Secret Tap Rhythm Authentication Against Shoulder Surfing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods are vulnerable to attacks such as shoulder surfing and remote observation of key sequences, which compromise security by allowing attackers to record and replay user inputs without permission.

Innovation Solution

Implementing a user authentication system that uses secret tap rhythms, where users register and authenticate with unique tap sequences and pauses, encoded as rhythms, which are protected from view by being input within a secure area.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password or biometric authentication is used, then user authentication can be performed, but the system is vulnerable to shoulder surfing and remote observation attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidshoulder surfing and remote observation attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication input process from the visible public space and relocates it to a private, secure area (such as a pocket or concealed compartment). By taking out the vulnerable typing action from public view and placing it in a hidden location, the system eliminates the risk of shoulder surfing and remote observation while maintaining the authentication function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a physical intermediary (a secure container or pocket with a hidden interface) that mediates between the user and the authentication system. This intermediary provides a concealed space where users can input authentication credentials without being observed, acting as a barrier between the vulnerable input process and potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If new authentication devices are introduced to improve security, then authentication security is enhanced, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidnew device requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the secure area serve multiple functions: it acts as both a physical container for the user's belongings and a secure authentication input interface. The same pocket or concealed compartment that holds personal items also provides the secure space for entering authentication credentials, eliminating the need for dedicated specialized authentication devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system utilizes the user's existing personal space (pockets, bags, or concealed compartments) for its intended purpose of storing belongings, while simultaneously enabling this space to function as a secure authentication interface. The user's own environment serves the dual purpose without requiring additional specialized equipment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250371121A1Security by secret tap rhythm
Publication Date: 2025.12.04 DELL PROD LP
  • US20250371121A1 patent drawing
  • US20250371121A1 patent drawing
  • US20250371121A1 patent drawing

AI summary

Techniques described herein relate to a method for performing user authentication. The method includes obtaining an authentication request from a user, wherein the authentication request comprises a tap rhythm generated by the user using an authentication device; in response to the obtaining: identifying a user entry of a user entry repository associated with the user, wherein the user entry comprises an authenticating tap rhythm associated with the user; comparing the tap rhythm with the authenticating tap rhythm; making a determination that the tap rhythm matches the authenticating tap rhythm; and in response to the determination: approving the authentication request.