Dynamic Code Key Device Authentication Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current username/password authentication mechanisms are insecure and inconvenient, as they can be easily compromised, and users often forget or share passwords, leading to unauthorized access and potential harm to legitimate users.
Innovation Solution
A key device authentication method that generates a dynamic code, which is used to create a first verification code, and a user enters a second verification code based on the same mechanism, with the key device comparing the two codes to authorize access, enhancing security by changing verification codes dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If username/password verification is used for authentication, then users can access software applications, but security is compromised and users may forget or share passwords
Solution Approach 1:
A key device is introduced as an intermediary authentication tool between the user and the software application. The key device stores authentication information securely and performs cryptographic operations, acting as a mediator that eliminates the need for users to directly manage passwords while maintaining both convenience and security.
Solution Approach 2:
The patent replaces the mechanical password-entry system with a cryptographic authentication system. Instead of manually entering passwords that can be forgotten or stolen, the system uses cryptographic keys stored in the key device to authenticate users, substituting weak mechanical authentication with stronger cryptographic mechanisms.
2Reliability
If different username/password combinations are set for different software applications, then access control is improved, but it becomes difficult to remember multiple credentials
Solution Approach 1:
The key device is designed as a universal authentication tool that can work with multiple software applications simultaneously. Instead of requiring separate password management for each application, the key device provides a single unified interface that handles authentication across different systems, making the credential management process universal and simplifying user operations.
3Ease of operation
If password is saved at a secure place to prevent forgetting, then memory burden is reduced, but password becomes easily known by others
Solution Approach 1:
The authentication information is extracted from the user's memory and stored securely in the key device. The sensitive password data is taken out of the user's control environment and placed in a dedicated secure storage device that provides both retention and protection, eliminating the need to remember passwords while preventing unauthorized access through secure cryptographic mechanisms.
4Device complexity
If static verification code is used in key device authentication, then authentication process is simple, but security is compromised if code is obtained by hacker
Solution Approach 1:
The verification code system is transformed from static to dynamic. Instead of using fixed verification codes that remain unchanged, the system generates verification codes dynamically based on cryptographic operations involving secret keys. This dynamic generation ensures that even if one code is compromised, subsequent codes remain secure, maintaining both simplicity and security.
Solution Approach 2:
The verification code parameters are changed from fixed values to dynamically generated values based on cryptographic algorithms. The verification code becomes a function of secret keys and other changing parameters, transforming the authentication mechanism from static to parameter-driven dynamic generation, which enhances security while maintaining process simplicity.
Data Source
AI summary
The present invention discloses an authentication method and a key device and relates to the information security field. The authentication method comprises initiating user authentication, generating a dynamic code and then a first verification code on the basis of the dynamic code, and outputting the dynamic code, by a key device; and receiving a second verification code entered by a user via a host, and collating the second verification code with the first verification code, by the key device, and if a match is found, the user access is authorized to the key device; otherwise, the user access is prohibited. The key device comprises a trigger module, a generator module, an output module, a communication module, a collator module, a controller module and a security module. According to the present invention, better security is achieved by reducing the possibility of sensitive information disclosure and misuse in case of password theft for the key device.


