Visual Image Authentication for Malware-Resistant Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity solutions fail to securely integrate user identity with data protection and transaction control, as they lack a secure link between user authentication and action authorization, making them vulnerable to malware attacks and hijacking, especially in untrusted computing environments.
Innovation Solution
The use of visual image authentication and non-deterministic random number generators based on quantum physics to create a secure transaction system that leverages human eye-brain processing for authentication, eliminating the need for traditional passwords and providing transaction-dependent passcodes, ensuring that only human users can initiate transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password-based authentication and cryptography keys are used, then user identity can be verified, but the system remains vulnerable to malware attacks and hijacking because there is no secure link between authentication and transaction authorization
Solution Approach 1:
The patent segments the authentication process into distinct components: visual image authentication for identity verification, quantum random number generation for secure credential creation, and transaction-dependent authorization. This segmentation prevents malware from compromising the entire system by isolating critical functions.
Solution Approach 2:
The patent introduces visual images as an intermediary between the user and the authentication system. Instead of directly using passwords or cryptographic keys that can be intercepted by malware, the system uses visual images that require human cognitive processing, creating a mediator that malware cannot easily compromise.
2Ease of operation
If cryptography keys are stored on the user's computer or chip, then authentication can be performed, but the system becomes insecure because the operating system can directly access the keys and they can be compromised by malware
Solution Approach 1:
The patent extracts cryptographic key generation from the vulnerable environment of the operating system and main memory. Quantum random number generators are used to create keys that never exist in plaintext in the system's memory, and visual image authentication credentials are stored in a manner that prevents direct access by the operating system or malware.
Solution Approach 2:
The patent replaces the traditional mechanical/digital storage of cryptographic keys with a cognitive-based visual image system. Instead of storing sensitive data that can be read by software, the system uses visual images that require human pattern recognition and cognitive processing, substituting a software-based security model with a human-cognitive-based model that malware cannot access.
3Ease of operation
If the web browser is used for user authentication and action authorization, then a convenient interface is provided, but the connection between authentication and authorization is broken because the browser can be compromised by malware
Solution Approach 1:
The patent uses visual images as an intermediary that maintains the secure link between authentication and authorization. The visual image authentication result is directly tied to transaction-dependent passcode generation, creating an unbreakable link that operates independently of the browser's security state. The browser remains a convenient interface but the critical security functions operate in a protected manner.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly enhances online transaction security by preventing malware attacks and ensuring that only human users can authenticate transactions, providing a robust and user-friendly solution that is resistant to sophisticated hacking methods.
Implementation Method 1
non-deterministic random number generators based on quantum physics
Data Source
AI summary
A common vulnerability during a Diffie-Hellman key exchange is a man-in-the-middle attack, where Eve is able to pretend she is Bob to Alice and also pretend that she is Alice to Bob. In an embodiment, after a key exchange is completed, visual image authentication between Alice and Bob can notify Alice and Bob that Eve has launched a man-in-the-middle attack. When Alice's sequence of visual images derived from her shared secret do not match Bob's sequence of visual images, Alice and Bob know that their key exchange has been compromised by Eve. In this case, Alice and Bob should perform their key exchange again.Our invention provides a malware resistant alternative to not using a root certificate during a key exchange. It is well-known that a root certificate can be compromised by an dishonest or corrupt insider. Since the institution has access to the root certificate, there is no guarantee that a rogue network administrator will not use it to personally profit, or breach the security of the system. There is also no guarantee that the institution cannot keep its root certificate from being breached by hackers.In at least one embodiment, quantum randomness helps unpredictably vary the image location, generate noise in the image, or change the shape or texture of the images that help protect Alice and Bob's key exchange.


