Graphical Authentication via Segmented Input Elements and Labels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication techniques, such as passwords and PINs, lack sufficient entropy and are vulnerable to attacks like shoulder-surfing and smudge attacks, particularly on touchscreen devices, due to the ease of observing and replaying user interactions.
Innovation Solution
The use of graphical-based input elements and labels, arranged in a specific configuration, where users authenticate by selecting and interacting with these elements and labels in a unique sequence, enhancing security and usability by increasing entropy and minimizing observable interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication techniques like passwords and PINs are used, then ease of operation is maintained, but security reliability deteriorates due to insufficient entropy and vulnerability to attacks
Solution Approach 1:
The authentication process is segmented into multiple independent components: a set of graphical input elements (e.g., icons, images) and a set of labels (e.g., words, phrases). The user must correctly match labels to input elements, creating a multi-factor authentication mechanism that increases entropy without requiring complex passwords. This segmentation transforms a single vulnerable authentication step into multiple verified components.
Solution Approach 2:
Graphical elements and labels serve as intermediaries between the user and the authentication system. Instead of directly inputting sensitive credentials, users interact with visual representations (input elements) that are matched to corresponding labels. This intermediary layer obscures the actual authentication data from observers, preventing shoulder-surfing and smudge attacks while maintaining user-friendly interaction.
2Ease of operation
If authentication information is displayed or entered in progress, then ease of operation is maintained, but vulnerability to observation attacks increases
Solution Approach 1:
The patent uses graphical input elements and labels as intermediaries that obscure the actual authentication process from observers. Users interact with visual elements whose meaning is not immediately apparent to bystanders, preventing shoulder-surfing attacks. The system verifies the correctness of label-element pairings without displaying sensitive authentication information during the process.
Solution Approach 2:
The system employs visual transformations and state changes in the graphical interface during authentication. Input elements and labels may change appearance, position, or state based on user selection, providing clear feedback to the user while maintaining obscurity for observers. These visual changes confirm authentication progress without revealing the underlying credentials.
3Ease of operation
If touchscreen-based authentication is implemented, then ease of operation is improved, but vulnerability to smudge attacks increases
Solution Approach 1:
The graphical input elements and labels act as intermediaries that prevent smudge attacks. Instead of directly touching sensitive authentication fields, users interact with visual elements whose purpose is not evident from physical contact alone. The system verifies the sequence and pairing of elements and labels, making it impossible for observers to deduce authentication information from finger residue or touch patterns.
Data Source
AI summary
Methods, apparatus and articles of manufacture for authenticating by labeling are provided herein. A method includes establishing a set of cryptographic information, wherein said set of cryptographic information comprises (i) a set of one or more graphical-based input elements and (ii) one or more graphical-based labels assigned to the set of one or more input elements in accordance with a given arrangement; generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device; processing input cryptographic information entered via the computing device interface in response to the prompt against the set of cryptographic information; and resolving the authentication request based on said processing.


