Variable Grid Password Authentication Against Shoulder Surfing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication methods, such as PIN-based systems, are vulnerable to shoulder surfing and keylogger attacks, as password exposure occurs during input, and existing grid-based authentication methods still risk revealing the location of predetermined cells.
Innovation Solution
A method and apparatus for password authentication using a variable password, where a user sets and remembers identification grid cells on a terminal screen, and inputs a password by indicating the number of these cells within a predetermined range, with the password being authenticated by matching the input to the number of cells in the authentication range, preventing exposure to third parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a PIN-based authentication method is used, then the authentication process is simple and direct, but the password is exposed during input making it vulnerable to shoulder surfing and keylogger attacks
Solution Approach 1:
The authentication interface is segmented into multiple grid cells instead of a single password field. The password is divided into multiple inputs distributed across different grid locations, preventing complete password exposure in one location and requiring the user to interact with multiple segmented elements rather than typing a continuous password
Solution Approach 2:
The authentication method transitions from a one-dimensional linear password input (typing characters in sequence) to a two-dimensional grid-based input system. The password is represented by selecting grid cells in specific patterns and sequences, adding spatial dimensionality to the authentication process and preventing traditional shoulder surfing and keylogger attacks
2Object-affected harmful factors
If a grid-based authentication method with predetermined cells is used, then password exposure is reduced, but the location of predetermined cells may still be exposed to a third person
Solution Approach 1:
The grid cell selections and authentication ranges are dynamically changed for each authentication attempt. The system randomly determines which grid cells form the authentication range and which cells contain identification markers, so the pattern and location of relevant cells varies each time, preventing observers from learning fixed patterns or locations
Solution Approach 2:
The system pre-establishes multiple possible authentication ranges and identification grid cell configurations before the actual authentication occurs. During authentication, one of these pre-configured patterns is selected and applied, ensuring that the structure is already determined and secure before the user begins interacting with the interface
3Object-affected harmful factors
If a variable password system is implemented, then security against shoulder surfing and keylogger attacks is enhanced, but the authentication system becomes more complex
Solution Approach 1:
The grid cell structure serves multiple functions simultaneously: it provides the visual interface for password input, defines the authentication range, contains identification markers, and establishes the validation logic. This multi-functionality reduces the need for separate components and mechanisms, managing system complexity while maintaining enhanced security
Data Source
AI summary
Provided is a method and apparatus for authenticating a password, wherein the method includes: generating at least one input grid cell into which a password is input from among a plurality of grid cells realized on a screen of a user terminal; and authenticating the password when the password is identical to a number of identification grid cells included in an authentication range predetermined based on the at least one input grid cell, wherein the identification grid cells are set to authenticate the password from among the plurality of grid cells. Accordingly, password information may be prevented from being exposed to a third person observer since a variable password is input whenever a user tries password authentication in a terminal.


