Graphical Authentication via Coordinate Transformation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional alphanumeric passwords are difficult for users to remember and are vulnerable to compromise due to their complexity, while graphical passwords can still be intercepted during transmission, necessitating a more secure method for authentication.
Innovation Solution
The system provides an authentication image associated with a resource-side coordinate system, which is encoded to generate a user-side coordinate system, allowing users to select a location on the image without entering keystrokes, and decodes this selection for secure authentication without transmitting the actual coordinates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional alphanumeric passwords are used, then authentication security can be strong, but users have difficulty remembering them and they are vulnerable to compromise
Solution Approach 1:
The patent replaces traditional alphanumeric password entry (mechanical keyboard input) with graphical coordinate selection (visual interface interaction). Users select points on a graphical authentication image, and the system converts these visual selections into authentication credentials, eliminating the need to memorize complex character sequences while maintaining security.
Solution Approach 2:
The patent transforms the authentication parameter space from discrete alphanumeric characters to continuous graphical coordinates. By changing the representation from text-based passwords to coordinate-based graphical selections, the system improves memorability through visual intuition while maintaining the mathematical complexity required for security.
2Ease of operation
If graphical passwords are used, then user memorability improves, but they can still be intercepted during transmission
Solution Approach 1:
The patent introduces coordinate transformation as an intermediary layer between the user's graphical selection and the authentication verification. The user selects coordinates in a local reference frame, which are then transformed through mathematical operations (rotation, translation, scaling) before transmission and verification, adding security obfuscation while maintaining user-friendly graphical interaction.
Solution Approach 2:
The patent adds dimensional complexity to the authentication transmission by applying multi-parameter coordinate transformations (rotation angles, translation vectors, scaling factors). This transforms the simple graphical coordinate selection into a more complex mathematical representation during transmission, making interception and replay attacks more difficult while preserving the original user intent.
3Reliability
If coordinate systems are encoded and decoded, then transmission security improves, but system complexity increases
Solution Approach 1:
The patent creates a simplified copy of the coordinate system for user interaction (the authentication image with visible axes), while maintaining the full complexity of the transformation system on the server side. The user interacts with the simple visual copy, unaware of the complex coordinate transformations being applied to their selections for secure transmission.
Solution Approach 2:
The system performs coordinate transformation automatically without requiring user understanding or input of transformation parameters. The user simply selects points on the graphical image, and the system self-manages the encoding through coordinate transformation, decoding upon receipt, and verification, hiding the complexity from the user while maintaining security.
Data Source
AI summary
Systems and methods for securely transferring authentication information between a user and an electronic resource are disclosed herein. The methods include providing an authentication image to a user interface. The authentication image is associated with a resource-side coordinate system and the providing includes encoding the resource-side coordinate system to generate a user-side coordinate system that is different from the resource-side coordinate system and transmitting the authentication image and the user-side coordinate system to the user interface. The methods further include receiving an encoded coordinate set, which uniquely identifies an authentication location in the user-side coordinate set and that is user-selected from the authentication image, from the user interface and decoding the encoded coordinate set to generate a decoded coordinate set that uniquely identifies the authentication location in the resource-side coordinate set. The systems include systems that perform the methods.


