Automated One-Time Passcode Authentication via Token Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

One-time passcode systems for user authentication are complex, cumbersome, and prone to errors, making them inefficient for secure access to sensitive information in financial and healthcare applications.

Innovation Solution

A one-time passcode authentication system comprising an application server, authentication server, and access device with an authentication engine that uses a token-based approach, including encryption and biometric authentication, to simplify and secure user access by automating the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one-time passcode systems are used to ensure security, then data security is improved, but device complexity and ease of operation deteriorate due to multiple manual steps

Engineering Contradiction:
Improvedata securityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automated authentication where the access device automatically receives one-time passcodes from the authentication server and initiates access requests without requiring manual user input for each step. The device performs encryption, decryption, and token extraction automatically, allowing the system to serve itself rather than requiring continuous user intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication server pre-generates one-time passcodes and sends them to the access device before authentication is needed. The access device stores these passcodes and automatically uses them when authentication requests are initiated, performing preliminary preparation of authentication credentials to eliminate manual steps during the actual authentication process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional one-time passcode systems are used to ensure security, then data security is improved, but productivity deteriorates due to arduous authentication process

Engineering Contradiction:
Improvedata securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The automated authentication system performs all authentication steps automatically including receiving passcodes, decrypting them, extracting tokens, and initiating access requests without requiring user manual input for each operation. This self-service automation dramatically improves authentication efficiency while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical authentication steps (typing passcodes, clicking buttons, navigating menus) with automated electronic processes. The access device automatically performs decryption, token extraction, and request initiation through software-based operations, eliminating the need for manual user actions and significantly improving authentication speed and efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If traditional one-time passcode systems are used to ensure security, then data security is improved, but device complexity increases due to multiple authentication steps

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple separate authentication operations into a single integrated automated process. The access device combines receiving passcodes, decrypting them, extracting tokens, and initiating access requests into one unified automated workflow, reducing the apparent complexity for users while maintaining all necessary security steps.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server acts as an intermediary that handles the complexity of passcode generation, encryption, and distribution. The access device receives pre-processed authentication data and automatically completes the remaining steps, distributing the complexity burden across system components rather than concentrating it all in user-facing operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If traditional one-time passcode systems are used to ensure security, then data security is improved, but loss of time increases due to manual entry requirements

Engineering Contradiction:
Improvedata securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The automated system performs all authentication operations without requiring user manual input for each step. The access device automatically receives passcodes, decrypts them, extracts tokens, and initiates access requests, eliminating the time users would spend on manual entry and significantly reducing total authentication time while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication server pre-generates and sends one-time passcodes to the access device before authentication is needed. The device stores these passcodes and automatically uses them when authentication is initiated, performing preliminary preparation to eliminate time-consuming manual steps during the actual authentication process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10432617B2One time passcode
Publication Date: 2019.10.01 MASTERCARD INT INC
  • US10432617B2 patent drawing
  • US10432617B2 patent drawing
  • US10432617B2 patent drawing

AI summary

A one-time passcode authentication system includes an application server, an authentication server, and an access device, wherein the access includes an authentication engine configured to receive an authentication request from the authentication server and automatically, or in response to a single user input, initiate an access request to the application server, wherein the access request includes a token extracted from the authentication request, and the application server is configured to receive the access request, query the authentication server to authenticate the token, and enable access to an application if the token is authenticated.