Dynamic Pattern Authentication Server Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods using pattern rendering commands are ineffective once a hacker intercepts and replicates the rendering pattern, allowing unauthorized access.

Innovation Solution

Implement a method where the server equipment generates and updates dynamic pattern rendering commands and their corresponding renderings after each successful authentication, ensuring new authentication data is produced and stored, making intercepted data unusable for future authentications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pattern rendering commands are used for authentication, then authentication capability is provided, but security is weakened once intercepted

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication data reuse vulnerability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic authentication by replacing static pattern rendering commands with dynamic ones that change after each authentication attempt. The server generates new random parameters for pattern rendering commands after each authentication, ensuring that intercepted authentication data becomes obsolete and cannot be reused for impersonation attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of pattern rendering commands dynamically. Instead of using fixed pattern parameters, the system generates new random parameters (such as pattern type, complexity, color scheme, size) for each authentication attempt, making each authentication challenge unique and preventing replay attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication data is updated after each authentication, then security against interception is improved, but system complexity increases

Engineering Contradiction:
Improveresistance to illegitimate authenticationVSAvoidauthentication data management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication data management where the server automatically generates new pattern rendering commands and parameters after each authentication attempt without requiring manual intervention. The system autonomously updates authentication data, manages parameter generation, and handles the replacement process, reducing operational complexity despite increased technical sophistication.

Inventive Principle:
Principle #25Self-service

3Reliability

If new random parameters are generated for each authentication, then authentication data uniqueness is improved, but processing time increases

Engineering Contradiction:
Improveauthentication data uniquenessVSAvoidparameter generation and update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating and storing multiple sets of random parameters for pattern rendering commands in advance. When an authentication attempt occurs, the system selects from pre-generated parameters rather than generating them in real-time, significantly reducing the time required for parameter generation while maintaining uniqueness through the use of pre-computed random values.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11134080B2Method for authenticating a terminal equipment, device, server equipment and related computer program
Publication Date: 2021.09.28 FOND B COM
  • US11134080B2 patent drawing
  • US11134080B2 patent drawing
  • US11134080B2 patent drawing

AI summary

A method for authenticating a user of a terminal equipment connected to a communication network, for access from this terminal equipment to a remote service hosted by a server equipment connected to the network. The method includes the following steps, implemented by the server: authenticating the user from credentials; in the event of successful user authentication, authenticating the client equipment from credentials stored in a first memory of the server in association with the user's credentials, including a command to render a first pattern, the command including parameters describing the first pattern and rendering the first pattern received from the client equipment, so-called reference pattern; deciding on authenticating the client equipment according to the evaluated score, a successful authentication being decided when the match score is greater than a predetermined threshold; and following the authentication decision, updating the credentials of the terminal equipment.