Beacon-Based TOTP Authentication for Secure Remote Gaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current remote gaming systems face limitations in ensuring secure and regulated gaming communications, particularly in environments where players need to authenticate without being physically present within a defined geographic location, and existing solutions lack robust security measures to prevent unauthorized access.

Innovation Solution

The implementation of a system utilizing Bluetooth-enabled beacons that issue periodically changed wireless passcodes, authenticated through a time-based one-time password (TOTP) algorithm, allows mobile devices to register and maintain connectivity within a regulated venue, ensuring secure gaming participation by continuously updating passcodes and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional remote gaming systems allow players to participate without physical presence, then player accessibility is improved, but security and unauthorized access prevention deteriorate

Engineering Contradiction:
Improveplayer accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by requiring players to physically present themselves at the retail location and authenticate through the beacon system before granting remote gaming access. This preliminary action ensures that only authorized individuals can participate in remote gaming, maintaining security while enabling remote participation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The beacon system acts as an intermediary between the player and the gaming system. The beacon transmits authentication data to the retail terminal, which then verifies credentials and grants or denies access. This intermediary layer adds security verification while still allowing remote gaming participation for authenticated users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If static authentication methods are used for remote gaming, then system complexity is reduced, but security against brute force attacks worsens

Engineering Contradiction:
Improveauthentication system complexityVSAvoidvulnerability to brute force attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system uses dynamic authentication codes that change over time rather than static passwords. The beacon generates time-varying authentication data that must be verified in real-time, making brute force attacks ineffective while adding minimal complexity through the use of standard time-based one-time password algorithms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system employs periodic verification where the beacon continuously transmits authentication data and the system periodically verifies credentials. This periodic action ensures that authentication remains valid only for current time periods, preventing replay attacks and brute force attempts while maintaining manageable system complexity.

Inventive Principle:
Principle #19Periodic action

3Reliability

If continuous authentication monitoring is implemented, then security is improved, but loss of time for authentication updates increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidauthentication update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The beacon system continuously transmits authentication data without requiring periodic interruptions for updates. The continuous transmission ensures that authentication monitoring is maintained without time loss, as the system constantly verifies credentials in real-time rather than requiring discrete update cycles that would interrupt gaming.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10819706B2System, apparatus and method for facilitating remote gaming communications in a venue
Publication Date: 2020.10.27 INTERNATIONAL GAME TECHNOLOGY INC
  • US10819706B2 patent drawing
  • US10819706B2 patent drawing
  • US10819706B2 patent drawing

AI summary

A system, apparatus and method are presented for facilitating remote wager communications using a mobile communications device while the device is within range of one or more beacons within a venue. In various embodiments, one or more beacons broadcast a periodically changing wireless passcode that is received by a mobile communications device and transmitted to a gaming authentication server. The gaming authentication server determines a shared secret code and compares it to the wireless passcode or a portion thereof in order to determine if the mobile communications device can be authenticated for remote gaming within the venue.