Graphical Authentication via Segmented Input Elements and Labels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication techniques, such as passwords and PINs, lack sufficient entropy and are vulnerable to attacks like shoulder-surfing and smudge attacks, particularly on touchscreen devices, due to the ease of observing and replaying user interactions.

Innovation Solution

The use of graphical-based input elements and labels, arranged in a specific configuration, where users authenticate by selecting and interacting with these elements and labels in a unique sequence, enhancing security and usability by increasing entropy and minimizing observable interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication techniques like passwords and PINs are used, then ease of operation is maintained, but security reliability deteriorates due to insufficient entropy and vulnerability to attacks

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is segmented into multiple independent components: a set of graphical input elements (e.g., icons, images) and a set of labels (e.g., words, phrases). The user must correctly match labels to input elements, creating a multi-factor authentication mechanism that increases entropy without requiring complex passwords. This segmentation transforms a single vulnerable authentication step into multiple verified components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Graphical elements and labels serve as intermediaries between the user and the authentication system. Instead of directly inputting sensitive credentials, users interact with visual representations (input elements) that are matched to corresponding labels. This intermediary layer obscures the actual authentication data from observers, preventing shoulder-surfing and smudge attacks while maintaining user-friendly interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication information is displayed or entered in progress, then ease of operation is maintained, but vulnerability to observation attacks increases

Engineering Contradiction:
Improveuser interaction simplicityVSAvoidshoulder-surfing vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses graphical input elements and labels as intermediaries that obscure the actual authentication process from observers. Users interact with visual elements whose meaning is not immediately apparent to bystanders, preventing shoulder-surfing attacks. The system verifies the correctness of label-element pairings without displaying sensitive authentication information during the process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs visual transformations and state changes in the graphical interface during authentication. Input elements and labels may change appearance, position, or state based on user selection, providing clear feedback to the user while maintaining obscurity for observers. These visual changes confirm authentication progress without revealing the underlying credentials.

Inventive Principle:
Principle #32Color changes

3Ease of operation

If touchscreen-based authentication is implemented, then ease of operation is improved, but vulnerability to smudge attacks increases

Engineering Contradiction:
Improvetouchscreen usabilityVSAvoidsmudge attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The graphical input elements and labels act as intermediaries that prevent smudge attacks. Instead of directly touching sensitive authentication fields, users interact with visual elements whose purpose is not evident from physical contact alone. The system verifies the sequence and pairing of elements and labels, making it impossible for observers to deduce authentication information from finger residue or touch patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10229260B1Authenticating by labeling
Publication Date: 2019.03.12 RSA SECURITY USA LLC
  • US10229260B1 patent drawing
  • US10229260B1 patent drawing
  • US10229260B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for authenticating by labeling are provided herein. A method includes establishing a set of cryptographic information, wherein said set of cryptographic information comprises (i) a set of one or more graphical-based input elements and (ii) one or more graphical-based labels assigned to the set of one or more input elements in accordance with a given arrangement; generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device; processing input cryptographic information entered via the computing device interface in response to the prompt against the set of cryptographic information; and resolving the authentication request based on said processing.