UI Authentication via Dynamic Image Variants
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure computing technologies, such as Hardware Security Modules (HSMs), are inadequate in preventing spoof attacks, as users may not be adequately informed about the authenticity of User Interfaces (UIs), and text-based authentication methods are vulnerable to over-the-shoulder attacks and user neglect.
Innovation Solution
Displaying recognizable images that can only be accessed by authenticated processes, with a large set of distinguishable images created through modification processes, and implementing a secure attention sequence to remove unauthenticated UIs, ensuring users recognize and trust only authenticated processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If text strings are used to authenticate a UI to a computer user, then the authentication mechanism is simple to implement, but users may overlook the authentication indicator and the system becomes vulnerable to over-the-shoulder attacks
Solution Approach 1:
The patent replaces text-based authentication indicators with image-based authentication indicators. Instead of displaying text strings that users may overlook or that can be easily observed by attackers, the system displays images that are more visually attention-grabbing and harder to spoof. This substitution leverages visual processing mechanisms in the human brain, which are more effective at capturing and retaining user attention compared to text processing.
Solution Approach 2:
The patent utilizes visual properties of images including color, brightness, and graphical elements to create authentication indicators that are distinctly different from normal UI elements. The images can be modified with various visual transformations (rotation, scaling, color changes) to create multiple variants, making it harder for attackers to predict or spoof the authentication indicator while keeping the verification process simple for users.
2Device complexity
If a single authentication image is used, then the implementation is simple, but the system becomes vulnerable to spoof attacks where attackers can replicate the same image
Solution Approach 1:
The patent implements a dynamic image selection and modification system where authentication images are not static but can be transformed through various operations such as rotation, scaling, color transformation, and cropping. The system can select from multiple pre-generated image variants or dynamically transform a base image to create the authentication indicator. This dynamic approach ensures that even if an attacker observes one authentication image, they cannot reliably replicate it because the next authentication cycle may present a different variant.
Solution Approach 2:
The patent changes multiple parameters of the authentication images including spatial orientation (rotation angles), size (scaling factors), color properties (hue, saturation, brightness transformations), and compositional elements (cropping regions). By varying these parameters across different authentication instances and user sessions, the system creates a large space of possible authentication indicators, making statistical spoofing attacks ineffective while maintaining a relatively simple implementation based on standard image processing operations.
Data Source
AI summary
Access to an authentication image may be protected so that only authenticated processes have access to the image. The image can be displayed to authenticate a User Interface (UI) to a computer user. The image indicates the UI can be trusted. If the image is not displayed, it may be that an application UI is “spoofed” to trick a user into providing sensitive information. Additionally, a large variety of different images can be used as authentication images, so spoofing one image be recognized by most users. A set of original images may be provided, along with image modification processes which can generate a large number of variations. Techniques for authenticating UIs in a virtual machine context are provided. A secure attention sequence is also provided, which allows users to test whether processes running on a computer are authenticated.


