Cognitive One-Time Password Generation via Third-Party Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional one-time password (OTP) systems are vulnerable to mobile malware and burdensome for users to enter long, randomly-generated codes, as they require a two-step process of receiving and typing the OTP, which can be intercepted and is difficult to manage.

Innovation Solution

A cognitive one-time password generation method that generates a question requiring a cognitive answer, sent via a third-party platform, allowing users to input the answer for secure service access, thereby eliminating the need for retyping a long alphanumeric password and enhancing security with a three-step authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional OTP is sent via SMS or email, then the authentication process can be implemented, but the OTP can be intercepted by mobile malware and the user burden increases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a question as an intermediary element between the system and the user. Instead of directly sending the OTP code, the system sends a question that the user must answer. This intermediary question format prevents malware from directly intercepting the authentication credential while still providing a secure verification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter format of the authentication credential from a randomly generated numeric code (6-12 digits) to a cognitive answer based on personal information. This parameter transformation makes the credential more resistant to automated interception and parsing by malware, while also making it more memorable and easier for users to input.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If long randomly-generated OTP codes are used, then security is improved, but the difficulty for users to enter correctly increases

Engineering Contradiction:
Improveauthentication securityVSAvoidentry difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent transforms the authentication parameter from a random alphanumeric string to a cognitively-derived answer based on personal information. This changes the nature of the credential from something that must be memorized and re-typed to something that can be naturally recalled and entered, significantly reducing user burden while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a new form of authentication credential that is ephemeral (valid for one use only) but cognitively accessible. Unlike persistent passwords that users must manage long-term, this one-time answer can be quickly recalled and entered, making the authentication process more efficient while maintaining strong security properties.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If two-step authentication process is used, then the implementation is simple, but the security against malware interception is reduced

Engineering Contradiction:
Improveprocess simplicityVSAvoidmalware interception risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent inserts a question format as an intermediary layer in the authentication flow. This intermediary structure prevents malware from directly capturing the authentication credential in transit, as the credential is now embedded within a question-answer format rather than being a standalone code that can be easily parsed and intercepted.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of sending the authentication credential directly to the user and having them re-enter it (the conventional approach), the patent inverts the process by sending a question and having the user provide the answer. This inversion fundamentally changes the authentication flow in a way that prevents traditional interception methods while maintaining the two-step verification structure.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS10904242B2System, method and computer program product for generating a cognitive one-time password
Publication Date: 2021.01.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10904242B2 patent drawing
  • US10904242B2 patent drawing
  • US10904242B2 patent drawing

AI summary

A cognitive one-time password generation method, system, and computer program product, include sending a cognitive one-time password question to a user via a third-party platform and granting access to a secured service when the user inputs into the secured service a cognitive one-time password as a correct answer to the cognitive one-time password question where the user receives the cognitive one-time password question, independently from the secured service via the third-party platform, to formulate the correct answer to input into the secured service.