Challenge-Response Authentication Using Visual Image Capture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in data processing systems are complex and costly, with issues such as synchronization discordances in hardware tokens, reliance on mobile telephony networks, and security linked only to terminal possession, leading to a need for a more secure and cost-effective solution.

Innovation Solution

A 'Challenge-Response' mechanism using a univocally correlated challenge sent in graphic form, processed by a user's device with image-capturing capabilities, such as a cellular telephone, to generate an answer code for authentication, without requiring radio coverage or internal clocks, and with limited temporal validity to prevent fraudulent reuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware tokens with internal clocks are used for authentication, then security is improved, but synchronization discordances occur and device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware token complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the time-keeping function from the authentication token itself, relying instead on the server's internal clock to generate time-based challenges. This eliminates the need for synchronized clocks in client devices, removing a major source of authentication failures while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server acts as an intermediary that generates and verifies time-based authentication challenges. Instead of requiring client devices to maintain accurate time, the server introduces the time element unilaterally, mediating the authentication process and eliminating synchronization issues.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If bidimensional barcodes and cellular phones with camera are used for visual identification, then authentication security is improved, but dependency on mobile telephony networks increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork dependency
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention uses standard display devices (monitors, screens) that are universally available on computers rather than relying on mobile phone cameras. This multi-functional approach allows the same authentication mechanism to work across different device types without requiring specialized mobile hardware or network connectivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware tokens and smart cards are used for authentication, then security is improved, but implementation costs and management expenses increase

Engineering Contradiction:
Improveauthentication securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system uses software-based authentication that leverages existing server infrastructure and standard client devices. Instead of requiring expensive hardware tokens or smart cards, the system enables authentication through software implementation on ordinary computers, eliminating manufacturing and distribution costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention replaces expensive, durable hardware tokens with inexpensive, software-based authentication mechanisms. The authentication credentials exist temporarily in memory during the authentication process rather than being stored on expensive physical media, reducing both initial implementation and ongoing management costs.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Ease of operation

If user-name and password combination is used for authentication, then ease of operation is improved, but security is weakened

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention implements dynamic authentication challenges that change over time and are generated by the server. Instead of static passwords, the system creates time-varying challenges that require computational processing, providing both security against replay attacks and continued ease of use through automated client software.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2220840B1Method of authentication of users in data processing systems
Publication Date: 2014.01.08 TELECOM ITALIA SPA
  • EP2220840B1 patent drawingFigure 1
  • EP2220840B1 patent drawingFigure 2
  • EP2220840B1 patent drawingFigure 3

AI summary

A method of authentication of users in a data processing system, the method comprising: generating a "Challenge" univocally associated with a user to be authenticated; processing the "Challenge" to generate an expected answer code, to be compared with an answer code that the user has to provide for his/her authentication; encoding the generated "Challenge" for obtaining an image displayable through a display device adapted to display the image to the user; sending the image containing the "Challenge" to the user; displaying to the user the image containing the "Challenge" through the display device; through a user device provided with an image-capturing device, optically capturing the displayed image; through the user device, processing the captured image for extracting from the captured image the "Challenge", and subsequently processing the obtained "Challenge" for generating the answer code; receiving the answer code from the user and comparing it to the expected answer code; and, in case of positive comparison, authenticating the user. One among the actions of generating a "Challenge" and an expected answer code, and the action of processing the captured image that generates the answer code exploit a secret information univocally associated with the user.