Visually Encoded Ciphertext for Bidirectional User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote user authentication methods lack comprehensive bidirectional authentication and efficient encryption solutions, particularly in scenarios requiring selective encryption of document portions and secure authentication between users and computer systems.

Innovation Solution

A system and method for bidirectional two-factor remote user authentication using visually encoded ciphertext, where login identifiers are encrypted and displayed as authentication images, allowing for decryption and validation through a workflow engine, and enabling selective encryption of document portions using visually encoded ciphertext.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional single-factor authentication methods are used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides authentication into two separate factors: something the user knows (password/PIN) and something the user has (physical token displaying one-time code). This segmentation allows the system to maintain ease of operation with familiar password entry while adding a separate security layer through the physical token, resolving the contradiction between operational simplicity and security strength.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a physical token as an intermediary device that generates and displays one-time codes. This intermediary adds security without requiring the user to memorize additional complex information, as the code is visually presented on the token's display. The intermediary bridges the gap between ease of use and enhanced security by providing a tangible, easy-to-read second factor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If two-factor authentication methods are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The physical token is designed to perform multiple functions: storing authentication credentials, generating one-time codes, displaying codes on an integrated display, and communicating with the authentication system. By consolidating these functions into a single universal device, the patent reduces the need for multiple separate components and reduces overall system complexity while maintaining strong two-factor authentication security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If bidirectional authentication is implemented, then security is improved, but ease of operation is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions by having the server verify the user's password and generate a one-time code before requiring the user to enter it. This preliminary action allows the server to initiate the authentication process and prepare verification data, making the user's subsequent interaction simpler while maintaining bidirectional security verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12469411B2Content encryption and in-place decryption using visually encoded ciphertext
Publication Date: 2025.11.11 CYPHLENS LLC
  • US12469411B2 patent drawing
  • US12469411B2 patent drawing
  • US12469411B2 patent drawing

AI summary

A system for bidirectional two-factor remote user authentication includes a workflow engine comprising one or more processors and at least one memory element for storing instructions. The system further includes a client device with one or more processors, a display, and a user login interface. The workflow engine generates and encrypts one or more login identifiers, which is visually encoded as an authentication image and displayed on the terminal's display. An electronic device, also connected to the workflow engine, includes a password, a display with a graphical user interface, one or more processors, and at least one memory element. The device's authentication identifier reader decrypts the one or more login identifiers from the authentication image and compares it with the password to determine a match. Upon a match, the device transmits an authorization for the login request to the workflow engine.