Scrambled Keypad Authentication for Secure Mobile PIN Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods, particularly in the banking industry, face challenges in providing secure authentication on mobile devices and require significant infrastructure changes to adopt biometric authentication, which also raises concerns about the security of biometric data.
Innovation Solution
A method that generates an operable, scrambled keypad on a device's screen while displaying a non-scrambled keypad image, allowing users to input identifiers without storing the real input on the device, using biometric data or random numbers to determine the keypad configuration, ensuring enhanced security by encoding the input before transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric authentication is implemented, then user convenience is improved (no need to remember passwords), but security risks increase (biometric data can be compromised and cannot be changed)
Solution Approach 1:
The authentication process is segmented into two distinct phases: biometric verification (what you are) and PIN entry (what you know). This segmentation allows the system to leverage the convenience of biometric authentication while maintaining the security of traditional PIN-based methods, avoiding the risk of storing or transmitting raw biometric data.
Solution Approach 2:
The patent introduces an intermediary mechanism where biometric data serves as a key to unlock a secure session, but the actual authentication credential (PIN) is entered through a scrambled keypad that prevents direct capture. The biometric data never leaves the device, and the PIN is encoded during entry, creating a secure intermediary layer between the user and the authentication system.
2Reliability
If scrambled keypad encoding is used, then security is improved (real input not stored on device), but device complexity increases (requires generating and managing scrambled keypad configurations)
Solution Approach 1:
The keypad configuration is made dynamic and transient rather than static. The scrambled keypad is generated temporarily during the authentication session and then discarded, preventing any persistent storage of sensitive data. The scrambling pattern changes with each session, ensuring that even if intercepted, the data cannot be reused.
Solution Approach 2:
The system changes the parameter of keypad key positions dynamically during authentication. Each key on the scrambled keypad maps to a different physical position than its standard location, and this mapping is determined by a random or biometric-derived pattern. This parameter change ensures that the same PIN entry will produce different encoded results each time.
3Reliability
If two-factor authentication (biometric + PIN) is implemented, then security is improved, but ease of operation deteriorates (users must complete two authentication steps)
Solution Approach 1:
The biometric verification is performed as a preliminary action before the PIN entry is required. The system quickly verifies the user's identity through biometric matching, and only if this preliminary check succeeds does it proceed to request the PIN. This preliminary action filters out unauthorized users early, making the additional authentication step necessary only for legitimate users.
Data Source
Figure 1

AI summary
The invention provides a solution for secure authentication of an individual. The invention comprises methods and apparatus for secure input of a user's identifier e.g. PIN. An image of a keypad is superimposed over a scrambled, operable keypad within a display zone of a screen associated with an electronic device. The keypad image depicts a non-scrambled keypad, in that the keys depicted in the image are in an expected or standardised format or order. The difference in positions of the keys depicted in the image, and those in the operable keypad, provides a mapping which enables an encoded form of the identifier to be generated, such that the un-encoded version is never stored in the device's memory. Preferably, the image depicts a keypad which is standard for the device which it is being shown on. The device may be a mobile phone, a tablet computer, laptop, PC, payment terminal or any other electronic computing device with a screen. The underlying keypad, which is at least partially obscured from the user's view by the image, may be generated at run time by a procedure call. Preferably, this procedure is native to the device ie part of a library which is provided as standard with the device.