Image-Based Key Exchange for Web Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current username and password authentication methods for web services are vulnerable to identity theft, as online criminals can acquire login information remotely, necessitating additional security measures to protect user identity.
Innovation Solution
The technique involves capturing an encoded graphical image on a secondary device using an image capture device, processing it to determine a secure authentication key, and storing it for generating a secondary password to access password-protected web services, thereby enhancing security and user experience by eliminating manual entry of complex authentication keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username and password authentication is used for web service access, then security is provided for users and service providers, but users are vulnerable to identity theft as criminals can acquire login information remotely
Solution Approach 1:
The patent introduces a secondary device as an intermediary between the user and the web service. This device generates and provides a secondary password that acts as a mediator, preventing direct exposure of the primary password and reducing identity theft risk while maintaining authentication security
Solution Approach 2:
The authentication process is segmented into two parts: a primary password stored securely and a secondary password generated by the secondary device. This segmentation separates the authentication credentials, so that even if the primary password is compromised, the secondary password provides an additional security layer that criminals cannot easily obtain
2Reliability
If a secondary password authentication system is implemented, then security against identity theft is improved, but device complexity increases due to additional authentication components
Solution Approach 1:
The secondary device automatically generates and provides the secondary password without requiring manual configuration by the user. The device performs self-service functions including key generation, password creation, and automatic provisioning, which reduces the perceived complexity for users while maintaining enhanced security
Solution Approach 2:
The system creates a copy of the authentication functionality in the secondary device. Instead of complicating the primary device, a separate copy of the password generation capability is created in the secondary device, which can independently generate and provide secondary passwords without adding complexity to the original system
3Reliability
If manual entry of secure authentication keys is required, then security is maintained, but user experience deteriorates due to cumbersome input processes especially on devices with limited input mechanisms
Solution Approach 1:
The patent replaces the mechanical process of manual key entry with an automatic electronic process. The secondary device automatically generates and transmits the secondary password electronically, eliminating the need for manual typing or input operations while maintaining security through automated key management
4Ease of operation
If automated secondary password generation is implemented, then ease of operation is improved by eliminating manual entry, but loss of time occurs during the key exchange and configuration process
Solution Approach 1:
The secondary password generation capability is pre-configured in the secondary device before authentication is needed. The device already contains the necessary cryptographic keys and algorithms, so when authentication is required, the secondary password can be generated immediately without delay for manual configuration or key exchange
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This disclosure is directed for improved techniques for configuring a device to generate a secondary password based at least in part on a secure authentication key. The techniques of this disclosure may, in some examples, provide for capturing, by a computing device, an image of a display of another computing device. The captured image includes at least one encoded graphical image, such as a barcode, that includes an indication of the content of a secure authentication key. The computing device may use the secure authentication key to generate a secondary password to be used in conjunction with a primary password to gain access to a password-protected web service.