Image-Based Authentication for Online Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional password-based authentication methods are vulnerable to hacking, phishing, and password management issues, leading to user inconvenience and security risks, as they rely heavily on passwords that are often lost, forgotten, or compromised.

Innovation Solution

Implementing a passwordless authentication system using imaging techniques, where users access online accounts by capturing and decoding unique images displayed on web pages using their mobile devices, eliminating the need for passwords and leveraging biometric methods for device binding and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then users can access online accounts, but security vulnerabilities increase due to hacking, phishing, and password management issues

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to hacking and phishing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password element from the authentication system entirely, replacing it with image-based authentication. Users take a photo of a displayed image containing authentication credentials, eliminating the need to transmit or store passwords, thereby removing the vulnerability vector that passwords create against hacking and phishing attacks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with an imaging-based system. Instead of typing passwords through keyboards (mechanical input), users capture images with mobile device cameras, and the system processes these images optically to authenticate users, fundamentally changing the authentication mechanism

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If complex password requirements are implemented, then security against hacking improves, but user convenience deteriorates due to difficulty in remembering passwords

Engineering Contradiction:
Improvepassword securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent employs disposable, transient authentication images that are displayed briefly and captured immediately. Each authentication image is unique and short-lived, eliminating the need for users to remember complex passwords while maintaining security through one-time use credentials that cannot be reused or compromised

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If password reset procedures are implemented, then lost passwords can be recovered, but system complexity and user burden increase due to call centers and security questions

Engineering Contradiction:
Improvepassword recoveryVSAvoidauthentication system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent enables self-service authentication where users independently capture and submit authentication images without requiring call center assistance or security question verification. The system automatically processes the captured images and authenticates users, eliminating the need for complex manual recovery procedures

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11405380B2Systems and methods for using imaging to authenticate online users
Publication Date: 2022.08.02 VERIZON PATENT & LICENSING INC
  • US11405380B2 patent drawing
  • US11405380B2 patent drawing
  • US11405380B2 patent drawing

AI summary

Systems and methods are disclosed for authenticating an identity of an online user. One method includes receiving from the user, through a first device, a request to access a web page associated with the user's online account; transmitting to the user an image that contains a unique ID and a URL of an authentication server; and receiving from the user, through the first device, an authentication request containing the unique ID. The method also includes receiving from the user, through a second device, a log-in ID associated with the user and the unique ID; and authenticating the identity of the user to grant the user access, through the first device, to the web page associated with the user's online account.