Camouflaged Key OTP Generation on Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure payment infrastructure using smart cards and dedicated card readers for generating one-time passcodes (OTPs) is inconvenient, requiring physical presence of hardware and potential for client-server synchronization issues, leading to locked cards and increased complexity.
Innovation Solution
A method to camouflage symmetric keys and securely host OTP generating software on user devices like iPhones and Blackberries, eliminating the need for dedicated hardware by using camouflaged keys and JavaScript within browsers, allowing for network-independent transactions and easy counter synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smart card and dedicated card reader hardware are used to generate OTP, then security is maintained, but user convenience deteriorates due to requiring physical presence of hardware
Solution Approach 1:
The patent replaces the mechanical hardware system (smart card and dedicated card reader) with a software-based OTP generation system that runs on general-purpose mobile devices. The cryptographic functions previously requiring specialized hardware are now implemented through software applications, eliminating the need for physical card insertion and dedicated reading devices while maintaining security through software-based cryptographic operations.
Solution Approach 2:
The patent enables OTP generation functionality to work across multiple platforms and device types (iOS, Android, JavaScript browsers) rather than being restricted to a single hardware platform. The same cryptographic system can operate on smartphones, tablets, or web browsers, providing universal access and eliminating the need for users to carry or insert specific hardware devices.
2Loss of information
If connected card reader is used, then network communication is enabled, but device complexity increases and portability is reduced
Solution Approach 1:
The patent implements a dynamic communication architecture where the system can operate in multiple modes: offline mode using cached cryptographic materials for standalone OTP generation, and online mode for server synchronization and key updates. This dynamic adaptability allows the system to function with or without network connectivity, eliminating the requirement for constant network connection while maintaining security through periodic synchronization.
3Reliability
If client-server synchronization is implemented, then counter synchronization is achieved, but system complexity and potential for locking issues increase
Solution Approach 1:
The patent implements a feedback-based synchronization mechanism where the server monitors and tracks counter values from multiple clients, providing feedback when synchronization is needed. The system automatically detects counter desynchronization and initiates re-synchronization only when necessary, rather than requiring continuous communication. This feedback loop maintains synchronization reliability while minimizing system complexity and avoiding unnecessary locking issues.
Data Source
AI summary
A system and method is provided for generating a one-time passcode (OTP) from a user device. The method includes providing a passcode application and a cardstring defined by a provider account to the user device. The passcode application is configured to generate a passcode configured as a user OTP for the provider account, using the cardstring. The cardstring is defined by at least one key camouflaged with a personal identification number (PIN). The key may be camouflaged by modifying and encrypting the modified key under the PIN. The key may be configured as a symmetric key, a secret, a seed, and a controlled datum. The cardstring may be an EMV cardstring; and the key may be a UDKA or UDKB. The cardstring may be an OTP cardstring, and the key may be a secret configurable to generate one of a HOTP, a TOTP, and a counter-based OTP.


