Authentication System Using Junk Data Masking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current password authentication technologies are vulnerable to exposure and hacking due to simplicity, inconvenience, and inability to prevent shoulder surfing, with existing solutions failing to effectively manage junk data generated during authentication attempts.
Innovation Solution
A user authentication system that allows users to input junk data freely before, after, or with their password, and processes authentication as a failure if the junk data matches a previously stored password, enhancing security by masking the actual password and preventing exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users input simple passwords for convenience, then ease of operation is improved, but security deteriorates due to exposure and hacking risks
Solution Approach 1:
The patent introduces junk data as an intermediary element that is mixed with the actual password during authentication. This junk data acts as a mediator that obscures the real password from observers while still allowing the legitimate user to authenticate successfully. The junk data is generated randomly and added to the password input, creating a barrier against shoulder surfing and exposure attacks without requiring users to change their password habits.
Solution Approach 2:
The patent changes the parameter of password input by adding variable junk data to it. Instead of keeping the password static and simple, the system dynamically modifies the password input by appending or prepending random junk data. This parameter change transforms the authentication input from a fixed value to a variable composition, enhancing security while maintaining user convenience.
2Reliability
If users are required to use complex passwords with multiple characters and periodic changes, then security is enhanced, but ease of operation deteriorates due to input errors and user inconvenience
Solution Approach 1:
The junk data serves as an intermediary that absorbs the complexity burden. Instead of requiring users to remember and input complex passwords with special characters and periodic changes, the system introduces random junk data that users don't need to remember. This mediator handles the complexity requirement while users continue to input simple, familiar passwords.
Solution Approach 2:
The system performs automatic password management by generating and managing the junk data component. Users don't need to manually create or remember complex passwords - the system self-generates the junk data and handles the complexity requirements automatically, reducing user burden while maintaining security.
3Ease of operation
If passwords are exposed to surroundings during input, then ease of operation is maintained, but security deteriorates due to shoulder surfing and hidden camera attacks
Solution Approach 1:
The junk data acts as a visual intermediary that conceals the actual password during input. When users type their password with added junk data, observers see a mixture of characters rather than the pure password. This intermediary layer protects against shoulder surfing and hidden camera attacks while allowing users to maintain their normal input speed and familiarity.
4Reliability
If junk data is added to mask the password, then security against exposure is improved, but device complexity increases due to additional data processing
Solution Approach 1:
The patent extracts and separates the junk data component from the actual password verification process. The system extracts only the necessary portion of the input (the real password) while discarding or ignoring the junk data portion. This extraction approach simplifies the processing by focusing only on the essential authentication element rather than processing the entire complex input string.
Solution Approach 2:
The system discards the junk data after it has served its protective function during authentication. The junk data is temporarily introduced to mask the password, fulfills its security purpose, and then is discarded. This temporary use and subsequent discarding reduces the long-term complexity burden on the system while maintaining security during the critical authentication moment.
Data Source
AI summary
The present invention relates to a technique of authenticating a user by using junk data randomly generated when a password is inputted. According to the present invention, a password is received from a user and is stored, and it is determined whether a password matches with an original password stored in a memory among junk data and a password inputted together in a user authentication step. At this time, if a password including the junk data matches, by at least a certain length or more, a password including junk data inputted in a previous authentication step, user authentication fails even if the separately extracted passwords match each other, such that security can be further enhanced.


