Text-Reading Test Authentication for Automated Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, such as two-step authentication and smart cards, are cumbersome, resource-intensive, and unable to effectively prevent phishing, Man-in-the-Middle (MITM), and Man-in-the-Browser (MITB) attacks, which pose significant risks in online transactions by allowing unauthorized access and data tampering.

Innovation Solution

Implementing a Text-Reading Test (TRT) that uses distorted text embedded in images or audio-visual presentations, which can only be deciphered by humans, to authenticate users by requiring them to recite or confirm the content, thereby distinguishing human users from automated programs and ensuring secure communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-step authentication or smart card methods are used, then security against automated attacks is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical/authentication hardware systems (smart cards, tokens) with a software-based Turing test mechanism that uses distorted text images and audio presentations. This substitution maintains security reliability while eliminating the need for additional physical authentication devices, thereby reducing device complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system performs self-verification by presenting distorted text or audio that only human users can interpret. The system automatically compares user responses with expected answers, eliminating the need for manual verification steps or additional authentication hardware, thus simplifying the overall authentication process while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If out-of-band communication is used for transaction confirmation, then security is improved, but loss of time and productivity worsen

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the transaction confirmation process with the authentication process by integrating the Turing test directly into the transaction flow. Users verify transaction details and authenticate simultaneously through the distorted text/audio challenge, eliminating the need for separate out-of-band communication steps and reducing time loss while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary authentication verification through the Turing test before the actual transaction is processed. By validating user humanity and intent in advance through the distorted text/audio challenge, the system prevents fraudulent transactions without requiring time-consuming post-transaction verification steps.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If traditional authentication methods are used, then ease of operation is maintained, but object-generated harmful factors worsen due to vulnerability to phishing and MITM attacks

Engineering Contradiction:
Improveuser convenienceVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a Turing test intermediary mechanism that sits between the user and the authentication system. This intermediary presents distorted text or audio challenges that verify human users while automatically blocking automated attacks. The mechanism maintains ease of operation for legitimate users (who can naturally interpret the distorted content) while eliminating vulnerability to phishing and MITM attacks by preventing automated bot participation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8869238B2Authentication using a turing test to block automated attacks
Publication Date: 2014.10.21 CA TECH INC
  • US8869238B2 patent drawing
  • US8869238B2 patent drawing
  • US8869238B2 patent drawing

AI summary

System and methods for authenticating a transaction between a user system and a host system are described herein. In one embodiment, the system and methods use a text-reading test (TRT) image as part of the authentication process. The TRT image is presented to the user upon initiation of a transaction by the user. Information provided by a user, via the user system, after perception of the TRT image is compared to the source information in the TRT image. If the user input corresponds to the source information, the user is authenticated and transaction is allowed to proceed.