Authentication System Using Geometric Pattern Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication methods face challenges such as password leakage, cumbersome password management, and inadequate security, especially when using random number tables or security tokens, which can be stolen or lost, leading to compromised security levels and illicit access.
Innovation Solution
A novel authentication system that utilizes an information communication terminal to manage user accounts with token IDs, generating token codes and performing authentication determinations based on prior notifications and token codes, allowing for secure password derivation patterns and additional codes to ensure robust security, even in varying network conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional password authentication is used, then user authentication can be performed, but password leakage and theft make security vulnerable
Solution Approach 1:
The patent extracts the secret element (password) from the authentication process and replaces it with a public geometric pattern. The password derivation pattern is stored publicly in the authentication server, while the actual password remains only in the user's mind, eliminating the risk of password leakage through database breaches or interception.
Solution Approach 2:
The patent introduces a geometric pattern as an intermediary between the user and the authentication system. Instead of directly transmitting or storing passwords, the system uses geometric patterns as a mediator that can be publicly displayed while still enabling secure authentication through the user's memorized password derivation pattern.
2Adaptability or versatility
If multiple passwords are managed for different systems, then each system can be accessed, but password management becomes cumbersome and users resort to weak passwords
Solution Approach 1:
The patent creates a universal authentication mechanism where a single geometric pattern can be used across multiple systems. The password derivation pattern stored in the authentication server serves all authentication requests, eliminating the need for users to manage multiple different passwords while maintaining system-specific security requirements.
3Reliability
If random number tables or security tokens are used for authentication, then authentication security is improved, but the tokens can be stolen or lost reducing security
Solution Approach 1:
The patent extracts the secret element from physical tokens and relocates it to the user's memory through password derivation patterns. Instead of relying on physical security tokens that can be stolen, the system stores only the geometric pattern publicly and keeps the actual authentication secret in the user's mind, eliminating token theft risks.
4Ease of operation
If information communication terminals are used for authentication, then user convenience is improved, but network communication conditions may prevent authentication
Solution Approach 1:
The patent performs preliminary actions by pre-storing the password derivation pattern in the authentication server and pre-generating geometric patterns. This allows the system to quickly authenticate users even under varying network conditions, as the heavy computational work of pattern generation has already been done in advance.
Data Source
AI summary
A new user authentication method which prevents illicit access to a system includes an authentication system which authenticates a user. The authentication system includes a database which manages user account information including a token ID which identifies a security token; a synchronization server which generates token codes on the basis of the token ID; and an authentication server which carries out an authentication determination transmitted from the system, and transmits the result to the system subject to use. If a prior notification of an authentication request is received prior to receiving the user authentication request, the authentication server carries out the authentication determination using a first token code. Alternatively, if the user authentication request is received without prior notification of the authentication request being received, the authentication server carries out the authentication determination using the first token code and a second token code.


