolen or memorized leading to increased fraud risk
Solution Approach 1:
The system makes the authentication grid dynamic by generating a new random grid for each transaction rather than using a fixed PIN. Users still interact with the grid in a simple manner by selecting characters, but the grid's randomness ensures that each authentication is unique and cannot be replicated, thus maintaining ease of operation while improving security.
Solution Approach 2:
The patent employs the principle of disposable authentication grids that are valid only for a single transaction and then discarded. Each grid is generated fresh and used once, after which it becomes invalid. This eliminates the risk of stolen PINs being reused, as each grid is as good as new and cannot be replicated by attackers.
3Reliability
If a physical card with fixed grid is used, then the system is simple to implement, but the card can be stolen or cloned
Solution Approach 1:
The patent replaces the physical card with a digital authentication system that generates grids dynamically. Instead of relying on a physical card that can be stolen or cloned, the system uses cryptographic generation to create unique grids for each transaction. This eliminates the copying risk while maintaining implementation simplicity through software-based authentication.
Solution Approach 2:
The system transitions from a static physical card grid to a dynamic digital grid that changes with each transaction. This dynamic approach ensures that even if a card is stolen, the authentication security is not compromised because the grid is regenerated continuously. The complexity is managed through automated grid generation and verification processes.
4Reliability
If the same authentication grid is used for multiple transactions, then the system is simple to operate, but the grid can be stolen or memorized
Solution Approach 1:
The patent implements disposable authentication grids that are valid for exactly one transaction and then discarded. Each grid is generated fresh for a single use and cannot be reused or stolen for future attacks. This short validity period resolves the contradiction by ensuring security through limited lifespan while maintaining operational simplicity through automatic regeneration.
Solution Approach 2:
The system makes the grid validity dynamic by assigning a one-time use period to each grid rather than permanent validity. The grid automatically becomes invalid after a single transaction, preventing reuse and theft. This dynamic validity period enhances security without requiring users to manage complex expiration schedules.
Data Source
AI summary
A method includes dynamically generating an authentication grid that identifies an association between a first set of characters and a second set of characters. Based on a shared secret associated with a user, an encrypted version of the authentication grid is generated and transmitted to a first computing device associated with the user. A challenge is generated and transmitted to a second computing device associated with the user. User input is received, and the user is authenticated based at least in part on the authentication grid and a mapping of at least one character in a first set of characters in the challenge to at least one second character the user input.


