Touchscreen Session Signature Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user name and password methods for accessing user accounts are not ideal for securing sensitive information, as they lack robustness and usability.

Innovation Solution

An authentication system utilizing a touch screen device to enter session signatures, which are compared to reference signatures stored on a verification server to allow access to user accounts, enhancing security while maintaining usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user name and password methods are used for accessing user accounts, then the system is simple to operate, but the security is insufficient for protecting sensitive information

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical typing system (keyboard input of passwords) with a biometric authentication system using touch screen signature input. The user's signing behavior on the touch screen captures dynamic characteristics (pressure, speed, timing, stroke order) that are inherently harder to replicate than static passwords, thereby improving security while maintaining ease of operation through natural signing gestures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the authentication parameter from static text (password characters) to dynamic behavioral parameters (signing speed, pressure, timing, stroke order, pauses). These dynamic parameters create a much larger parameter space that is difficult to guess or brute-force, significantly enhancing security while the signing action remains as intuitive as writing by hand

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional password authentication is used, then the device complexity is low, but the security robustness is insufficient

Engineering Contradiction:
Improvesecurity robustnessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a verification server as an intermediary between the user and the account system. This server handles the complex tasks of capturing signing data, extracting behavioral parameters, comparing signatures, and making authentication decisions. This distributes the computational complexity away from the user device while providing enhanced security through server-side verification of dynamic signing characteristics

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a reference copy of the user's signing behavior during enrollment and stores it on the verification server. During authentication, the system captures a new signing copy and compares it against the reference copy using multiple parameter dimensions. This copying approach allows for robust security verification while keeping the user interface simple, as the complexity is handled in the background comparison process

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10791104B2Systems and methods for authenticating users of a computer system
Publication Date: 2020.09.29 PAYEAZY INC
  • US10791104B2 patent drawing
  • US10791104B2 patent drawing
  • US10791104B2 patent drawing

AI summary

An authentication system for allowing access to a user account server has at least one access device and at least one verification server. The at least one access device is capable of operatively connecting to the user account server and comprises a touch screen for allowing entry of session signatures. The at least one verification server is capable of comparing session signatures to reference signatures. A user reference signature is stored on the at least one verification server. The at least one access device allows entry of a user session signature and transmission of the user session signature to the at least one verification server. The at least one verification server allows the at least one user to connect to the user account server based on a comparison of the user session signature with the user reference signature.