Biometric-Integrated One-Time Password Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current one-time password (OTP) authentication systems are vulnerable to unauthorized access, as they do not provide sufficient user characterization, leading to potential account takeovers and security breaches.

Innovation Solution

Integration of biometric data into OTP systems using neural network machine learning to generate biometric-integrated OTPs, which require users to provide both OTPs and biometric inputs, such as voice, gestures, or facial recognition, to enhance authentication security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one-time password authentication systems are used, then authentication speed and ease of operation are maintained, but security reliability deteriorates due to vulnerability to unauthorized access and account takeovers

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines traditional OTP authentication with biometric verification (fingerprint, facial recognition, voice) into a unified authentication system. The biometric verification module integrates with the OTP generation and validation processes, creating a multi-factor authentication mechanism that maintains ease of use while significantly improving security reliability by requiring both the OTP and biometric confirmation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a biometric verification module as an intermediary component between the OTP generation and validation processes. This intermediary layer performs additional verification using biometric data without disrupting the core OTP flow, thereby enhancing security while maintaining the simplicity and speed of traditional OTP authentication through modular integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric-integrated OTP systems are implemented, then authentication security and user characterization are improved, but authentication time and processing complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing and storing biometric data templates before authentication is needed. The biometric verification module has pre-established reference data for authorized users, enabling rapid comparison during actual authentication without requiring real-time biometric capture and processing from scratch, thus reducing authentication time while maintaining enhanced security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses digital copies of biometric data (templates, hashes, or encoded representations) rather than processing raw biometric inputs in real-time during authentication. By working with pre-processed copies of biometric data, the system achieves fast and accurate verification while minimizing the time required for authentication operations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11115406B2System for security analysis and authentication
Publication Date: 2021.09.07 BANK OF AMERICA CORP
  • US11115406B2 patent drawing
  • US11115406B2 patent drawing
  • US11115406B2 patent drawing

AI summary

Embodiments of the present invention provide a system for security analysis and authentication. The system can analyze, using a deep neural network machine learning system, historical one time password (“OTP”) information, historical information, historical malfeasance information, and historical information for a plurality of users to determine available OTPs. When an authentication request is received, one of the available OTPs is randomly or variedly selected and the user is prompted to provide information along with a response for the OTP. The received information is analyzed against the historical information and an OTP signature is generated for the user. This OTP signature is used to determine whether the user is authenticated for one or more authentication elements.