Encrypted Graphic Authentication for Human Presence Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user presence detection methods, such as CAPTCHA, are inadequate in distinguishing between human and automated systems, and lack effective second factor authentication mechanisms for secure electronic device access.
Innovation Solution
A system that encrypts interactive or static graphics using a cryptographic certificate, allowing only authorized users to decrypt and interact with them, providing both user presence detection and second factor authentication by requiring responses to prompts or interactions that are difficult for automated systems to interpret.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional CAPTCHA challenge-response tests are used for user presence detection, then automated systems can be partially deterred, but they remain inadequate at distinguishing between human and automated systems
Solution Approach 1:
The patent transforms the authentication approach by changing from text-based challenge-response to encrypted graphic-based interaction. The server encrypts graphics using a cryptographic certificate, and the client decrypts them using a cryptographic engine. This parameter change in the authentication medium (from text to encrypted graphics) significantly improves reliability in distinguishing human from automated systems while maintaining manageable complexity through standardized cryptographic operations.
2Reliability
If encrypted graphics with cryptographic certificates are implemented, then security and authentication reliability are significantly improved, but the complexity of the authentication system increases
Solution Approach 1:
The patent extracts the cryptographic processing functions into dedicated components: a cryptographic certificate module on the server side and a cryptographic engine on the client side. This separation allows the main authentication logic to remain simple while the cryptographic complexity is isolated to specialized modules, effectively managing system complexity while maintaining high security reliability.
Solution Approach 2:
The patent introduces encrypted graphics as an intermediary medium between the server and client for authentication. Instead of direct communication or simple password verification, the system uses encrypted graphic images that require cryptographic decryption and human interaction to solve, serving as a mediator that enhances security while maintaining a user-friendly interface.
3Reliability
If interactive graphics requiring user interaction are used, then second factor authentication is achieved, but the ease of operation decreases
Solution Approach 1:
The patent uses visual copying and pattern recognition in the interactive graphics, where users can observe encrypted graphic patterns and replicate or interact with them in a structured manner. This approach maintains ease of operation by leveraging human visual processing strengths while achieving second-factor authentication through the cryptographic layer that automated systems cannot bypass.
Data Source
Figure 1
Figure 2
Figure 3~4D
AI summary
This disclosure relates generally to a system and method for authenticating an electronic device may comprise a server configured to transmit an encrypted object, the encrypted object having an image file format, to the electronic device, the encrypted object being encrypted based on a certificate, the electronic device operatively coupled to the server and comprising a processor registered with the server to create a secured communication link between the processor and the server, wherein the certificate corresponds to the processor, the processor having a cryptographic engine configured to decrypt the encrypted object to result in a decrypted graphic, and a user interface operatively coupled to the processor. The user interface may be configured to display the decrypted graphic and receive a user input responsive to the decrypted graphic. The server may authenticate the electronic device based, at least in part, on the user input.