Dynamic Grid Authentication Using Position-Based Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional password-based authentication systems are vulnerable to various attack vectors such as phishing, malware, and key logging, and require frequent resets due to memorization difficulties, leading to compromised security and increased costs.

Innovation Solution

The implementation of an enumerated pattern credential system using a content-based challenge and position-based response, where users authenticate by identifying positions on a dynamic grid rather than entering static values, shifting the authentication paradigm to an intangible, user-mind-based process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then implementation is simple and familiar to users, but security is compromised due to vulnerability to phishing, malware, and key logging attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidattack vectors
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical typing of passwords with a visual pattern recognition system. Users authenticate by recognizing and selecting fields that form a graphical pattern on a dynamically generated grid, substituting the mechanical act of typing with visual cognitive processing that cannot be captured by key loggers or phishing attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The grid of fields is dynamically generated with random positions and values for each authentication session. The graphical pattern credential remains constant in the user's mind, but its representation on the grid changes each session, preventing replay attacks and credential theft while maintaining user memorability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If password length and complexity are increased to improve security, then security strength improves, but user memorization difficulty increases leading to frequent credential resets

Engineering Contradiction:
Improvecredential securityVSAvoidmemorization ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes the parameter of authentication from remembering complex character sequences to remembering simple visual patterns. The graphical pattern credential uses spatial arrangement and visual recognition, which are naturally more memorable than alphanumeric sequences, while providing equivalent or superior security through the dynamic grid implementation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If dynamic grids with graphical patterns are implemented, then security is improved and memorization is easier, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server stores only the graphical pattern credential (the sequence of field positions) rather than complex password data. During authentication, the server generates a copy of the grid with random field values and compares the user's selected pattern against the stored pattern, simplifying server storage requirements while enabling secure authentication.

Inventive Principle:
Principle #26Copying

4Reliability

If content-based challenge with position-based response is used, then credential entropy leakage is reduced and security is enhanced, but authentication process becomes more complex

Engineering Contradiction:
Improvecredential securityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of challenging the user to provide content (password characters), the system inverts the approach by providing content (random values in grid fields) and challenging the user to identify positions that form the secret pattern. This inversion prevents credential leakage because the challenge contains no information about the actual credential, only random distractor values.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS8868919B2Authentication method of field contents based challenge and enumerated pattern of field positions based response in random partial digitized path recognition system
Publication Date: 2014.10.21 AUTHERNATIVE INC
  • US8868919B2 patent drawing
  • US8868919B2 patent drawing
  • US8868919B2 patent drawing

AI summary

An interactive method for authentication is based on a shared secret which is in the form of an enumerated pattern of fields on a frame of reference. An instance of the frame of reference comprises an array of characters in which the characters are arranged in a random or other irregular pattern on a grid of content fields. An authentication challenge includes characters from the character set, and is delivered in- or out-of-band. The authentication response includes the enumerated position numbers on the enumerated pattern of the field locations on the grid at which the challenge characters are found.