Touchscreen Password Authentication via Overlapping Windows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication techniques using personal identification numbers (PINs) are vulnerable to shoulder surfing and keylogger attacks, as the password is exposed during input, and existing methods to prevent keylogger attacks do not adequately protect against observation.
Innovation Solution
A password authentication method where a user sets a password and an identification image, and moves a keypad window and image window on a screen to overlap, determining if the corresponding keys and image overlap, thereby authenticating the password without direct input, using a touch screen interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a password is directly input through a conventional interface, then the authentication process is simple and fast, but the password is exposed to shoulder surfing and recording attacks
Solution Approach 1:
The authentication interface is segmented into two separate windows: a keypad window containing keys and an image window containing multiple images. The user must selectively overlap the image window with the keypad window to reveal the password, preventing direct observation while maintaining authentication functionality.
Solution Approach 2:
An identification image is introduced as an intermediary element between the user and the password. The user overlaps the identification image with the keypad window to indirectly select the password without directly inputting it, preventing exposure to shoulder surfing and recording attacks.
2Reliability
If random numbers are arranged for password input to prevent keylogger attacks, then keylogger attacks are mitigated, but the password remains exposed via shoulder surfing or recording attacks
Solution Approach 1:
The identification image serves as a mediator that allows the user to indirectly input the password by overlapping it with the keypad window. This indirect input method prevents the password from being exposed during the input process, addressing both keylogger and shoulder surfing vulnerabilities.
Solution Approach 2:
The password input process is transformed from a direct one-dimensional input into a two-dimensional overlapping operation. The user must position the image window over the keypad window, adding a spatial dimension to the authentication process that prevents observation-based attacks.
3Ease of operation
If the user directly types the password, then the input process is quick and easy, but the password is visible and can be captured by attackers
Solution Approach 1:
The identification image acts as a mediator that enables the user to input the password indirectly through overlapping operations rather than direct typing. This maintains operational convenience while preventing password exposure to attackers.
Solution Approach 2:
The interface elements (keypad window and image window) are made dynamic and movable, allowing the user to freely position and overlap them. This dynamic interaction maintains ease of operation while the overlapping mechanism prevents password exposure.
Data Source
AI summary
Provided are method and apparatus for authenticating a password of a user terminal. The method includes: pre-setting, by a user, a password and an identification image for identifying the password; moving a keypad window or an image window realized on a screen of the user terminal according to an action of the user; determining, when a plurality of images included in the image window and a plurality of keys included in the keypad window sequentially overlap with each other, whether a plurality of keys and the identification image corresponding to the password sequentially overlap; and authenticating the password when the plurality of keys and the identification image corresponding to the password sequentially overlap. Accordingly, password information may be protected from a third person observation as the user inputs a pre-set password in an indirect method without having to directly input the pre-set password through an authentication interface.


