Authentication Key Using 3D Barcode and RFID for Secure Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multifactor authentication methods, such as 2FA and biometric systems, are vulnerable to hacking and data breaches, particularly when relying on SMS, USB devices, and shared secrets, which can lead to unauthorized access to digital and physical assets.
Innovation Solution
A Unique Identity and Authentication Key (UIAK) system that combines a physical key with a mobile device, using a barcode or RFID tag with three-dimensional elements and machine-readable data, providing a secure authentication process through a smartphone app, eliminating the need for passwords and reducing the risk of data breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional password-based authentication is used, then ease of operation is improved, but security is worsened due to vulnerability to hacking and password leaks
Solution Approach 1:
The authentication system is segmented into multiple independent factors (knowledge factor, possession factor, biometric factor) that must all be satisfied simultaneously. This segmentation prevents a single point of failure and requires attackers to compromise multiple separate security layers rather than a single password.
Solution Approach 2:
The authentication mechanism uses a composite approach combining multiple authentication factors (password/PIN, physical token, biometric data) into a unified authentication system. This composite structure leverages the strengths of each factor while mitigating their individual weaknesses.
2Reliability
If SMS-based 2FA is implemented, then security is improved, but reliability is worsened due to vulnerability to SIM swapping and interception attacks
Solution Approach 1:
A physical authentication token serves as an intermediary device between the user and the authentication server. This token generates and transmits one-time passwords through secure channels (NFC, Bluetooth, USB) rather than relying on SMS, thereby eliminating vulnerabilities associated with cellular network interception and SIM swapping attacks.
Solution Approach 2:
The system replaces the SMS-based authentication mechanism with a direct physical connection mechanism using authentication tokens. This substitution eliminates the need for cellular network infrastructure and replaces it with localized secure communication protocols that are resistant to remote interception.
3Reliability
If USB authentication tokens are used, then security is improved, but device complexity is worsened due to requiring additional hardware
Solution Approach 1:
The authentication token is designed with multi-functionality, serving as both a security credential and a portable storage device. It can authenticate across multiple platforms and devices through different connection methods (NFC, Bluetooth, USB), eliminating the need for separate authentication solutions for different devices and reducing overall system complexity.
Solution Approach 2:
The authentication functionality is merged with a portable physical token that users already carry daily. This combines the authentication mechanism with a familiar object, reducing the perceived complexity by integrating security into an existing part of the user's routine rather than introducing entirely new hardware.
4Ease of operation
If biometric authentication is implemented, then ease of operation is improved, but security is worsened due to inability to revoke compromised biometric data
Solution Approach 1:
The authentication system segments biometric verification as one factor among multiple required factors, rather than using it as the sole authentication mechanism. This segmentation means that even if biometric data is compromised, the attacker must also compromise the other authentication factors (password, physical token) to gain access.
Solution Approach 2:
The system applies different security characteristics to different authentication factors. Biometric authentication provides convenience for daily use, while the physical token and password provide revocable security layers. This local quality assignment optimizes both ease of operation and security without requiring biometric data to serve all security functions.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security by creating an impenetrable lock system, making it difficult to clone the key and preventing viruses from infecting the authentication process, thus protecting digital assets from cyber attacks and unauthorized access.
Implementation Method 1
The authentication item includes an RFID tag with an identification code and authentication information
Data Source
AI summary
Authorized access to a digital asset is obtained by associating an authentication tag with a physical object accessible to a user, by configuring the tag with a first dataset comprised of a random distribution of three-dimensional elements and with a second dataset comprised of machine-readable data elements, and by authorizing a mobile device to scan the elements. The first and second datasets together comprise an authentication key that uniquely identifies the object and, in turn, the user. The authentication key is scanned by a device in response to a prompt from the digital asset to obtain scanned key data. Predetermined key data and a device identifier indicative of the authorized device are stored in a database. Access to the digital asset is allowed when the scanned key data matches the stored predetermined key data, and when the device scanning the data is authorized.


