Authentication via Complex Picture Passwords    

Provides a robust, usable, inexpensive and scalable multi-factor authentication solution.


The technology uses the fact that the human brain is extremely good at recognizing faces that it has seen before. We created a user interface that used this universal and intuitive human skill to function as a “something you know” factor for user authentication purposes. It solves many of the problems that traditional password systems create. For example: it is very hard to forget, difficult to write the faces down, difficult to tell another person your faces. It is also inexpensive compared to hardware authentication based systems such as biometrics and tokens.

This technology introduces an additional, optional authentication factor that perfectly complements this invention; effectively creating a complete multi- factor authentication system for use with web applications.

It is generally recognized that any authentication factor will be susceptible to certain types of attack or misuse. However, by combining authentication factors it is possible to mitigate vulnerabilities while actually increasing usability.

When combining authentication technologies at a single point of entry to a web service, it is important to ensure that no clues are given at each authentication step as to whether the user provided a correct or incorrect credential. For example, regardless of whether users enter the correct or incorrect face combination authentication, they should be prompted for the password and only after entering both credentials will they be informed whether the authentication succeeded or failed (and not informed which part failed). If this approach is taken, then the combined entropy of the authentication factors is the result of multiplying the entropy of the two individual factors.
In this manner, a number of “lightweight” authentication technologies can be combined to create a stronger, more usable overall authentication system than a single traditional authentication factor alone. In this context, the term “lightweight” may have a number of meanings:

• Inexpensive;
• Relatively low security when used alone;
• Easy for the user to comprehend and use.

Combining face combination authentication and password authentication mitigates a number of issues associated with using a password alone (this includes dictionary attacks and the predictability of user chosen passwords). This combined “something you know” also scores highly for usability because it eliminates the need for enforced password complexity rules and password change policy which have been generally shown to be counterproductive (for example, users are forced to cheat and write down their passwords and PINs).

Presenting users with the a combination of faces before prompting them for their password also provides the opportunity for the user to judge the authenticity of the web service itself before they can disclose either their face combination credential or their password. This is a useful defense against “phishing” and other forms of social engineering attack. Once users are familiar with logging on with a face password and then a password, they are likely to be suspicious if a fake site only requests their password. And in order to present a coherent face password challenge for any user, a fake site would need to contact the genuine site in order to retrieve the appropriate set of faces for that user. This query would provide an opportunity for the genuine site to detect and prevent the fake site from operating.

Primary Application of the Technology

Any service or web site that requires a user to log into their account.

Patent Summary

