Agile OTP Generation via Dynamic Variance Techniques

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems, such as those using RSA SecurID authentication tokens, face challenges in providing robust privacy and authentication due to vulnerabilities in seed management and algorithm implementations, making them susceptible to attacks and replication.

Innovation Solution

The introduction of variance techniques in one-time passcode (OTP) generation, including randomized start times, device-specific bindings, and multiple algorithm implementations, complicates attacks by varying the data collection and management requirements for attackers, binding OTPs to specific devices, and modifying provisioning processes to include unique identifiers and time functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional seed-based OTP generation is used, then authentication functionality is provided, but the system is vulnerable to attacks and replication due to seed management weaknesses

Engineering Contradiction:
Improveauthentication securityVSAvoidsusceptibility to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameters of OTP generation by introducing multiple variance techniques (time-based, counter-based, event-based) and allowing dynamic selection between them. This transforms the static seed-based approach into a dynamic multi-parameter system where the generation method can change based on conditions, making replication and attacks significantly more difficult.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system transitions from a static OTP generation approach to a dynamic one where the variance technique can change over time and based on events. The OTP generator can switch between different generation methods (time-based, counter-based, event-based) and can respond to security events, creating a living system that adapts to threats rather than a fixed vulnerable target.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple variance techniques are implemented in OTP generation, then security against attacks is enhanced, but the device complexity increases

Engineering Contradiction:
Improveresistance to replicationVSAvoidgeneration algorithm complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the OTP generation function into multiple independent variance techniques (time-based, counter-based, event-based) that can be selected and combined. Each technique is a separate module that can operate independently, allowing the system to achieve high security through composition rather than requiring one monolithic complex algorithm.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The OTP generator is designed as a universal system capable of performing multiple generation functions through a single device. By incorporating multiple variance techniques and allowing dynamic selection, one device can fulfill multiple security requirements and adapt to different authentication scenarios, reducing the need for multiple specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9306942B1Agile OTP generation
Publication Date: 2016.04.05 RSA SECURITY INC
  • US9306942B1 patent drawing
  • US9306942B1 patent drawing
  • US9306942B1 patent drawing

AI summary

A method, system, and apparatus for agile generation of one time passcodes (OTPs) in a security environment, the security environment having a token generator comprising a token generator algorithm and a validator, the method comprising generating a OTP at the token generator according to a variance technique; wherein the variance technique is selected from a set of variance techniques, receiving the OTP at a validator, determining, at the validator, the variance technique used by the token generator to generate the OTP, and determining whether to validate the OTP based on the OTP and variance technique.