Position-Based Grid Authentication for Front-End Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, particularly those relying on passwords, are vulnerable to front-end attacks such as phishing, malware, and keylogging, and are difficult for users to remember and manage, leading to security weaknesses and frequent credential resets.

Innovation Solution

The integration of an enumerated position-based challenge and response system within a grid of fields, where users interact with a dynamic grid of random digital content, using either position-based or content-based challenges and responses, to create a secure and user-friendly authentication paradigm.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are made longer and more complex to improve security, then security strength is improved, but user memorization difficulty and operational complexity increase

Engineering Contradiction:
Improvesecurity strengthVSAvoiduser memorization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces traditional text-based passwords with a graphical authentication system using a grid of fields containing digital content. Users authenticate by recognizing and interacting with visual patterns and positions rather than memorizing complex character sequences, substituting mechanical memory recall with visual pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The invention transitions from one-dimensional linear passwords to a two-dimensional grid structure with multiple fields. This dimensional expansion allows authentication information to be distributed across spatial positions and visual content, enabling more secure authentication without increasing memorization burden through the use of visual-spatial relationships.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If traditional password-based authentication is used, then implementation simplicity is maintained, but vulnerability to front-end attacks increases

Engineering Contradiction:
Improveimplementation simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication secret from the digital content fields themselves and stores it separately as enumerated position information. The grid fields contain random digital content that changes per session, while the actual authentication credential is the enumerated list of field positions, separating the challenge presentation from the secret storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements dynamic grid content that is randomized for each authentication session. The digital content in the fields changes between sessions, making each authentication challenge unique and preventing attackers from using recorded sessions or pre-computed attacks, while the underlying enumerated position structure remains consistent for the user's credential.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If digital content is used in authentication challenges, then authentication flexibility is improved, but attack vectors relying on digital content are created

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidattack vectors
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces an intermediary layer where the enumerated field positions serve as the actual authentication credential, while the digital content in the fields acts as a mediator or placeholder. The digital content facilitates the authentication interaction but is not the secret itself, preventing attackers from compromising the system by analyzing or recording digital content.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8955074B2Authentication method of enumerated pattern of field positions based challenge and enumerated pattern of field positions based response through interaction between two credentials in random partial digitized path recognition system
Publication Date: 2015.02.10 AUTHERNATIVE INC
  • US8955074B2 patent drawing
  • US8955074B2 patent drawing
  • US8955074B2 patent drawing

AI summary

An interactive method for authentication is based on two shared secrets, both shared secrets in the form of an ordered path on the frame of reference. An instance of the frame of reference comprises a set of characters which is arranged in a random or other irregular pattern. The first step of authentication that a user performs requires the user to remember one or all of the characters in the displayed instance of the frame of reference found in the locations in the random subset of the first ordered path by indicating characters either in these locations, or any other locations having the same characters. The second step of authentication requires that a user enter the position of the second ordered path, which only they know during an authentication session, where the challenge identifying the position of the ordered path is the single or multiple values that matches the value of the digital content of the frame of reference.