Where is my password

Ragnvald Larsen
2 min readJan 1, 2018

We humans are good at remembering places. With a little help from a map we are able to find back to places we visited decades ago. What if you could authenticate yourself without remembering passwords consisting of meaningless stream of characters?

We already have several biometrically based authentications methods. Fingerprints, iris scans, facial recognition, hand geometry and what have you. More are probably more to come. The jury is out on several of the methods. I will leave this to the experts.

Being a geographer my favourite authentication method will rely on spatially referenced secrets buried deep inside my mind. I want to propose a novel method for authentication. I want to use a map to navigate to a place which has a special meaning for me. It would basically work like this:

  1. I am stating my username (written)
  2. The system then asks me to authenticate by asking me for one or several geographical positions.

The position could be the answer to questions like these:

  • Where did you find your wallet when you lost it in 2012?
  • Where was your father born?
  • What is your favourite place to pick blueberries?
  • Where is the secret rockface outside Trondheim?
  • Where did you spend the night the 17th of november 1995?
  • and so on…

My answer would be made not by entering a string of characters. It would be by answering the question by panning and zooming a map to the particular place. My answer would basically be to place a pin somewhere.

The method could be strengthened by asking for a combination of several places, or by varying the required precision in my answer. The answer (coordinates backoffice) would then be used to establish a string which again is the authentication variable (password).

Here are some combinations of the screen based password:

  • One position
  • Several positions
  • User traces a path

Real position combinations

  • Your authenticated physical position represents the password
  • An other variation of this method could be physical location or relocation in a given pattern. Imagine a document which will only open if you first go for that walk in the park?

Both the above would of course require a positional system which can not be spoofed, but where the position and its reporting is possible to confirm.

Originally published at http://www.mindland.com on January 1, 2018.

--

--

Ragnvald Larsen

Geographer working with GIS, data management and development cooperation. My opinions are my own. https://www.linkedin.com/in/ragnvald/