Quotient One-Way Function for Secure Password Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems using one-way functions lack proof of their true nature, leading to potential security breaches and collisions in decoding processes, which compromises the security of password authentication.

Innovation Solution

A method and system utilizing a true one-way function, specifically a quotient of real functions, which is proven to be unique and computationally secure, ensuring that only the authentication value is stored and not the original password, even if the server is hacked.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a Hash function is used to map password to an authentication value, then the password security is improved by not storing the plain password, but the function cannot be proven to be a true one-way function leading to potential collisions and security breaches

Engineering Contradiction:
Improvepassword securityVSAvoidcollision in decoding process
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the core requirement of a true one-way function by removing the problematic element of proven invertibility. It uses a quotient of real functions where the denominator ensures the function never equals zero, making inversion mathematically impossible. This extracts the essential one-way property without the theoretical vulnerabilities of conventional hash functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a composite cryptographic function by combining a real function with a quotient structure. The composite nature of using f(x)/g(x) where g(x) ≠ 0 provides both the one-way property and mathematical proof of security, combining advantages that neither simple hash functions nor individual real functions provide alone.

Inventive Principle:
Principle #40Composite materials

2Productivity

If conventional one-way functions are used for cryptographic applications, then computational efficiency is maintained, but the lack of proof for true one-way nature compromises security

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidcryptographic security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces the mechanical trial-and-error approach of conventional hash functions with a mathematical system based on quotient of real functions. This substitution provides deterministic security proof through mathematical theory rather than relying on computational difficulty assumptions, maintaining efficiency while guaranteeing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of the cryptographic function from arbitrary hash mappings to a structured quotient of real functions with specific mathematical properties. This parameter change ensures the function maintains computational efficiency while providing proven one-way properties through the mathematical structure where the denominator is never zero.

Inventive Principle:
Principle #35Parameter changes

3Speed

If the password is stored in server memory for authentication, then authentication speed is improved, but the password can be stolen and abused if someone gains access to the server

Engineering Contradiction:
Improveauthentication speedVSAvoidpassword theft
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by transforming the password into an authentication value using the proven one-way function before storage. This preliminary transformation ensures that even if the stored data is accessed, the original password cannot be recovered, preventing password theft while maintaining authentication capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of storing authentication data into a benefit by using the quotient of real functions. The mathematical structure ensures that the stored authentication value provides security proof, turning the storage vulnerability into a security advantage where the stored data cannot be inverted to reveal the password.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP2966801B1Chaotic based hash function and their use to authentication.
Publication Date: 2019.08.21 EUROPA UNIVET VIADRINA FRANKFURTODER
  • EP2966801B1 patent drawing
  • EP2966801B1 patent drawing
  • EP2966801B1 patent drawing

AI summary

The invention relates to a method for generating an authentication value, wherein the method is performed by a processor of a computing device and comprises the following steps: receiving an input value, computing, by the processor, an authentication value from the input value using a one-way function, and storing the authentication value in a memory, wherein the one way function is a quotient of functions having a specific rest value. Furthermore, the invention relates to a system for generating an authentication value, a method for verifying an input value and a system for verifying an input value.