Image-Based Mutual Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer authentication systems primarily focus on user authentication, leaving a gap in verifying the authenticity of computer systems and networks, especially in distributed networks like the Internet, where users may unknowingly interact with spoofed servers, leading to security breaches.
Innovation Solution
A system and method that utilizes a shared secret between a server and a client to authenticate both the user and the server through image modification, where the server generates an image based on the shared secret, and the user modifies it according to a shared modification secret, with the modified image being analyzed for authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password authentication is used, then user authentication is achieved, but server authentication to the user is not provided
Solution Approach 1:
The patent merges server authentication and user authentication into a single integrated image-based authentication process. The server generates an image containing authentication data, the user modifies the image, and both authentications are completed through analysis of the modified image, eliminating the need for separate authentication mechanisms.
Solution Approach 2:
The patent introduces an image as an intermediary carrier that transports authentication information between the server and user. The image serves as a medium that the user can interact with (modify) while containing encoded authentication data, enabling both parties to authenticate each other through this intermediary object.
2Adaptability or versatility
If users interact with unauthenticated servers on the Internet, then network accessibility is maintained, but security breaches occur through spoofing
Solution Approach 1:
The patent performs preliminary authentication before allowing user interaction with the server. The server generates an authentication image that the user must successfully process, establishing trust before any sensitive operations occur. This preliminary verification prevents spoofing attacks by ensuring the server's identity is confirmed in advance.
Solution Approach 2:
The patent implements a feedback mechanism where the user's modification of the authentication image is analyzed by the server to confirm both parties' identities. The server receives the modified image, analyzes it for correctness, and provides authentication feedback, creating a verified communication channel that resists spoofing.
Data Source
AI summary
Computers can be authenticated using a shared secret. During an authentication process, a server transmits an image to a client. A mobile device captures and analyzes the image. If the image contains the shared secret known only to the authentic server and the authentic mobile communication device, the mobile device can authenticate the server. The secret in the image can be readily analyzed. A single image may contain multiple shared secrets. Once the server has been authenticated, the user must modify the image in accordance with a shared modification secret to thereby authentic the user. The modified image is transmitted back to the authenticated server. If the image was properly modified, the user is authenticated.


