Authentication System Using One-Time Key XOR Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication systems are vulnerable to memory hacking and interception of authentication messages, leading to potential fraudulent use of credit information, as they require input of sensitive personal information and rely on insecure methods like SMS or MMS for authentication.
Innovation Solution
A system and method for user authentication using a one-time random key, where a user terminal unit creates an authentication-related value by performing an XOR operation on an authentication key and a security key, preventing fraudulent use even if the authentication key is leaked or stolen, by not requiring input of sensitive information and using secure key operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional user authentication systems use SMS or MMS for authentication, then user authentication can be performed, but the system becomes vulnerable to memory hacking and interception of authentication messages
Solution Approach 1:
The patent extracts sensitive authentication data from the communication channel by using an authentication number that does not require transmission of personal information. The system separates the authentication mechanism from the personal data, allowing verification without exposing sensitive information through SMS or MMS messages.
Solution Approach 2:
The patent introduces an intermediary authentication number that acts as a mediator between the user and the system. This authentication number serves as a temporary credential that enables verification without directly exposing personal information, thereby preventing memory hacking and message interception attacks.
2Reliability
If the system requires input of sensitive personal information for authentication, then user verification can be performed, but credit information may be leaked through memory hacking
Solution Approach 1:
The patent extracts the essential verification function from sensitive personal information by using an authentication number that can verify user identity without requiring transmission or storage of credit card numbers, social security numbers, or other sensitive data.
Solution Approach 2:
The patent employs a disposable authentication number that is valid for a single use and a limited time period. This temporary credential can be used once for verification and then becomes invalid, preventing long-term exposure of sensitive information and reducing the risk of credit information leakage.
3Ease of operation
If the authentication number is sent via mobile message, then user authentication can be completed, but the authentication message may be stolen and illegally used by third parties
Solution Approach 1:
The patent implements a disposable authentication number that expires after a single use or after a short time period. This ensures that even if the message is intercepted, the stolen authentication number cannot be reused for illegal purposes, as it becomes invalid immediately after use or expiration.
Solution Approach 2:
The patent employs periodic authentication numbers that are generated for specific time intervals. Each authentication number is valid only within a predetermined time window, creating a time-based security mechanism that prevents unauthorized use of intercepted messages outside the valid period.
Data Source
AI summary
The present disclosure relates to an electrical circuit system for performing a test. The electrical circuit system includes a first circuitry that transmits a test request signal; a second circuitry that receives a response signal including a test authentication key, generates a test authentication-related value by performing a first Exclusive-OR operation on the test authentication key and a security, and sends the generated test authentication-related value to a third circuitry; and the third circuitry that generates the test authentication key in response to the request for test authentication, send the test authentication key, to the second circuitry, receives the test authentication-related value from the second circuitry, create a verification key by performing a second Exclusive-OR operation on the test authentication-related value and the security key, and generates a test result by verifying whether the verification key is identical to the test authentication key.


