Dynamic Image Modification for Malware-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing image-based authentication systems are susceptible to malware, which can recognize and mimic user responses, allowing unauthorized machine access to computer systems and services.

Innovation Solution

Modifying images by changing their checksums or making subtle to obvious changes, such as altering pixels, dividing images into sections, or modifying backgrounds, to make them more recognizable by humans than computers, thereby preventing malware from recognizing the images during the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If images are used for authentication, then user convenience is improved and entry errors are reduced, but the system becomes susceptible to malware that can recognize and mimic user responses

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity against malware
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by dynamically modifying images before each authentication challenge. The system generates multiple versions of the same base image with different transformations (rotation, scaling, cropping, color adjustments) and presents a different modified version each time. This dynamic transformation ensures that malware cannot rely on static image recognition, as the images change between authentication attempts while still being recognizable to human users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies parameter changes by altering various parameters of the authentication images including geometric transformations (rotation angles, scale factors, crop positions) and visual parameters (color brightness, contrast, saturation). These parameter modifications maintain the semantic content recognizable by humans while changing the pixel-level characteristics that malware might use for automated recognition.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional authentication questions are used, then security can be maintained, but user convenience deteriorates and entry errors increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies copying by replacing text-based authentication questions with visual copies or representations. Instead of presenting users with text questions that require typing responses, the system uses images that visually represent the authentication challenge. Users can select answers by clicking on image elements rather than typing, reducing entry errors while maintaining security through visual recognition tasks.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11068576B2Hardening security images
Publication Date: 2021.07.20 PAYPAL INC
  • US11068576B2 patent drawing
  • US11068576B2 patent drawing
  • US11068576B2 patent drawing

AI summary

Methods and systems are provided for electronic authentication. A modified electronic image is generated by altering at least a pixel of an electronic image. The electronic image is an image that has been previously viewed by a user during a setup process. In response to receiving an authentication request from the user, the modified electronic image is displayed to the user via an electronic display along with one or more other electronic images. A determination is made as to whether the user is able to recognize the modified electronic image. In response to determination that the user is able to recognize the modified electronic image, the authenticating request is granted.