Biometric TOTP Wireless Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems lack robust authentication methods that continuously verify user identity and securely encrypt communications, particularly in SOHO environments, where traditional password-based systems are vulnerable to impersonation and device sharing attacks.
Innovation Solution
A method and system that utilize biometric credentials to generate Time-based One Time Passwords (TOTPs) with a random and temporal factor, ensuring only authorized users can establish and maintain encrypted wireless connections by periodically refreshing biometric authentication, using cryptographic functions like hash and HMAC with AES encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional password-based authentication is used, then ease of operation is improved, but security is worsened due to impersonation and device sharing vulnerabilities
Solution Approach 1:
The patent transforms the authentication parameter from static passwords to dynamic biometric data combined with temporal factors (TOTP). Biometric characteristics (fingerprint, face, iris) serve as the basis for generating time-varying authentication credentials, making the authentication parameter both unique to the user and continuously changing, thereby resolving the contradiction between ease of use and security
Solution Approach 2:
The system implements dynamic authentication by continuously generating new TOTP values based on biometric data and time. Instead of relying on static passwords, the authentication credentials are constantly refreshed, ensuring that even if one credential is compromised, it becomes invalid after a short period. This dynamic approach maintains user convenience while significantly improving security
2Reliability
If periodic authentication is implemented, then security is improved by preventing device sharing and robbery, but device complexity is worsened
Solution Approach 1:
The patent makes the biometric data serve multiple functions simultaneously: it acts as the foundation for TOTP generation, provides continuous authentication verification, and enables both initial login and periodic re-authentication. This multi-functionality approach avoids adding separate complex authentication mechanisms while achieving continuous security verification
Solution Approach 2:
The system uses the user's own biometric characteristics as the authentication source, eliminating the need for external authentication servers or complex key management infrastructure. The device itself performs biometric verification and TOTP generation, reducing system complexity while maintaining high security standards
3Reliability
If biometric credentials are used for authentication, then security is improved by unique user identification, but ease of operation is worsened due to biometric collection requirements
Solution Approach 1:
The patent replaces traditional mechanical authentication methods (typing passwords, inserting cards) with biometric sensing systems. Modern biometric sensors (fingerprint scanners, facial recognition cameras, iris detectors) have become integrated into everyday devices, making the collection process seamless and user-friendly despite the underlying complexity
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A method and system for encrypting wireless communications including authentication. The method comprises a) setting configuration parameters for a wireless connection; b) receiving, by a networking device (20), a request for the wireless connection to said communications network from a computing device (10); c) receiving, by the computing device (10), biometric credential information from the user (1); d) generating, by both devices (10, 20) a temporary passcode taking into account biometric information of the user (1), a random string and a temporal factor; e) sending, by the computing device (10), to the networking device (20), a device address thereof and an encrypted data packet containing a given text, said data packet being encrypted with an encryption key corresponding to the temporary passcode generated by the computing device (10); f) checking, by the networking device (20), whether the received device address of the computing device (10) is stored in a register; and g) establishing the wireless connection if all the parameters match.