Visual Image Authentication for Malware-Resistant Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions fail to securely integrate user identity with data protection and transaction control, as they lack a secure link between user authentication and action authorization, making them vulnerable to malware attacks and hijacking, especially in untrusted computing environments.

Innovation Solution

The use of visual image authentication and non-deterministic random number generators based on quantum physics to create a secure transaction system that leverages human eye-brain processing for authentication, eliminating the need for traditional passwords and providing transaction-dependent passcodes, ensuring that only human users can initiate transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication and cryptography keys are used, then user identity can be verified, but the system remains vulnerable to malware attacks and hijacking because there is no secure link between authentication and transaction authorization

Engineering Contradiction:
Improveauthentication securityVSAvoidmalware attacks and hijacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process into distinct components: visual image authentication for identity verification, quantum random number generation for secure credential creation, and transaction-dependent authorization. This segmentation prevents malware from compromising the entire system by isolating critical functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces visual images as an intermediary between the user and the authentication system. Instead of directly using passwords or cryptographic keys that can be intercepted by malware, the system uses visual images that require human cognitive processing, creating a mediator that malware cannot easily compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptography keys are stored on the user's computer or chip, then authentication can be performed, but the system becomes insecure because the operating system can directly access the keys and they can be compromised by malware

Engineering Contradiction:
Improveauthentication functionalityVSAvoidkey storage security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts cryptographic key generation from the vulnerable environment of the operating system and main memory. Quantum random number generators are used to create keys that never exist in plaintext in the system's memory, and visual image authentication credentials are stored in a manner that prevents direct access by the operating system or malware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the traditional mechanical/digital storage of cryptographic keys with a cognitive-based visual image system. Instead of storing sensitive data that can be read by software, the system uses visual images that require human pattern recognition and cognitive processing, substituting a software-based security model with a human-cognitive-based model that malware cannot access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If the web browser is used for user authentication and action authorization, then a convenient interface is provided, but the connection between authentication and authorization is broken because the browser can be compromised by malware

Engineering Contradiction:
Improveuser interface convenienceVSAvoidauthentication-authorization link
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses visual images as an intermediary that maintains the secure link between authentication and authorization. The visual image authentication result is directly tied to transaction-dependent passcode generation, creating an unbreakable link that operates independently of the browser's security state. The browser remains a convenient interface but the critical security functions operate in a protected manner.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach significantly enhances online transaction security by preventing malware attacks and ensuring that only human users can authenticate transactions, providing a robust and user-friendly solution that is resistant to sophisticated hacking methods.

Implementation Method 1

non-deterministic random number generators based on quantum physics

Methodology Applied
Scientific EffectQuantum physics:

Data Source

PatentUS11128453B2Visual image authentication
Publication Date: 2021.09.21 FISKE SOFTWARE LLC
  • US11128453B2 patent drawing
  • US11128453B2 patent drawing
  • US11128453B2 patent drawing

AI summary

A common vulnerability during a Diffie-Hellman key exchange is a man-in-the-middle attack, where Eve is able to pretend she is Bob to Alice and also pretend that she is Alice to Bob. In an embodiment, after a key exchange is completed, visual image authentication between Alice and Bob can notify Alice and Bob that Eve has launched a man-in-the-middle attack. When Alice's sequence of visual images derived from her shared secret do not match Bob's sequence of visual images, Alice and Bob know that their key exchange has been compromised by Eve. In this case, Alice and Bob should perform their key exchange again.Our invention provides a malware resistant alternative to not using a root certificate during a key exchange. It is well-known that a root certificate can be compromised by an dishonest or corrupt insider. Since the institution has access to the root certificate, there is no guarantee that a rogue network administrator will not use it to personally profit, or breach the security of the system. There is also no guarantee that the institution cannot keep its root certificate from being breached by hackers.In at least one embodiment, quantum randomness helps unpredictably vary the image location, generate noise in the image, or change the shape or texture of the images that help protect Alice and Bob's key exchange.