VR Authentication Security via Mobile Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual reality environments, particularly financial centers, face security issues as users' authentication credentials can be compromised when entered within the virtual environment, allowing others to observe and potentially mimic the authentication process.
Innovation Solution
Implementing a two-factor authentication system that requires users to provide something they know, something they have, or something they are, using biometric information, tokens from mobile devices, and randomized objects within the virtual environment to secure authentication, reducing the risk of credential exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide authentication credentials within the virtual reality environment, then the authentication process becomes convenient and integrated, but the security of credentials is compromised as others can observe and potentially mimic the authentication process
Solution Approach 1:
The patent extracts the authentication credential input process from the virtual reality environment and relocates it to the user's mobile device. The virtual reality environment only displays authentication prompts and receives verification, while the actual credential entry (password, biometric, or token) occurs securely on the mobile device where it cannot be observed by others in the virtual space.
Solution Approach 2:
The mobile device serves as an intermediary between the user and the virtual reality authentication system. It handles the sensitive credential input locally and communicates only verification status back to the virtual environment, preventing direct exposure of credentials within the observable virtual space.
2Reliability
If the virtual reality session is streamed to external devices for monitoring, then user activity can be tracked and supported, but authentication credentials become visible to external observers
Solution Approach 1:
The patent applies different quality requirements to different parts of the virtual reality session. During authentication, the session stream is blocked or obscured to external devices. After successful authentication, normal streaming resumes for monitoring purposes. This local quality differentiation ensures credentials are protected while maintaining overall session transparency.
Solution Approach 2:
The streaming to external devices is periodically interrupted or paused during the authentication phase, then resumed after authentication completes. This periodic action allows monitoring to continue for most of the session while temporarily preventing credential exposure during the sensitive authentication window.
3Ease of operation
If users arrange objects in the virtual environment to display authentication information, then authentication can be performed, but observers can watch user movements and mimic the authentication process
Solution Approach 1:
The patent extracts the credential input action from virtual object manipulation and relocates it to mobile device input mechanisms (keyboard, biometric sensor, token reader). The virtual objects serve only as visual prompts, not as the actual authentication interface, eliminating the risk of observers watching hand movements and mimicking the authentication sequence.
Solution Approach 2:
The patent replaces the mechanical interaction of manipulating virtual objects with mobile device-based authentication mechanisms. Instead of physically moving virtual dice or objects to display credentials, users enter credentials through their mobile device's secure input methods, substituting observable mechanical actions with non-observable electronic authentication processes.
Data Source
AI summary
This disclosure provides methods and systems for performing authentication in a virtual reality environment. In some implementations, the system receives a request for access to a virtual reality financial center requiring authentication from a user. The system can collect user identification information that identifies the user and verification information required to verify the user's identity via a virtual reality platform.


