- - method and system for authentification using multi-tier multi-class objects
Abstract
The present invention provides a method for authenticating a user in a touch screen environment. The method includes detecting the gesture, and authenticating the user based on the matching of the registered gesture and the detected gesture. The gesture includes dropping objects from the first tier to the second tier or dropping objects from the first tier through at least one intermediate tier to the second tier.

Term
6.9 yearsleft in the term
Expires 6 August 2033.
- Priority
- Filed
- Granted
- Today
- Expires
20 claims: 2 independent, 18 dependent
- 1터치 스크린 환경에서 사용자를 인증하는 방법에 있어서, 복수의 오브젝트를 포함하는 제1 티어 및 복수의 저장소를 포함하는 제2 티어를 포함하는 화면을 터치 스크린에 표시하는 동작;상기 제1 티어로부터의 적어도 하나의 오브젝트를 상기 제2 티어의 적어도 하나의 저장소로 이동시키는 적어도 하나의 사용자 제스처를 상기 터치 스크린을 통해 수신하는 동작;및 상기 수신된 적어도 하나의 사용자 제스처의 시퀀스가 등록된 제스처의 시퀀스와 일치하면, 터치 스크린 장치의 액세스를 허용하는 동작을 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 2제1항에 있어서, 상기 화면은 적어도 하나의 중간 티어를 더 포함하며, 상기 적어도 하나의 사용자 제스처는 상기 제1 티어로부터의 적어도 하나의 오브젝트가 상기 적어도 하나의 중간 티어를 통해 상기 제2 티어의 적어도 하나의 저장소로 이동시키는 사용자 제스처를 포함하며, 상기 적어도 하나의 중간 티어는 상기 제1 티어와 상기 제2 티어 사이에 표시되는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 3제1항에 있어서, 상기 등록된 제스처는 상기 제1 티어의 적어도 하나의 오브젝트를 상기 제2 티어의 적어도 하나의 저장소로 적어도 일회 반복하여 이동시키는 제스처를 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 4제3항에 있어서, 상기 등록된 제스처는 상기 제1 티어로부터의 상기 적어도 하나의 오브젝트를 상기 제2 티어의 상이한 저장소로 연속적으로 반복하여 이동시키는 제스처를 더 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 5제4항에 있어서, 상기 이동된 적어도 하나의 오브젝트의 수는 인증키의 길이와 동일한 것인 터치 스크린 환경에서 사용자를 인증하는 방법.
- 6제1항에 있어서, 더미 오브젝트 및 더미 저장소를 정의하는 동작;및 상기 더미 오브젝트를 저장소로 이동시키고, 접근이 허용되는지 여부의 결정에 영향을 미치지 않는 더미 저장소로 오브젝트를 이동시키는 동작을 더 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 7제1항에 있어서, 상기 복수의 오브젝트를 포함하는 제1 티어 및 상기 복수의 저장소를 포함하는 제2 티어를 정의하는 동작;및 상기 제1 티어의 적어도 하나의 오브젝트가 상기 제2 티어의 상기 적어도 하나의 저장소로의 이동에 대한 시퀀스 순서에 기반하여 인증키를 생성하는 동작을 더 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 8제1항에 있어서, 상기 등록된 제스처는 관리자에 의해 설정되는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 9제1항에 있어서, 상기 수신하는 동작은, 상기 적어도 하나의 제스처에 의해 이동된 적어도 하나의 오브젝트의 수를 기록하는 동작을 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 10제1항에 있어서, 상기 화면은 상기 제1 티어의 각 오브젝트, 상기 각 중간 티어, 또는 상기 제2 티어의 각 저장소 중 적어도 하나가 랜덤하게 배치된 화면을 포함하는 터치 스크린 환경에서 사용자를 인증하는 방법.
- 11전자 장치에 있어서, 터치 스크린;및 제어부를 포함하며, 상기 제어부는, 복수의 오브젝트를 포함하는 제1 티어 및 복수의 저장소를 포함하는 제2 티어를 포함하는 화면을 표시하도록 상기 터치 스크린을 제어하고, 상기 제1 티어로부터의 적어도 하나의 오브젝트를 상기 제2 티어의 적어도 하나의 저장소로 이동시키는 적어도 하나의 사용자 제스처를 상기 터치 스크린을 통해 수신하고, 상기 수신된 적어도 하나의 사용자 제스처가 등록된 제스처와 일치하면, 터치 스크린 장치의 액세스를 허용하는 것을 특징으로 하는 전자 장치.
- 12제11항에 있어서, 상기 제어부는, 상기 제1 티어로부터의 적어도 하나의 오브젝트를 적어도 하나의 중간 티어를 통해 상기 제2 티어의 적어도 하나의 저장소로 이동시키는 상기 적어도 하나의 사용자 제스처를 상기 터치 스크린을 통해 수신하며, 상기 제1 티어와 상기 제2 티어 사이에 상기 적어도 하나의 중간 티어가 표시되도록 상기 터치 스크린을 제어하는 것을 특징으로 하는 전자 장치.
- 13제11항에 있어서, 상기 등록된 제스처는 상기 제1 티어의 적어도 하나의 오브젝트를 상기 제2 티어의 적어도 하나의 저장소로 적어도 일회 반복하여 이동시키는 제스처를 포함하는 것을 특징으로 하는 전자 장치.
- 14제13항에 있어서, 상기 등록된 제스처는 상기 제1 티어로부터의 상기 적어도 하나의 오브젝트를 상기 제2 티어의 상이한 저장소로 연속적으로 반복하여 이동시키는 제스처를 더 포함하는 것을 특징으로 하는 전자 장치.
- 15제14항에 있어서, 상기 이동된 적어도 하나의 오브젝트의 수는 인증키의 길이와 동일한 것을 특징으로 하는 전자 장치.
- 16제11항에 있어서, 상기 제어부는, 더미 오브젝트 및 더미 저장소를 정의하고, 상기 더미 오브젝트를 저장소로 이동시키고, 접근이 허용되는지 여부의 결정에 영향을 미치지 않는 더미 저장소로 오브젝트를 이동시키는 것을 특징으로 하는 전자 장치.
- 17제11항에 있어서, 상기 제어부는, 상기 복수의 오브젝트를 포함하는 제1 티어 및 상기 복수의 저장소를 포함하는 제2 티어를 정의하고, 상기 제1 티어의 적어도 하나의 오브젝트가 상기 제2 티어의 상기 적어도 하나의 저장소로의 이동에 대한 시퀀스 순서에 기반하여 인증키를 생성하는 것을 특징으로 하는 전자 장치.
- 18제11항에 있어서, 상기 등록된 제스처는 관리자에 의해 설정되는 것을 특징으로 하는 전자 장치.
- 19제11항에 있어서, 상기 제어부는, 상기 적어도 하나의 제스처에 의해 이동된 적어도 하나의 오브젝트의 수를 기록하는 것을 특징으로 하는 전자 장치.
- 20제11항에 있어서, 상기 제어부는, 상기 제1 티어의 각 오브젝트, 상기 각 중간 티어, 또는 상기 제2 티어의 각 저장소 중 적어도 하나가 랜덤하게 배치된 상기 화면을 표시하도록 상기 터치 스크린을 제어하는 것을 특징으로 하는 전자 장치.
Independent claims20
95 paragraphs in 1 section, as filed
METHOD AND SYSTEM FOR AUTHENTIFICATION USING MULTI-TIER, MULTI-CLASS OBJECTS
The present invention relates to an authentication method, and more particularly, to a gesture-based authentication method.
Devices with authentication mechanisms can prevent access to confidential information by denying unauthorized access. Today, most application systems are configured to include a touch screen user interface in order to make these systems more user friendly and enhance the user experience. The use of these touch interfaces allows existing authentication applications to use the virtual keyboard displayed on the screen to provide input to the device. Alternatively, existing authentication applications may use a pattern or gesture-based input rather than a virtual keyboard displayed on the screen. In the gesture-based authentication system, the user can form a specific pattern on the screen of the device. If this pattern matches an already registered pattern, the system allows the user to access the device.
Many different systems implement gesture-based authentication mechanisms. In the gesture-based authentication mechanism, the user is allowed to select an object displayed on the screen only once. As such, it is limited for the user to repeatedly select an object in successive iterations. With the existing gesture-based authentication system, the number of possible erroneous combinations of objects displayed on the screen or the number of attempts is not sufficient to guarantee the failure of unauthorized attempts.
As a result, the level of security achieved by this gesture or pattern-based authentication mechanism is low compared to existing numeric keypad systems. To improve security, the screen size of the device must be increased, which limits its use on small screen devices such as smartphones. In addition, potential fraudsters can easily observe and remember patterns entered by authorized users and attempt access to the device. Similarly, if the scammer knows the number of objects to be selected in the pattern, the number of attempts to limit unauthorized access to the device can be reduced.
In light of the above discussion, there is a need for an authentication method that is required for high security applications.
<p>A primary object of embodiments of the present invention is to achieve a method and system for gesture-based authentication using multi-tier based multi-class objects.</p><p>Another object of the present invention is to achieve a high level of security by allowing the user to select objects in each tier regardless of selections in previous iterations.</p>
<p>The present invention provides a method for authenticating a user in a touch screen environment. The method includes detecting the gesture, and authenticating the user based on the matching of the registered gesture and the detected gesture. The gesture includes dropping objects from the first tier to the second tier or dropping objects from the first tier through the middle tier to the second tier.</p><p>The registered gesture includes dropping objects of the first tier into objects of the second tier in a plurality/sequential iterations. In one embodiment, the number of objects dropped is equal to the length of the authentication key. In one embodiment, the objects of the first tier and the second tier are displayed in the touch screen environment. In one embodiment, intermediate tiers are indicated between the first tier and the second tier. The registered gesture is set by the administrator. In one embodiment, detecting the gesture comprises recording the number of objects dropped in the gesture. In one embodiment, authentication includes matching a sequence of dropping objects.</p>
<p>As described above, the authentication method and system using multi-tier and multi-class objects according to an embodiment of the present invention allows a user to select an object in each tier regardless of selection in a previous iteration, thereby providing a high It has the effect of achieving the level of security. </p>
BRIEF DESCRIPTION OF THE DRAWINGS The invention is illustrated in the accompanying drawings in which like reference characters indicate corresponding parts in the various drawings. Embodiments herein will be better understood from the following description with reference to the accompanying drawings. 1 illustrates a touch screen device with modules, in accordance with various embodiments of the present invention. 2 is a flowchart illustrating a method of authenticating a user of a touch screen device according to various embodiments of the present disclosure; 3 illustrates an authentication-key using two tiers in accordance with various embodiments of the present invention. 4 illustrates an authentication-key using one intermediate tier with channels in accordance with various embodiments of the present invention. 5 illustrates an authentication-key using two intermediate tiers with channels in accordance with various embodiments of the present invention. 6 illustrates an authentication key of randomly ordered objects of a source tier and bins of a destination tier, according to various embodiments of the present invention. 7 illustrates a computing environment executing an application in accordance with various embodiments of the present invention.
Embodiments of the invention and its various features and advantageous details are explained more fully with reference to the non-limiting embodiments shown in the accompanying drawings and detailed in the description that follows. Descriptions of well-known components and processing techniques are omitted so as not to unnecessarily obscure the embodiments herein. The examples used herein are merely intended to facilitate understanding of the ways in which the embodiments herein may be practiced and further to enable those skilled in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.
Embodiments in the present invention achieve a gesture-based authentication method and system using objects from a plurality of classes arranged in a plurality of tiers. The method enables the touch screen device to display a plurality of objects. The method allows a user to select, drag and drop objects from a source tier through one or more intermediate tiers to a destination tier. A gesture-based authentication key (also interchangeably referred to as a 'password') is formed based on a number of selected objects with a sequence of dragging and dropping the selected object. The method allows the user to select objects independently of previous iterations, thereby enabling a very high rejection of the scammer. The method described in the present invention exponentially improves the security level with a small increase in the number of objects in any tiers.
Moreover, the present invention is widely applicable to any type of system or application, such as a small screen device, a defense system, an automated teller machine (ATM), a door security system or any other system. The methods described herein are presented graphically and may be implemented in a touch screen environment of a high security system. The method can be conveniently used by a person who can read and write, an illiterate person, or a person who has difficulty remembering or remembering passwords in English and numbers. Graphical gesture-based authentication provides easy integration of the method into devices used by children. The method allows the user to easily adjust the security level of the authentication mechanism according to his requirements. The user may increase the number of objects and/or the number of intermediate tiers in the authentication key to increase the level of security.
In the specification, the terms source tier and first tier are used interchangeably. The terms destination tier and second tier are used interchangeably. The terms gesture and pattern are used interchangeably. The terms touch screen device and touch screen environment are used interchangeably.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS With reference now to the drawings, and more particularly, with reference to Figures 1 to 7 in which like reference characters consistently indicate corresponding features throughout the drawings, preferred embodiments are shown.
1 illustrates a touch screen device 100 with modules in accordance with various embodiments of the present invention. The touch screen device 100 described herein may be configured to include a display module 102 , a touch interface module 104 , a storage module 106 , and a communication interface module 108 . The display module 102 of the touch screen device 100 may be configured to display a plurality of objects in a plurality of classes and a plurality of tiers. This display allows the user to select, drag and drop objects during authentication. The touch interface module 104 may be configured to extract a gesture provided by a user at the touch screen device 100 . The storage module 106 may be a memory space used to store a plurality of objects and registered authentication keys. In one example, the storage module 106 may be internal memory, such as read-only memory (ROM) and random access memory (RAM), or external memory. The communication interface module 108 may be configured to provide a mechanism for the touch screen device 100 to enable external communication with other devices.
In one embodiment, the touch screen device 100 described herein may be a mobile phone, a personal digital assistant (PDA), a personal computer, a portable device, a portable electronic device, communicators, a laptop, or the like.
2 is a flowchart 200 illustrating a method of authenticating a user of the touch screen device 100 according to various embodiments of the present disclosure. The authentication method for protecting the touch screen device 100 includes two steps: an authorization or registration step, and an authentication or verification step. In one example, authorization may be defined as the process of setting the touch screen device 100 to a gesture or pattern of user selection, with the aid of objects selected by the user. The authorized gesture forms an authentication key. In addition, the number of objects selected to generate the gesture determines the authentication key length. In one example, authentication may be defined as a process in which a user presents an authorized pattern to access the touch screen device 100 .
In step 202 of the flowchart 200, the touch screen device 100 displays a plurality of objects in the multi-tier. In step 204, the user selects one object from among the plurality of objects in the first tier. In step 206, the user drops the selected object from the first tier through one of the plurality of elements in each intermediate tier to the last tier. In one example, the method allows the touch screen device 100 to display a plurality of predefined intermediate tiers during the authentication process. In one example, during the authentication process, the user drops the selected object from the source tier through one element in each intermediate tier to the destination tier. The touch screen device 100 verifies whether the gesture executed by the user matches the gesture defined during authorization (registration). In one embodiment, the route taken by the dropped object may be displayed on the screen, thereby assisting the user in tracking the route. In one example, the method may record the number of dropped objects and the sequence of dropped objects.
In step 208, the touch screen device 100 checks whether the number of objects dropped by the user matches the authentication key length. If the dropped objects do not match the length of the authentication key, the touch screen device 100 maintains the object displayed on the screen so that the user can complete the selection and dropping sequence. In one embodiment, in step 210, if the dropped objects successfully match the authentication key length, the touch screen device 200 compares the recorded objects along with the paths with the stored (authorized) authentication key.
In one embodiment, in step 212, if the stored authentication key does not match objects dropped by the user, the method may allow the touch screen device 200 to repeat steps 202-212. In one embodiment, at step 214 , the user may be allowed to access the touch screen device 100 after successful matching. It may be noted that the various operations performed in flowchart 200 may be performed in the order presented and/or in other orders. Moreover, in some embodiments, some operations listed in FIG. 2 may be omitted.
3 illustrates an authentication-key using two tiers in accordance with various embodiments of the present invention. The two-tiers described herein may include a source tier 300 and a destination tier 302, respectively. In one embodiment, destination tiers 302 may include elements B1, B2, B3 (referred to as repositories), while source tier 300 includes elements O1 O2, O3, and O4 ( objects)).
In general, a source set O (referred to as objects) may include a plurality of elements β, and a destination set B (referred to as bins) is represented by Equation 1 and may include a plurality of elements β as described in Equation 2:
<maths num="1"><img file="KR102078552B1_D0001.tif" /></maths>
<maths num="2"><img file="KR102078552B1_D0002.tif" /></maths>
In one embodiment, to authorize the touch screen device 100 , the user drags and drops objects from the source set O to the repository of the destination set B. For example, the user can drag and drop object O1 from source set O to repository B1. In one example, the user may repeat the process for different objects. For each iteration, the selection of an object from source set O or a repository from destination set B is independent of the corresponding selection in previous iterations. Thus, the method may allow the user to repeatedly select objects and repositories. The sequence or order of dropping objects from the source set O to the repositories of the destination set B can be considered as an authentication key. In addition, the number of objects dropped from the source set to the repositories of the destination set may provide the authentication key length (L). Objects of source set O may be dropped into repositories of destination set B based on equations 3 to 7 given below:
<maths num="3"><img file="KR102078552B1_D0003.tif" /></maths>
<maths num="4"><img file="KR102078552B1_D0004.tif" /></maths>
<maths num="5"><img file="KR102078552B1_D0005.tif" /></maths>
<maths num="6"><img file="KR102078552B1_D0006.tif" /></maths>
<maths num="7"><img file="KR102078552B1_D0007.tif" /></maths>
where ? indicates dropping elements from one set to another. In one example, the qth iteration dropping the source set element Oi to the destination element Bj is<img file="KR102078552B1_D0008.tif" />can be considered as sequential order<img file="KR102078552B1_D0009.tif" /> is the authentication key, and L is the length of the authentication key.
3 illustrates the process of authenticating using the two-tier of objects. In one example, the source tier 300 may include four elements (O1, O2, O3, and O4 (referred to as objects)), and the destination tier 302 includes three elements (B1, B2, and B3 (referred to as objects)). referred to as repositories)) may be included. The sequence/order of objects dropped into the respective repositories serves as an authorized authentication key. The sequence order as shown in Fig. 3 for the authentication key length (L = 7) is given in the equation below.
<maths num="8"><img file="KR102078552B1_D0010.tif" /></maths>
<maths num="9"><img file="KR102078552B1_D0011.tif" /></maths>
<maths num="10"><img file="KR102078552B1_D0012.tif" /></maths>
<maths num="11"><img file="KR102078552B1_D0013.tif" /></maths>
<maths num="12"><img file="KR102078552B1_D0014.tif" /></maths>
<maths num="13"><img file="KR102078552B1_D0015.tif" /></maths>
<maths num="14"><img file="KR102078552B1_D0016.tif" /></maths>
Equations 8, 9, 10, 11, 12, 13, and 14 represent actions performed by the user during authentication. In one example, during the first iteration, object O1 of source tier 300 may be dropped into storage B1 of destination tier 301 . In one example, during the second iteration, object O2 of source tier 300 may be dropped into storage B3 of destination tier 301 . In one example, during the third iteration, object O4 of source tier 300 may be dropped into storage B3 of destination tier 301 . In one example, during the fourth iteration, object O3 of source tier 300 may be dropped into storage B2 of destination tier 301 . In one example, during the fifth iteration, object O1 of source tier 300 may be dropped into storage B2 of destination tier 301 . In one example, during the sixth iteration, object O2 of source tier 300 may be dropped into storage B1 of destination tier 301 . In one example, during the seventh iteration, object O4 of source tier 300 may be dropped into storage B3 of destination tier 301 , thereby making authentication key length L equal to 7, wherein the authentication key is <img file="KR102078552B1_D0017.tif" />exists as
In one embodiment, during the authentication process, the user according to an authorized authentication key of length 7 <img file="KR102078552B1_D0018.tif" />Drop the objects O1 , O2 , O3 , and O4 of the source tier 300 into the repositories B1 , B2 and B3 of the destination tier 301 in the same sequence order as In an embodiment, if the user fails to follow the authentication key sequence order, the user may be denied access to the touch screen device 100 .
In one embodiment, the user may select elements of the source set and elements of the destination set from equations 1 and 2. The source set and destination set may use different elements. For example, if the device is being used by kids, the elements of the source tier 300 may be fruits and the elements of the destination tier 302 may be in baskets or boxes. can take In another example, elements in source tier 300 may include video clips (or live video) of various sporting events, and elements in destination tier 302 may include display names of such sporting events. The user can then drop the selected video clip onto the corresponding sporting events.
In one embodiment, the elements of the source tier 300 and destination tier 302 may be toys, pets, a cage, a combination thereof, or any other element. In one example, these elements may be stored in the storage module 106 as a gallery set.
4 illustrates an authentication key using one middle tier with channels in accordance with various embodiments of the present invention. In one embodiment, the method described herein allows a user to use a plurality of intermediate tiers (such as C1, C2, ..., Cζ) between the source tier 300 and the destination tier 302 . By allowing it, it is possible to provide improved security to the touch screen device 200 . As described in Equations 1 and 2, the source set O and the destination set B may include a plurality of elements. In one example, each of the intermediate tiers may also include a plurality of elements called channels. The intermediate tiers C1, C2, ... Cζ may contain an infinite number of channels, called γ, δ, ... η channels, respectively, where τ 0, γ, δ, ...η > 1.
The general form of all elements of all tiers used by the methods described here during the authentication mechanism is as follows:
<maths num="15"><img file="KR102078552B1_D0019.tif" /></maths>
<maths num="16"><img file="KR102078552B1_D0020.tif" /></maths>
<maths num="17"><img file="KR102078552B1_D0021.tif" /></maths>
<maths num="18"><img file="KR102078552B1_D0022.tif" /></maths>
<maths num="19"><img file="KR102078552B1_D0023.tif" /></maths>
<maths num="20"><img file="KR102078552B1_D0024.tif" /></maths>
In one example, L represents the number of objects dropped from the source tier 300 through one channel to the repositories of the destination tier 302, and the sequence/order of dropping objects to the repositories is the authentication key. to form In one example, intermediate tiers such as 1,2,..,τ<img file="KR102078552B1_D0025.tif" />The q-th iteration of dropping the object Oi from the source tier 300 to the storage Bj of the destination tier 302 through channels such as
<maths num="21"><img file="KR102078552B1_D0026.tif" /></maths>
Here, 0< i α, 0 < j β, 0 < x γ, 0 < y δ and 0 < z η.
In one example, each of the selected objects Oi of the source tier 300 passes through one channel in each intermediate tier before being dropped into one of the selected storage Bj of the destination tier 302 . The sequence/order of dropping objects from the source set O to the destination set B is as follows:
<maths num="22"><img file="KR102078552B1_D0027.tif" /></maths>
<maths num="23"><img file="KR102078552B1_D0028.tif" /></maths>
<maths num="24"><img file="KR102078552B1_D0029.tif" /></maths>
<maths num="25"><img file="KR102078552B1_D0030.tif" /></maths>
Here, ? indicates dropping elements from one set to another.
In a generalized form, <img file="KR102078552B1_D0031.tif" />denotes channel k in middle tier i. Channels in middle tiers 1,2,...τ<img file="KR102078552B1_D0032.tif" />The qth iteration dropping the source set object Oi to the destination storage Bj through <img file="KR102078552B1_D0033.tif" />can be expressed as A generalized sequence order for giving an authentication key of length L is given as in Equation 26 below.
<maths num="26"><img file="KR102078552B1_D0034.tif" /></maths>
4 shows a source tier 300 , a destination tier 302 , and an intermediate tier 400 . The middle tier 400 described herein is<img file="KR102078552B1_D0035.tif" />Wow <img file="KR102078552B1_D0036.tif" /> Like channels, it may include two channels. The user authorizes the authentication key by dropping objects from the source tier 300 through the channels of the intermediate tier 400 to the repositories of the destination tier 301 . In one embodiment, the user may drop objects in a specific user-selected sequence order. In one example, during the first iteration, the user<img file="KR102078552B1_D0037.tif" />can drop O1 to B1 through , and during the second iteration, the user <img file="KR102078552B1_D0038.tif" />can drop O2 to B3 through <img file="KR102078552B1_D0039.tif" />can drop O4 to B3 through <img file="KR102078552B1_D0040.tif" />can drop O3 to B2 through <img file="KR102078552B1_D0041.tif" />can drop O1 to B2 through , and during the sixth iteration, the user <img file="KR102078552B1_D0042.tif" />can drop O2 to B1 through , and during the 7th iteration, the user <img file="KR102078552B1_D0043.tif" />You can drop O4 into B3 through . In one example, therefore, the authentication key length L is equal to 7, and the authentication key is<img file="KR102078552B1_D0044.tif" />can be described as
In one example, if the user wants to access the touch screen device 100 , the user must drop objects from the source tier 300 to the destination tier 302 . The sequence/order of dropping objects must be the same as the authentication key. If the user fails to follow the defined sequence, the user is denied access to the touch screen device 100 .
5 illustrates an authentication key using two intermediate tiers with channels in accordance with various embodiments of the present invention. 5 shows a source tier 300 , a destination tier 302 , and two intermediate tiers 500 and 502 . Intermediate tiers are provided between the source tier 300 and the destination tier 302 . In one example, the middle tier 500 is<img file="KR102078552B1_D0045.tif" />Wow <img file="KR102078552B1_D0046.tif" /> It may include two channels such as <img file="KR102078552B1_D0047.tif" />, <img file="KR102078552B1_D0048.tif" /> and <img file="KR102078552B1_D0049.tif" />It may include three channels such as A user of the touch screen device 100 drops objects from the source tier 300 through the channels of the intermediate tiers 500 , 502 to the repositories of the destination tier 302 in an intermediate tier 500 specific user-selected sequence. Authorize the authentication key by pinging. In one example, the sequence shown in Figure 5 is<img file="KR102078552B1_D0050.tif" />Provides an authentication key of length 7 as given by .
6 generally illustrates an authentication-key of randomly ordered objects and repositories in accordance with various embodiments of the present invention. In one example, as shown in FIG. 5 , objects are randomly placed between the source tier 300 and the destination tier 302 . In one example, the order of objects in the source tier 300 is changed to O2, O1, O3, and O4, and the order of the repositories in the destination tier 302 is changed to B2, B1 and B3. A random or shuffled arrangement of objects and repositories can be implemented for every instance of authentication so that a swindler or swindler may be confused. Thus, the sequence/order of dropping objects into the repositories remains unchanged and is known only to authorized users.
In one example, the authentication key generated during the authentication process drops object O1 of source tier 300 into storage B1 of destination tier 302 during a first iteration, and object O2 of source tier 300 during a second iteration. to the storage B3 of the destination tier 302 , drop the object O4 of the source tier 300 during the third iteration to the storage B3 of the destination tier 302 , and during the fourth iteration the object O4 of the source tier 300 Drop object O3 into storage B2 of destination tier 302 , drop object O1 of source tier 300 into storage B2 of destination tier 302 during a fifth iteration, and drop object O1 of source tier 300 into storage B2 of destination tier 302 during a sixth iteration ) into storage B1 of destination tier 302 , and dropping object O4 of source tier 300 into storage B3 of destination tier 302 during the seventh iteration. In one example, 7 iterations define an authentication key length L equal to 7, and the authentication key is<img file="KR102078552B1_D0051.tif" />exists as
In one example, the authentication key defined in the present invention is the same as that defined in FIG. 3 , but the pattern for dropping objects of the source tier 300 to the repositories of the destination tier 301 is different. In one example, a fraudster who imitates the observed pattern is denied use of the touch screen device 100 . Thus, the method provides enhanced security to the touch screen device 100 by randomly ordering the displayed objects (rather than having a fixed or static display pattern).
In one embodiment, the user's location may be identified from applications such as a global positioning system (GPS), a system time and date application installed on the touch screen device 100, user profiles, or any other application. Moreover, based on the user location information, the method may allow the touch screen device 100 to change the display or gallery set of the screen accordingly. For example, the user may apply the touch screen device 100 to different gallery sets.
In one embodiment, the method may enable the touch screen device 100 to easily add empty or dummy bins among existing bins of the destination tier 302 . Any objects in the source tier 300 dropped into dummy repositories may be ignored or considered based on the authorized user's preference. If the user recognizes a potential scammer, the user can drop objects into a dummy repository that cannot be accounted for according to the authorized user's preferences. Thus, fraudsters who may attempt to imitate user gestures do not notice the dummy store and fail to access the touch screen device 100 . In one embodiment, dummy objects may be part of the objects of the source tier 300 . Dummy objects dropped into true bins or dummy bins may be ignored. These dummy objects in the source tier 300 or dummy repositories in the destination tier 302 can provide many folds as compared to static pattern based authentication to improve the level of security. have.
In one embodiment, the method may enable the touch screen device 100 to easily execute a plurality of authentication checks, all of which may be adjusted to different security levels based on a user's requirements. For example, a user may have a low security level of authentication for unlocking a smart phone, but may include a high security level authentication check for certain important files or folders. The security level can be configured by the user by using a larger number of intermediate tiers thereby allowing others to access the smart phone without the user having to worry about secret information being disclosed.
analysis
Comparative analysis shows that the proposed method is much more secure than the existing gesture-based authentication method. The rating scale presents a mathematical analysis of a method using existing methods. The source tier 300 represented by the source set O and the destination tier 301 represented by the destination set B have α and β objects as shown in Equations 1 and 2, respectively, and intermediate tiers 1,2,.. .τ may include γ, δ, η channels, respectively. Existing methods may include only one set of objects, such as an alphabetic set, to achieve fair comparisons. The sum of the number of elements from all tiers that may include a source tier, a destination tier, and all intermediate tiers is regarded as an alphabetic set having a size χ, and is expressed by Equation (27).
<maths num="27"><img file="KR102078552B1_D0052.tif" /></maths>
Metrics used for comparison can be, for example, Elimination Combinations (EC), Visual Eliminations (VE), and Effective Eliminations (EE).
The EC described herein may be defined as the number of erroneous combinations or challenges or rejections that the system presents to a fraudulent user or fraudster. The more removals, the better the security. In the disclosed method, for each iteration, the selection of elements from the source, destination, or intermediate tiers is independent of the corresponding selection of the previous iteration. EC for an authentication key of length L is given as in Equation 28 below.
<maths num="28"><img file="KR102078552B1_D0053.tif" /></maths>
In the existing gesture-based authentication method, there is a limitation that an object selected from the alphabet set χ cannot be repeated. Existing system elimination combinations (PECs) for an authentication key of length L are as shown in Equation 29 below.
<maths num="29"><img file="KR102078552B1_D0054.tif" /></maths>
If an authorized user is authenticating the graphical secure touch screen device 100 while a fraudster or fraudulent user has the opportunity to visually observe the authentication key, the VE described herein may be considered. A fraudulent user may access the touch screen device 100 by providing an observed authentication pattern or gesture. VE gives the total number of background changes to enter the authentication pattern. VE of this method is given by the following Equation 30.
<maths num="30"><img file="KR102078552B1_D0055.tif" /></maths>
Thus, the visual removal is constant and is given by the following equation (31).
<maths num="31"><img file="KR102078552B1_D0056.tif" /></maths>
The EE described herein gives the total number of rejections or difficulties the system presents to a fraudulent user or fraudster because of removal combinations and visual removal.
Since the elimination chances and the visual eliminations are interdependent, the efficient elimination (EE) of the fraudulent user for the proposed system is given by the following Equation (32).
<maths num="32"><img file="KR102078552B1_D0057.tif" /></maths>
On the other hand, the efficient removal of illegal users (PEE) with respect to the existing method is given by the following Equation (33).
<maths num="33"><img file="KR102078552B1_D0058.tif" /></maths>
mathematical analysis
A mathematical analysis of the method and system (derived from equations 28 and 29) shows that the elimination combination (EC) of this method is exponential. The Existing System Elimination Combination (PEC) is factorial for an authentication key of length L. If the fraudulent user or crook knows the length L of the authentication key from equation (28), the proposed system proposes (α × β × γ × δ, ..., η)L removal combinations. That is, a successful scammer is 1:(α × β × γ × δ, ..., η)L, thereby allowing the user to repeatedly select an element in all tiers. Therefore, if the fraudulent user or fraudster does not know the length L of the authentication key, the proposed system has a number of elimination combinations of EC = (α × β × γ × δ, ...η) . That is, a successful illegal user is 1: . The chance for a scammer to succeed is very low. Equation 21 shows that the security of the proposed system is directly dependent on the number of factors in all tiers, such as the number of source tier α, destination tier β, intermediate tiers 1,2,...τ channels γ, δ, η. shows that it is proportional to Therefore, changing these parameters could change the security level exponentially. Therefore, with a small increase in these parameters, a high level of security can be achieved compared to the conventional method.
In Equations 30 and 31, the VE generated in the proposed system is the product of factorial of the number of elements in each tier, although constant in the existing system. By increasing the number of elements in any of the plurality of tiers to a small value, the VE generated is significantly increased compared to the PVE generated by the existing system. Therefore, it can be said that the method of the present invention handles persistent visual attacks by fraudsters better than existing systems. Efficient removal is the product of EC and visual removals.
7 illustrates a computing environment executing an application in accordance with embodiments disclosed herein. As shown, the computing environment includes at least one processing unit equipped with a control unit, an Arithmetic Logic Unit (ALU), a memory, a storage unit, a plurality of network devices, and a plurality of input/output (I/O) devices. includes the device. The processing unit is responsible for processing the instructions of the algorithm. The processing device receives instructions from the control device to execute the processing. In addition, any logical and arithmetic operations involved in the execution of instructions are computed with the aid of the ALU.
The overall computing environment may consist of multiple homogeneous and/or heterogeneous cores, multiple CPUs of different types, specialized media and other accelerators. The processing unit is responsible for processing the instructions of the algorithm. The processing device receives commands from the control device to perform processing. In addition, any logical and arithmetic operations involved in the execution of instructions are computed with the aid of the ALU. Moreover, the plurality of processing devices may be located on a single chip or may be located on multiple chips.
The embodiments disclosed herein may be implemented through at least one software program running on at least one hardware device and executing a network management function to control the elements. The elements shown in FIGS. 1 to 7 include blocks that may be at least one of a hardware device or a combination of a hardware device and a software module.
The above description of specific embodiments will fully represent the general nature of the embodiments herein, so that others, by applying their present knowledge, may readily change and/or modify these specific embodiments for various applications without departing from the general concept. Accordingly, such modifications and variations should be understood within the meaning and scope of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology used herein is for the purpose of description and not limitation. therefore. While the embodiments herein are described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modifications within the spirit and scope of the embodiments as described herein. .
65 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2007531942A | Cites | Japan | Search report |
6 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2806DEL2012 | India | – | |
| 2806DE2012 | India | A |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| OA01109A | African Intellectual Property Organization (OAPI) | A | |
| BR6243280D0 | Brazil | D0 | |
| US2014075552A1 | United States of America | A1 | |
| KR20140035245A | Republic of Korea | A | |
| US8997215B2 | United States of America | B2 | |
| KR102078552B1This record | Republic of Korea | B1 |
7 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-2078552
- Application
- 100093017
Titles5
- Korean
- 멀티-티어, 멀티-클래스 객체들을 사용하는 인증 방법 및 시스템
- English
- METHOD AND SYSTEM FOR AUTHENTIFICATION USING MULTI-TIER, MULTI-CLASS OBJECTS
- English
- Authentication method and system using multi-tier, multi-class objects
- Unlabeled
- 멀티-티어, 멀티-클래스 객체들을 사용하는 인증 방법 및 시스템{METHOD AND SYSTEM FOR AUTHENTIFICATION USING MULTI-TIER, MULTI-CLASS OBJECTS}
- Unlabeled
- METHOD AND SYSTEM FOR AUTHENTIFICATION USING MULTI-TIER, MULTI-CLASS OBJECTS
Classification
- CPC, 2
- G06F3/048
- G06F21/30
- IPC, 2
- G06F21 30
- G06F3 048