Graphical Authentication Interface Using Spatial Code Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating users to a central server via electronic devices are vulnerable to security threats such as malware, man-in-the-middle attacks, and brute force attacks, particularly when sharing secrets like PIN codes or passwords, as these can be intercepted or compromised.

Innovation Solution

A method and system that associate each electronic device and user with a unique set of digitally stored codes, using a graphical user interface to allow users to specify information through different activation methods, calculating an output value of a one-way function, and authenticating the user if the calculated output value matches the expected value on the central server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, PIN codes) are used, then user authentication can be achieved, but security vulnerabilities arise from malware, man-in-the-middle attacks, and brute force attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication secret from traditional vulnerable channels (keyboards, text inputs) and embeds it within an image matrix. The secret is taken out of the digital text domain and transformed into a visual spatial domain, making it inaccessible to traditional malware and interception methods.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an image matrix as an intermediary between the user and the authentication system. Instead of directly transmitting passwords or PINs, the system uses image coordinates as a mediator to convey authentication information, adding a layer of abstraction that protects against direct interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is used to protect authentication data, then security is improved, but encrypted signals remain vulnerable to keyboard monitoring attacks and memory scanning attacks

Engineering Contradiction:
Improvedata protectionVSAvoidmonitoring attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical/digital input system (keyboards, text fields) with a visual interaction system. Users interact with images through spatial selection rather than textual input, substituting the input mechanism itself to eliminate vulnerabilities associated with traditional input methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a visual copy of authentication information within an image matrix. Instead of storing or transmitting the actual secret in traditional formats, the system creates a visual representation where the secret is embedded as spatial coordinates, making it difficult for attackers to scan and identify.

Inventive Principle:
Principle #26Copying

3Ease of operation

If a software-implemented on-screen keyboard is used, then user input is enabled, but malware can scan and capture user input

Engineering Contradiction:
Improveuser input capabilityVSAvoidmalware scanning
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transitions authentication from a one-dimensional linear input (keyboard sequence) to a two-dimensional spatial input (image coordinates). This dimensional change fundamentally alters the input paradigm, making it impossible for traditional linear scanning malware to effectively capture or predict user input patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Ease of operation

If physical keyboards are used, then user input is enabled, but brute force attacks can test numerous PIN codes automatically

Engineering Contradiction:
Improveuser input capabilityVSAvoidbrute force attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces dynamic elements to the authentication process through image manipulation. The target coordinates within the image can change, rotate, or move, making the authentication challenge dynamic rather than static. This prevents automated brute force attacks from effectively testing multiple possibilities.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3201814B1Method for authentication using an electronic device
Publication Date: 2020.06.10 SURFBOARD PAYMENTS AB
  • EP3201814B1 patent drawingFigure 1
  • EP3201814B1 patent drawingFigure 2
  • EP3201814B1 patent drawingFigure 3

AI summary

Method for authenticating a user to a central server (130) and using an electronic device (120,122) with a screen display (121,123). The method comprises the following steps: a) associating each of the devices or users, with a unique set of codes (132), and each code with a piece of information; b) providing a software function, accessible from the selected electronic device; c) providing, on the screen display, a user interface activatable in several different ways, corresponding to different codes; d) specifying pieces of information and determining the corresponding codes; e) calculating a one-way function; f) communicating the calculated value to the central server; g) calculating a comparison output value; and h) authenticating the user if the values are equal. The invention also relates to a system (100) and a computer software product arranged to cooperate with such a system.