Cognitive One-Time Password Generation via Third-Party Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional one-time password (OTP) systems are vulnerable to mobile malware and burdensome for users to enter long, randomly-generated codes, as they require a two-step process of receiving and typing the OTP, which can be intercepted and is difficult to manage.
Innovation Solution
A cognitive one-time password generation method that generates a question requiring a cognitive answer, sent via a third-party platform, allowing users to input the answer for secure service access, thereby eliminating the need for retyping a long alphanumeric password and enhancing security with a three-step authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional OTP is sent via SMS or email, then the authentication process can be implemented, but the OTP can be intercepted by mobile malware and the user burden increases
Solution Approach 1:
The patent introduces a question as an intermediary element between the system and the user. Instead of directly sending the OTP code, the system sends a question that the user must answer. This intermediary question format prevents malware from directly intercepting the authentication credential while still providing a secure verification mechanism.
Solution Approach 2:
The patent changes the parameter format of the authentication credential from a randomly generated numeric code (6-12 digits) to a cognitive answer based on personal information. This parameter transformation makes the credential more resistant to automated interception and parsing by malware, while also making it more memorable and easier for users to input.
2Reliability
If long randomly-generated OTP codes are used, then security is improved, but the difficulty for users to enter correctly increases
Solution Approach 1:
The patent transforms the authentication parameter from a random alphanumeric string to a cognitively-derived answer based on personal information. This changes the nature of the credential from something that must be memorized and re-typed to something that can be naturally recalled and entered, significantly reducing user burden while maintaining security.
Solution Approach 2:
The patent creates a new form of authentication credential that is ephemeral (valid for one use only) but cognitively accessible. Unlike persistent passwords that users must manage long-term, this one-time answer can be quickly recalled and entered, making the authentication process more efficient while maintaining strong security properties.
3Device complexity
If two-step authentication process is used, then the implementation is simple, but the security against malware interception is reduced
Solution Approach 1:
The patent inserts a question format as an intermediary layer in the authentication flow. This intermediary structure prevents malware from directly capturing the authentication credential in transit, as the credential is now embedded within a question-answer format rather than being a standalone code that can be easily parsed and intercepted.
Solution Approach 2:
Instead of sending the authentication credential directly to the user and having them re-enter it (the conventional approach), the patent inverts the process by sending a question and having the user provide the answer. This inversion fundamentally changes the authentication flow in a way that prevents traditional interception methods while maintaining the two-step verification structure.
Data Source
AI summary
A cognitive one-time password generation method, system, and computer program product, include sending a cognitive one-time password question to a user via a third-party platform and granting access to a secured service when the user inputs into the secured service a cognitive one-time password as a correct answer to the cognitive one-time password question where the user receives the cognitive one-time password question, independently from the secured service via the third-party platform, to formulate the correct answer to input into the secured service.


