Scrambled Keypad Authentication for Secure Mobile PIN Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, particularly in the banking industry, face challenges in providing secure authentication on mobile devices and require significant infrastructure changes to adopt biometric authentication, which also raises concerns about the security of biometric data.

Innovation Solution

A method that generates an operable, scrambled keypad on a device's screen while displaying a non-scrambled keypad image, allowing users to input identifiers without storing the real input on the device, using biometric data or random numbers to determine the keypad configuration, ensuring enhanced security by encoding the input before transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication is implemented, then user convenience is improved (no need to remember passwords), but security risks increase (biometric data can be compromised and cannot be changed)

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct phases: biometric verification (what you are) and PIN entry (what you know). This segmentation allows the system to leverage the convenience of biometric authentication while maintaining the security of traditional PIN-based methods, avoiding the risk of storing or transmitting raw biometric data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where biometric data serves as a key to unlock a secure session, but the actual authentication credential (PIN) is entered through a scrambled keypad that prevents direct capture. The biometric data never leaves the device, and the PIN is encoded during entry, creating a secure intermediary layer between the user and the authentication system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If scrambled keypad encoding is used, then security is improved (real input not stored on device), but device complexity increases (requires generating and managing scrambled keypad configurations)

Engineering Contradiction:
ImprovesecurityVSAvoidkeypad management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The keypad configuration is made dynamic and transient rather than static. The scrambled keypad is generated temporarily during the authentication session and then discarded, preventing any persistent storage of sensitive data. The scrambling pattern changes with each session, ensuring that even if intercepted, the data cannot be reused.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of keypad key positions dynamically during authentication. Each key on the scrambled keypad maps to a different physical position than its standard location, and this mapping is determined by a random or biometric-derived pattern. This parameter change ensures that the same PIN entry will produce different encoded results each time.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If two-factor authentication (biometric + PIN) is implemented, then security is improved, but ease of operation deteriorates (users must complete two authentication steps)

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The biometric verification is performed as a preliminary action before the PIN entry is required. The system quickly verifies the user's identity through biometric matching, and only if this preliminary check succeeds does it proceed to request the PIN. This preliminary action filters out unauthorized users early, making the additional authentication step necessary only for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3304396B1Authentication methods and systems
Publication Date: 2022.02.23 LICENTIA GROUP
  • EP3304396B1 patent drawingFigure 1
  • EP3304396B1 patent drawing
  • EP3304396B1 patent drawing

AI summary

The invention provides a solution for secure authentication of an individual. The invention comprises methods and apparatus for secure input of a user's identifier e.g. PIN. An image of a keypad is superimposed over a scrambled, operable keypad within a display zone of a screen associated with an electronic device. The keypad image depicts a non-scrambled keypad, in that the keys depicted in the image are in an expected or standardised format or order. The difference in positions of the keys depicted in the image, and those in the operable keypad, provides a mapping which enables an encoded form of the identifier to be generated, such that the un-encoded version is never stored in the device's memory. Preferably, the image depicts a keypad which is standard for the device which it is being shown on. The device may be a mobile phone, a tablet computer, laptop, PC, payment terminal or any other electronic computing device with a screen. The underlying keypad, which is at least partially obscured from the user's view by the image, may be generated at run time by a procedure call. Preferably, this procedure is native to the device ie part of a library which is provided as standard with the device.