Multidimensional Authentication Module for Web Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user identification and authentication in Internet environments rely on long character strings for security, which enhance protection but make it difficult for users to remember their codes, thus compromising security due to potential random character input attempts for account takeover.

Innovation Solution

A system and method for user security authentication that combines a member ID, password, and unique code values from a security code selection module, where the code values are displayed in a random order on a webpage, allowing users to select and encode these values for authentication, increasing complexity and security by using a multidimensional table with various selection options like numbers, characters, images, and keywords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If long character strings are used for authentication codes, then security protection is improved, but user memory burden increases making it difficult to remember codes

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser memory burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system divides the long character string code into multiple segments including member ID, password, and security code selection module codes. Users authenticate by selecting from predefined code options rather than remembering a single long string, reducing memory burden while maintaining security through combined verification of all segments

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from one-dimensional long character string authentication to multi-dimensional authentication by incorporating member ID, password, and security code selection module. This dimensional expansion allows shorter individual codes to collectively provide equivalent or superior security while being easier to remember

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If long character strings are used for authentication codes, then complexity is increased to prevent account takeover, but security is compromised due to potential random character input attempts

Engineering Contradiction:
Improvecode complexityVSAvoidsecurity against random input attempts
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system introduces a security code selection module as an intermediary between the user and the authentication system. This module provides predefined code options that users select rather than input randomly, maintaining high complexity for security while eliminating the vulnerability to random character input attempts through structured selection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system changes from accepting arbitrary long character strings to accepting structured selections from predefined code options. This parameter change maintains complexity through the combination of multiple authentication elements (member ID, password, security codes) while improving security by constraining input to validated options that prevent random input attacks

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10924474B2User security authentication system in internet and method thereof
Publication Date: 2021.02.16 EBAY INC
  • US10924474B2 patent drawing
  • US10924474B2 patent drawing
  • US10924474B2 patent drawing

AI summary

Example embodiments of the present invention provides a system and method for user security authentication in an Internet environment, in which the user may generate encoded member authentication data by combining a member ID, a password, and a unique code value of a security code selection module that are selected when the user has signed up for membership to any web service provider system, thus increasing code complexity in an access stage in which the web service provider system is accessed as well as simply enhancing security.