Signature Graph Authentication for High-Entropy Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Humans struggle to memorize high-entropy data, leading to vulnerabilities in data security systems, such as dictionary attacks and man-in-the-middle attacks, especially in public key-based systems, which are costly to maintain and difficult to implement without a certificate authority.
Innovation Solution
A signature graph method using a mini blockchain derived from high-entropy data, generating a visually distinct graph that can be recognized by humans or computer algorithms, eliminating the need for a certificate authority to authenticate the data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high-entropy data is used for authentication, then security is improved, but human memorability deteriorates
Solution Approach 1:
The patent creates a visual copy or representation of the high-entropy authentication data through a graph generated from a mini blockchain. Instead of requiring users to memorize the actual high-entropy data, they memorize the visual graph representation, which serves as a human-friendly copy that preserves the security properties while improving memorability.
Solution Approach 2:
The patent replaces the mechanical/cognitive process of human memorization with an visual recognition system. Users authenticate by recognizing and comparing visual graph patterns rather than memorizing and recalling high-entropy data sequences, substituting cognitive load with visual pattern recognition.
2Reliability
If certificate authorities are used to authenticate public keys, then security is improved, but system cost and complexity increase
Solution Approach 1:
The patent enables devices to self-authenticate through the mini blockchain graph mechanism. Each device generates its own authentication graph from its public key, allowing mutual authentication without requiring external certificate authorities. The system serves itself by creating verifiable visual representations that devices can compare directly.
Solution Approach 2:
The patent extracts the essential authentication function from the complex certificate authority infrastructure and implements it through a simplified mini blockchain graph mechanism. By taking out only the core verification need and implementing it through visual graph comparison, the system eliminates the need for expensive CA infrastructure while maintaining security.
3Reliability
If complex passwords are used, then security is improved, but usability deteriorates due to dictionary attacks and user behavior
Solution Approach 1:
The patent creates a visual copy of the password authentication process through the mini blockchain graph. Instead of users typing and memorizing complex passwords, they recognize and compare visual graph representations, which are generated from the same cryptographic material but presented in a human-friendly format that eliminates dictionary attack vulnerabilities.
Data Source
AI summary
A signature graph method is proposed to authenticate shared high-entropy data using a graph that can be easily identified by human eyes (or by computer image recognition algorithms). An example method for authenticating a shared data element comprises receiving a data element to be shared; transforming the data element to be shared into signature graph data, using at least one collision-resistant one-way mapping function; and rendering a human-perceptible representation of the signature graph data, such as an audible and/or visual representation, for perception by a human user. In some embodiments, transforming the data element comprises applying a cryptographic hash function to the data element, to obtain a first hash output, and applying a cryptographic hash function to the first hash output, to obtain the signature graph data.


