Multi-Step Authentication Using Subjective Emotional Responses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-step authentication methods that rely solely on objective credentials are vulnerable to breaches, as they require storing and maintaining secret data, which can be compromised by advanced technologies like OCR and image recognition.

Innovation Solution

Implementing a user-authentication system that uses both objective and subjective credentials, where users authenticate by responding to subjective challenges with emotional descriptions, eliminating the need to store secret responses and enhancing security through interactive inference based on user behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-step authentication mechanisms verify only objective credentials, then authentication security is improved compared to one-step password-based authentication, but the system remains vulnerable to cracking by malicious parties with access to stored credentials and advanced recognition technologies

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to cracking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the traditional mechanical system of storing and verifying objective credentials (passwords, PINs) with a physiological system that measures and analyzes the user's autonomic nervous system responses. Instead of relying on memorized secrets that can be stolen, the system uses biological signals (skin conductance, heart rate, respiration) that are difficult to replicate or steal, thereby substituting a vulnerable mechanical credential system with a more secure physiological authentication system

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter being authenticated from objective knowledge (what you know) to physiological state (how you respond). By measuring and analyzing the user's physiological parameters during authentication challenges, the system transforms the authentication basis from static stored credentials to dynamic biological responses, making the authentication process resistant to traditional credential theft attacks

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the system stores secret responses for verification, then authentication can be performed, but security is compromised because stored secret data can be stolen or compromised

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the secret verification data from storage and replaces it with real-time physiological measurements. Instead of storing secret responses in a database that could be compromised, the system extracts authentication information directly from the user's current physiological state during the authentication process, eliminating the need to store sensitive secret data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses the user's own physiological responses as the authentication credential, eliminating the need for external storage of secret data. The user's body effectively serves as the storage medium for authentication information, with each physiological response being unique and non-storable, thereby making the system self-sufficient and free from vulnerabilities associated with stored secrets

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10798091B2Multi-step authentication using objective and subjective credentials
Publication Date: 2020.10.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10798091B2 patent drawing
  • US10798091B2 patent drawing
  • US10798091B2 patent drawing

AI summary

Multi-step user authentication combines steps of authenticating both objective and subjective credentials. A user selects objective credentials, such as a password, and enters subjective credentials, such as a subjective description of the user's emotional response to a subjective challenge, such as a musical recording or image. The system identifies other content likely to elicit a similar emotional response from the same user. When the user later attempts to log onto a secured system, the user must enter the objective credentials and then describe the user's emotional response to a second subjective challenge that is likely to elicit an emotional response similar to that invoked by the first subjective challenge. If the user enters the correct objective credentials and describes an emotional response consistent with the first subjective description, then the user is given access to the secured system.