Variable Keypad Biometric Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods using variable keypads are vulnerable to password leakage and hacking, as the password itself is transmitted to the server, and do not effectively prevent impersonation by unauthorized users.
Innovation Solution
A user authentication system that transmits only the position information of password input on a variable keypad, combined with biometric data such as iris, fingerprint, or voice recognition, to a server for authentication, ensuring that the password remains secure and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the password itself is transmitted from terminal to server during authentication, then authentication can be performed, but password leakage occurs and security is compromised
Solution Approach 1:
The patent extracts only the essential authentication elements (position information and biometric data) from the complete password, transmitting only what is necessary for verification while leaving the actual password secure in the user's device. This resolves the contradiction by enabling authentication without exposing the full password.
Solution Approach 2:
The patent transforms the one-dimensional password input into a two-dimensional coordinate system on the keypad, where authentication is based on the spatial position and sequence of key presses rather than the password itself. This dimensional transformation allows verification without transmission of the actual password.
2Ease of operation
If a fixed keypad is used for password entry, then user input is simple, but password touch coordinates are revealed and security is compromised
Solution Approach 1:
The patent implements a dynamic keypad layout where key positions are randomized for each authentication session. This dynamic reconfiguration maintains ease of operation through familiar keypad interaction while preventing coordinate exposure, as the same password will have different coordinate sequences in each session.
Solution Approach 2:
The patent performs preliminary randomization of the keypad layout before each authentication session, establishing a new coordinate mapping that prevents previous coordinate information from being useful. This preliminary action secures against replay attacks while maintaining operational simplicity.
3Device complexity
If only password-based authentication is used, then the system is simple, but it cannot prevent impersonation by users who know the password
Solution Approach 1:
The patent merges password-based authentication with biometric verification, combining two different authentication modalities into a unified system. This combination maintains relative simplicity while significantly improving reliability by requiring both knowledge (password) and physical presence (biometric) for successful authentication.
Solution Approach 2:
The patent creates a composite authentication mechanism that combines positional information from the keypad with biometric data, similar to how composite materials combine different substances to achieve properties neither material has alone. This composite approach prevents impersonation while maintaining system accessibility.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
The present invention relates to a user authentication server which mixedly uses both a password and biometric information. The user authentication server comprise: a variable keypad generation unit for generating a variable keypad including encryption keys and a biometric authentication key, wherein the position of each encryption key and the position of the biometric authentication key are changed in each generation of the keypad; an authentication information storage unit for storing authentication information of portable terminal users; and an authentication unit for authenticating a user by remotely providing information of generated variable keypad to a portable terminal, and comparing biometric information and information of the positions of the encryption keys in accordance with the order of input by the user, received from the portable terminal, with the authentication information stored in the authentication information storage unit.