Random Partial Pattern Recognition Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard Static Password Recognition (SSPR) algorithms are vulnerable to brute-force attacks and have limited combinatorial capacity, making them inadequate for large-scale security systems, while alternative methods like biometrics are expensive and face public reluctance.

Innovation Solution

The Random Partial Pattern Recognition (RPPR) algorithm enhances security by using a graphical user interface for users to input a random subset of data fields from a full pattern stored on the server, expanding combinatorial capacity without exceeding users' memorization limits, and providing strong protection against various attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard static password recognition (SSPR) algorithms are used, then the system is simple and widely adopted, but the system is vulnerable to brute-force attacks and has limited combinatorial capacity

Engineering Contradiction:
Improvesecurity against brute-force attacksVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two distinct phases: account set-up mode where the user creates a passcode, and account authentication mode where the user provides a challenge response. This segmentation allows the system to maintain simplicity in the authentication phase while achieving high security through the cryptographic challenge-response mechanism, resolving the contradiction between security reliability and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by requiring account set-up mode to be completed first, where the user's passcode is processed to generate cryptographic credentials stored on the server. This preliminary cryptographic preparation enables the authentication phase to achieve high security against brute-force attacks without requiring complex real-time processing, thus resolving the contradiction between security and complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If password length is increased to sustain combinatorial attacks, then security is improved, but user memorization comfort level is exceeded

Engineering Contradiction:
Improvepassword combinatorial capacityVSAvoiduser memorization comfort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical approach of increasing password length with a cryptographic substitution approach. Instead of relying on long passwords for combinatorial capacity, the system uses cryptographic hash functions and challenge-response mechanisms that provide high security with short passcodes. This substitution resolves the contradiction by achieving high combinatorial capacity through cryptography rather than through increased password length.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter from password length to cryptographic key space. The server stores cryptographic credentials derived from the user's passcode through hash functions, transforming the security basis from combinatorial password space to cryptographic key space. This parameter change enables high security with short passcodes, resolving the contradiction between combinatorial capacity and memorization comfort.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If enterprise-level password policies requiring 4-5 alphanumeric characters are implemented, then security is improved, but password reset frequency increases due to user forgetfulness

Engineering Contradiction:
Improveenterprise security levelVSAvoidpassword reset time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service through the challenge-response authentication mechanism where users interact with a graphical interface to visually select and enter challenge elements corresponding to their passcode. This self-service approach makes authentication more intuitive and memorable, reducing forgetfulness and reset frequency while maintaining enterprise-level security through cryptographic verification, thus resolving the contradiction between security and time loss.

Inventive Principle:
Principle #25Self-service

4Reliability

If biometric authentication methods are used, then security is improved, but cost increases and public reluctance arises

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent employs cheap, software-based cryptographic credentials instead of expensive biometric hardware. The server stores cryptographic data structures that can be generated and updated at low cost, providing high security through mathematical principles rather than expensive biological sensors. This approach resolves the contradiction by achieving authentication security through inexpensive cryptographic methods rather than costly biometric systems.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS7577987B2Operation modes for user authentication system based on random partial pattern recognition
Publication Date: 2009.08.18 AUTHERNATIVE INC
  • US7577987B2 patent drawing
  • US7577987B2 patent drawing
  • US7577987B2 patent drawing

AI summary

A system for authentication of a client includes logic supporting a “what user knows” algorithm for authentication of a client, such as a random partial pattern recognition algorithm, based upon client credentials including an account user name and an account authentication code. Logic supporting client account administration is operable without human intervention on the server side, and includes at least one mode of operation that presents an interface to a client via the data network having at least two tiers of security based on input by the client of secret information shared only between the client and the server. A first tier in said at least two tiers requires entry of one of the account user name and user's email address, and a second tier in the at least two tiers requires entry of one of client profile data sufficient to identify the client and at least a subset of said account authentication code.