Mobile Image-Code Authentication for Web Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing web service authentication methods are vulnerable to fraud due to keylogging programs, requiring servers to take extra precautions, which reduces their efficiency.
Innovation Solution
A user authenticates using a smart device app that issues a secure token, which is used to verify the user's identity through a unique image or audio code, eliminating the need for direct password entry on the server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional username and password authentication is used, then ease of operation is improved, but security deteriorates due to keylogging fraud
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using a mobile device that captures an image displayed on a computer screen. The mobile device app processes this image to generate authentication credentials, acting as a mediator between the computer system and the authentication server. This eliminates direct password entry on the computer, preventing keylogging attacks while maintaining user convenience through the mobile device's secure environment.
Solution Approach 2:
The patent replaces the traditional mechanical keyboard input method with an optical imaging system. Instead of typing passwords on a keyboard that can be monitored by keyloggers, the system uses the mobile device's camera to capture a visual display of authentication credentials. This substitution of mechanical input with optical capture fundamentally prevents keylogging fraud.
2Reliability
If servers take extra precautions to detect malicious parties, then security is improved, but productivity deteriorates
Solution Approach 1:
The patent implements preliminary authentication actions on the mobile device before the actual authentication request reaches the server. The mobile device app performs image capture, processing, and initial validation locally, pre-filtering and preparing authentication data. This preliminary action reduces the burden on servers, eliminating the need for complex real-time fraud detection mechanisms while maintaining high security standards.
Data Source
AI summary
A method for authenticating a user for a web service includes receiving, at a first device, a request from a second device to authenticate the user for the web service and in response to the request, returning a code from the first device to the second device and generating, with the second device, a human-perceptible rendering including the code. The method further includes, capturing the human-perceptible rendering by a third device, providing an identifier of the user by the third device, identifying the code from the human-perceptible rendering, and granting access to the web service based on the code identified and the identifier of the user.


