Random Partial Digitized Path Recognition for Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication systems face challenges in reducing entropy leakage, particularly due to guessing attacks and reengineering of credentials, despite conventional security measures like echo dots and data encryption, which can be vulnerable to intruders recording challenges and responses over multiple sessions.
Innovation Solution
The implementation of a Random Partial Digitized Path Recognition system with a Secret Challenge (RPDPR-SC) uses a graphical representation of a frame of reference with characters positioned at random locations, where the secret challenge is embedded within the path, allowing users to enter authentication responses without revealing sensitive information, thus minimizing entropy leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication systems use shared secrets for user verification, then authentication functionality is achieved, but entropy leakage occurs over multiple sessions allowing credential reengineering
Solution Approach 1:
The patent segments the authentication credential into two separate components: a static shared secret and a dynamic session-specific challenge. The challenge is generated randomly for each authentication session and combined with the shared secret to form the authentication token. This segmentation ensures that even if one component is compromised, the other remains secure, preventing credential reengineering attacks.
Solution Approach 2:
The patent introduces dynamic challenges that change with each authentication session. Instead of using a static shared secret alone, the system generates a unique challenge value for each session that is combined with the shared secret. This dynamic approach ensures that authentication credentials are different each session, eliminating entropy leakage and making replay attacks ineffective.
2Reliability
If the authentication challenge is made more complex to resist guessing attacks, then security against guessing attacks improves, but user operation complexity increases
Solution Approach 1:
The patent uses a server as an intermediary that generates and manages the complex challenge values. Instead of requiring users to create or remember complex secrets, the server automatically generates random challenges and combines them with the user's shared secret. This intermediary approach maintains high security while simplifying the user experience, as users only need to provide their shared secret without worrying about challenge generation.
Data Source
AI summary
An interactive method for authentication is based on two shared secrets, including a first shared secret in the form of an ordered path on the frame of reference, and a second shared secret in the form of locations on the frame of reference at which characters identifying a subset of the ordered path are to be displayed. An instance of the frame of reference comprises a set of characters which is arranged in a random or other irregular pattern. Authentication requires that a user enter the characters in the displayed instance of the frame of reference found in the locations in the random subset of the ordered path by indicating characters either in these locations, or any other locations having the same characters. Thus, a secret challenge identifying the random partial subset is embedded within the displayed instance of the graphical representation of the frame of reference.


