Dynamic Positioning Authentication Using Location-Based Factor Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user identity authentication methods, such as those using fixed usernames and passwords, or dynamic passwords, are vulnerable to security threats due to their complexity and reliance on hardware or third-party plugins, making them difficult to secure effectively.
Innovation Solution
A one-time dynamic positioning authentication method that generates a positioning factor string and maps it into a full-element dynamic factor table, allowing users to input a dynamic graphical password based on a specific rule, which is then verified by an authentication server, providing a secure and user-friendly authentication process without the need for external hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a fixed username and password authentication method is used, then the implementation is simple, but the security is poor and easy to be cracked
Solution Approach 1:
The patent transforms the static username and password authentication into a dynamic positioning-based authentication system. The authentication credential changes dynamically based on the user's geographic location, making each authentication instance unique and time-sensitive, thereby resolving the contradiction between simplicity and security.
Solution Approach 2:
The patent changes the authentication parameter from a fixed string (password) to a dynamic parameter based on geographic coordinates. The positioning factor string and authentication credentials are regenerated based on location data, transforming the authentication mechanism from static to location-dependent dynamic parameters.
2Reliability
If complex password requirements are imposed (uppercase, lowercase, numerals, symbols), then the security is improved, but the user experience deteriorates and passwords are difficult to remember
Solution Approach 1:
The system automatically generates authentication credentials based on the user's location data without requiring the user to manually create complex passwords. The positioning-based authentication mechanism handles the complexity internally, providing secure authentication while maintaining ease of use for the end user.
Solution Approach 2:
The patent replaces the mechanical system of manual password creation and memorization with an automated positioning-based authentication system. The geographic location data serves as the basis for generating authentication credentials, eliminating the need for users to manage complex password strings.
3Reliability
If dynamic password or token authentication is used, then the security is improved, but the device complexity increases due to hardware or third-party plugin requirements
Solution Approach 1:
The patent extracts the authentication mechanism from hardware dependencies and third-party plugins, creating a standalone positioning-based authentication system. By using the device's built-in location capabilities (GPS, network location) rather than external hardware tokens, the system achieves enhanced security without increasing device complexity.
Solution Approach 2:
The positioning-based authentication system leverages the multi-functionality of modern devices that already possess location capabilities for navigation and other purposes. By repurposing this existing functionality for authentication, the system avoids adding dedicated hardware components while achieving improved security.
4Reliability
If mobile dynamic password authentication is used, then the security is improved, but the vulnerability to attacks (pseudo base station, Trojan) increases
Solution Approach 1:
The patent converts the potential harm of location data being used for tracking or surveillance into a security benefit by making authentication dependent on location. The system uses the device's inherent location capabilities, which cannot be easily spoofed without physical presence, thereby converting a privacy concern into a security advantage.
5Reliability
If hardware token authentication is used, then the security is improved, but the vulnerability to time error attacks increases
Solution Approach 1:
The patent replaces time-based authentication mechanisms with location-based authentication. Instead of relying on synchronized time clocks between server and client, the system uses geographic positioning data as the basis for generating authentication credentials, eliminating the vulnerability to time synchronization errors and related attacks.
Data Source
AI summary
Provided in the present application are a one-time dynamic positioning authentication method, system and password changing method. The method comprises: an authentication server receives an authentication request from a client, generates a positioning factor string, and transmits generated information containing the positioning factor string and a structure of an all-element dynamic factor table to the client; the client receives the generated information, generates the all-element dynamic factor table, and maps the positioning factor string into the all-element dynamic factor table to acquire a dynamic graphical password inputted in accordance with a first positioning rule by a user and transmit to the authentication server; the authentication server receives the dynamic graphical password from the client, and if the first positioning rule corresponding to the parsed dynamic graphical password is consistent with a preset positioning rule, then the authentication is successful. The graphic passwords being visual and easy to remember, combined with the variability of one-time dynamic passwords, improves the overall convenience and security of an authentication system.


