Image-Based Key Exchange for Web Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current username and password authentication methods for web services are vulnerable to identity theft, as online criminals can acquire login information remotely, necessitating additional security measures to protect user identity.

Innovation Solution

The technique involves capturing an encoded graphical image on a secondary device using an image capture device, processing it to determine a secure authentication key, and storing it for generating a secondary password to access password-protected web services, thereby enhancing security and user experience by eliminating manual entry of complex authentication keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password authentication is used for web service access, then security is provided for users and service providers, but users are vulnerable to identity theft as criminals can acquire login information remotely

Engineering Contradiction:
Improveauthentication securityVSAvoididentity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secondary device as an intermediary between the user and the web service. This device generates and provides a secondary password that acts as a mediator, preventing direct exposure of the primary password and reducing identity theft risk while maintaining authentication security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two parts: a primary password stored securely and a secondary password generated by the secondary device. This segmentation separates the authentication credentials, so that even if the primary password is compromised, the secondary password provides an additional security layer that criminals cannot easily obtain

Inventive Principle:
Principle #1Segmentation

2Reliability

If a secondary password authentication system is implemented, then security against identity theft is improved, but device complexity increases due to additional authentication components

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secondary device automatically generates and provides the secondary password without requiring manual configuration by the user. The device performs self-service functions including key generation, password creation, and automatic provisioning, which reduces the perceived complexity for users while maintaining enhanced security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates a copy of the authentication functionality in the secondary device. Instead of complicating the primary device, a separate copy of the password generation capability is created in the secondary device, which can independently generate and provide secondary passwords without adding complexity to the original system

Inventive Principle:
Principle #26Copying

3Reliability

If manual entry of secure authentication keys is required, then security is maintained, but user experience deteriorates due to cumbersome input processes especially on devices with limited input mechanisms

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical process of manual key entry with an automatic electronic process. The secondary device automatically generates and transmits the secondary password electronically, eliminating the need for manual typing or input operations while maintaining security through automated key management

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If automated secondary password generation is implemented, then ease of operation is improved by eliminating manual entry, but loss of time occurs during the key exchange and configuration process

Engineering Contradiction:
Improveauthentication process easeVSAvoidkey exchange time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The secondary password generation capability is pre-configured in the secondary device before authentication is needed. The device already contains the necessary cryptographic keys and algorithms, so when authentication is required, the secondary password can be generated immediately without delay for manual configuration or key exchange

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3364327B1Image-based key exchange
Publication Date: 2019.08.14 GOOGLE LLC
  • EP3364327B1 patent drawingFigure 1
  • EP3364327B1 patent drawingFigure 2
  • EP3364327B1 patent drawingFigure 3

AI summary

This disclosure is directed for improved techniques for configuring a device to generate a secondary password based at least in part on a secure authentication key. The techniques of this disclosure may, in some examples, provide for capturing, by a computing device, an image of a display of another computing device. The captured image includes at least one encoded graphical image, such as a barcode, that includes an indication of the content of a secure authentication key. The computing device may use the secure authentication key to generate a secondary password to be used in conjunction with a primary password to gain access to a password-protected web service.