Security Function Triggering via Challenge-Response Input Pattern Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for triggering security-relevant functions in systems lack a reliable mechanism to ensure that the input is intentionally made by a human user, potentially allowing unintentional or non-human inputs.

Innovation Solution

A method involving the generation and verification of input patterns, such as touch or continuous patterns, displayed on a terminal, where the user's input is captured and compared to a predefined pattern, ensuring a human-initiated request through wireless communication with the system, optionally involving a server for accelerated data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional input methods (e.g., simple buttons or text fields) are used to trigger security-relevant functions, then the ease of operation is improved, but the reliability of ensuring human intent deteriorates

Engineering Contradiction:
Improveease of triggering functionVSAvoidreliability of human intent verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system generates and displays a challenge input pattern (e.g., specific touch sequence, drawing pattern, or gesture) before allowing the security function to be triggered. The user must complete this pattern accurately to proceed, ensuring human intent is verified before the actual security action occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides immediate feedback by displaying the challenge pattern and evaluating the user's input in real-time. The comparison between the expected pattern and actual input gives feedback on whether the authentication succeeded or failed, allowing the system to confirm human intent before triggering the security function.

Inventive Principle:
Principle #23Feedback

2Reliability

If complex input patterns are required to ensure human intent, then the reliability of security triggering is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improvereliability of human intent verificationVSAvoidease of triggering function
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system adapts the complexity of input patterns dynamically based on the security level required, the user's authentication history, and the context of the request. Simple gestures may suffice for low-risk operations, while more complex patterns are required for high-security actions, balancing reliability with usability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters of the input pattern such as complexity, time limit, or sequence length based on the security context. This allows the same authentication mechanism to adjust its difficulty level, maintaining reliability while optimizing ease of operation for different scenarios.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If input patterns are transmitted and verified through wireless communication, then the adaptability and remote access capability are improved, but the difficulty of detecting and measuring genuine human input deteriorates

Engineering Contradiction:
Improveremote triggering capabilityVSAvoiddifficulty of verifying human input remotely
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system moves the input pattern verification to a different dimension by using visual display on a screen combined with touch input detection. This allows the challenge-response mechanism to work effectively over wireless communication, where the user interacts with a visual representation of the pattern on their device while the system verifies the input through the communication channel.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10997282B2Method for triggering a security-relevant function of a system, and system
Publication Date: 2021.05.04 VOLKSWAGEN AG
  • US10997282B2 patent drawing
  • US10997282B2 patent drawing
  • US10997282B2 patent drawing

AI summary

A method for triggering a security-relevant function of a system by a terminal including generating or selecting an input pattern by the system; inputting a request to carry out the function by the terminal; transmitting the input pattern to the terminal; displaying the input pattern on a display and user interface of the terminal, which pattern must be input by a user; capturing and storing an input by a user on the display and user interface by the terminal; transmitting the captured and stored input from the terminal to the system; receiving the captured and stored input by the system; comparing the received input with the transmitted input pattern in the system; and carrying out the function by the system in response to the received input matching the input pattern within a predefined extent. Also disclosed is an associated system.