Dynamic Image Authentication System Resisting Intersection Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional image-based authentication systems are vulnerable to educated-guess and intersection attacks, where a third party can guess the selected image or coordinates based on personal information, and are also susceptible to wiretapping of secret information.
Innovation Solution
An authentication system that stores images with associated region and word information, where users authenticate by designating positions within images, making it difficult for attackers to identify the specific image or coordinates, and includes mechanisms to prevent brute force attacks by randomly displaying dummy images.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a predetermined image is always displayed in one of screens for authentication, then the user can easily identify the image to be selected, but a third party can perform intersection attack to identify the same image across multiple screens
Solution Approach 1:
The patent implements dynamic image selection where the system randomly determines whether to display a predetermined image or a dummy image on each authentication screen. This dynamic behavior prevents attackers from identifying consistent patterns across multiple screens, as the same predetermined image may or may not appear depending on random determination, thereby resisting intersection attacks while maintaining user authentication capability
Solution Approach 2:
The patent introduces dummy images as intermediaries that mix with predetermined images in the authentication screen. These dummy images serve as decoys that prevent attackers from easily identifying the actual predetermined image, while the system internally tracks which image corresponds to the correct authentication target, thus maintaining security without compromising user ability to authenticate
2Ease of operation
If personal information about the user is used to select authentication images, then the user can easily remember and select the correct image, but a third party can perform educated-guess attack using the same personal information
Solution Approach 1:
The patent dynamically determines on each authentication attempt whether to display the predetermined image (linked to user's personal information) or a dummy image. This dynamic random determination means that even if an attacker knows the user's personal information, they cannot predict which image will be the correct one on any given screen, as the system randomly decides whether to show the predetermined image or not
Solution Approach 2:
The patent changes the parameter of image display probability by introducing random determination. Instead of always displaying the predetermined image linked to user's personal information, the system varies the display parameter by randomly selecting whether to show the predetermined image or a dummy image, thereby transforming a static predictable system into a dynamic unpredictable one that resists educated-guess attacks
Data Source
AI summary
An information processing apparatus for executing authentication processing, characterized by comprises: storage means for storing, in association with each other, an image, region information indicating a region included in the image, and word information indicating an object linked with the region; determination means for determining an image to be used for the authentication processing among the images stored in the storage means; display means for displaying the image determined by the determination means; specification means for specifying, in a case where a user designates a position within the image displayed by the display means, word information associated with region information of a region including the position; and authentication means for executing authentication processing using the word information specified by the specification means.


