Dynamic Authentication via Rotating 3D Object Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods using mobile devices are vulnerable to fraud and unauthorized access due to the use of static authentication IDs and data, which can be easily copied or intercepted, leading to security risks.
Innovation Solution
A two-way authentication method utilizing a mobile device to scan a 3D rotating object with dynamic encoded data, where the rotation speed and direction change based on time and location, ensuring that credentials are confirmed through three-way encryption involving the user's mobile device, merchant computing device, and authentication server, with data expiring shortly to prevent replication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static authentication IDs and data are used in mobile devices, then authentication process is simple and easy to implement, but security is compromised as data can be easily copied or intercepted
Solution Approach 1:
The patent transforms static authentication data into dynamic authentication credentials. The mobile device generates time-varying authentication data that changes continuously, making it impossible to copy or intercept effectively. This dynamic approach maintains ease of operation while dramatically improving security, as the authentication data is valid only for specific time windows and cannot be reused.
Solution Approach 2:
The patent changes the temporal parameter of authentication data from static to dynamic. By introducing time-based validity and continuous change in authentication credentials, the system prevents copying and interception while maintaining user-friendly authentication processes. The authentication data parameters (time, sequence number) are continuously modified to ensure security.
2Reliability
If authentication data is made dynamic and time-sensitive, then security is improved, but system complexity increases due to multiple encryption layers and validation requirements
Solution Approach 1:
The patent segments the authentication system into three distinct components: the mobile device that generates authentication data, the authentication server that validates credentials, and the communication protocol that transfers data. This segmentation allows each component to handle specific security functions independently, managing complexity through modular design while maintaining high security standards.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the user and the protected resource. This intermediary handles the complex validation of time-sensitive credentials, managing encryption and decryption operations, and verifying authentication data without requiring the mobile device or target system to implement complex security protocols themselves.
3Ease of operation
If authentication credentials are valid for extended periods, then user convenience is improved, but vulnerability to fraud and unauthorized access increases
Solution Approach 1:
The patent implements periodic regeneration of authentication credentials with short validity periods. Instead of long-lived static credentials, the system continuously generates new authentication data at regular intervals, with each credential valid only for a brief window. This periodic action maintains user convenience through automated generation while preventing fraud by limiting the time window for unauthorized use.
Solution Approach 2:
The patent treats authentication credentials as disposable, short-lived objects rather than permanent assets. Each authentication credential is designed to be used once or within a very short time frame, then discarded and replaced. This approach prevents the value accumulation that makes long-lived credentials vulnerable to fraud, while maintaining convenience through automated credential management.
Data Source
AI summary
A two way authentication method, including receiving by an authentication server first encrypted data from a merchant computing device, receiving by the authentication server second encrypted data from a customer computing device, determining by the authentication server if the first encrypted data matches the second encrypted data, if the first encrypted data matches the second encrypted data, authenticating the customer computing device, if the first encrypted data does not matches the second encrypted data, not authenticating the customer computing device.


