Virtual Reality Dynamic Authentication via Gesture Recognition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods are vulnerable to unauthorized access and data breaches, particularly in network transactions, as they rely on conventional one-dimensional passwords that can be easily observed or recorded, leading to security compromises.

Innovation Solution

A virtual or augmented reality system that displays a virtual authentication object, allowing users to enter authentication codes through dynamic gestures in a three-dimensional space, which are detected and combined with a virtual object template and overlay to create a unique, changing authentication code, making it difficult for attackers to replicate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional one-dimensional passwords are used for authentication, then the authentication process is simple and easy to implement, but the security is vulnerable to unauthorized access and data breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from conventional one-dimensional passwords to multi-dimensional authentication by incorporating spatial gestures, temporal sequences, and contextual information. Users perform physical gestures in 3D space that are captured by sensors, adding spatial and temporal dimensions to the authentication process, thereby significantly enhancing security while maintaining user-friendly operation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The authentication system employs dynamic authentication codes that change with each authentication event, rather than static passwords. The system captures real-time gesture data, temporal sequences, and contextual information to generate unique authentication credentials, making each authentication attempt distinct and resistant to replay attacks.

Inventive Principle:
Principle #15Dynamics

2Reliability

If passwords are entered in conventional interfaces, then the input process is straightforward, but the authentication information is susceptible to observation and recording by attackers

Engineering Contradiction:
Improveauthentication information protectionVSAvoidauthentication input convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer between the user and the authentication system in the form of gesture-based input. Instead of directly typing passwords that can be observed, users perform physical gestures that are captured by sensors and translated into authentication codes, protecting the authentication information from direct observation while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces conventional mechanical keyboard input with gesture-based input captured by sensors. Users perform physical movements in space that are detected and converted into authentication codes, eliminating the need for direct keyboard typing and thereby protecting authentication information from shoulder surfing and recording attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If static authentication codes are used, then the authentication process is fast and efficient, but the system is vulnerable to brute-force attacks and credential theft

Engineering Contradiction:
Improveresistance to brute-force attacksVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic refreshment of authentication codes, where each authentication event generates a new unique code based on current gesture and contextual data. This periodic regeneration prevents credential theft and replay attacks, as each authentication code is valid only for that specific moment and gesture sequence.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication system dynamically changes multiple parameters including spatial gesture coordinates, temporal sequences, velocity, acceleration, and contextual information. These parameter variations create uniquely complex authentication codes for each event, providing strong resistance to brute-force attacks while maintaining efficient authentication processing through optimized sensor data capture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10311223B2Virtual reality dynamic authentication
Publication Date: 2019.06.04 BANK OF AMERICA CORP
  • US10311223B2 patent drawing
  • US10311223B2 patent drawing
  • US10311223B2 patent drawing

AI summary

A system for performing authorization of a user in a virtual reality environment includes a virtual reality user device. The virtual reality user device includes a display configured to display a virtual environment. The user device receives a virtual authentication object comprising a virtual representation of an object that the user can manipulate to enter an authentication code. The user device detects gestures performed by the user on the displayed virtual authentication object and forms an authentication request, which includes the virtual authentication object, the detected gestures; and an identifier of the user. The user device sends the authentication request to an authentication server. The authentication server determines an authentication code using the virtual authentication object and the detected gestures. The authentication server authenticates the user by comparing the determined authentication code with an authentication code stored in a database and sends an authentication response to the user device.