Dynamic Key Updating Mechanism for Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Dynamic tokens face security risks due to constant keys that can be leaked, leading to unauthorized access if compromised.
Innovation Solution
A key updating method and system that dynamically generates and updates keys in both the dynamic token and the back-end authentication system, using authentication processes to ensure new keys are synchronized and replace original keys, thereby enhancing security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a constant key is used in the dynamic token, then the system is simple and easy to implement, but the security is compromised when the key is leaked
Solution Approach 1:
The patent applies the dynamics principle by transitioning from a static constant key to a dynamic key that changes over time. The key updating mechanism allows the authentication key to be periodically renewed through authentication processes, ensuring that even if a key is leaked, subsequent keys will be different, thereby maintaining security while keeping the system implementable
Solution Approach 2:
The patent changes the parameter of the key from a fixed value to a variable value that undergoes updates. By implementing key updating mechanisms where the key parameter changes based on authentication results and time, the system maintains simplicity in key management while significantly improving security against key leakage
2Device complexity
If a constant key is used in the dynamic token, then the system structure is simple, but the flexibility and adaptability are reduced
Solution Approach 1:
The system introduces dynamic key updating capability while maintaining a relatively simple overall structure. The key updating mechanism provides flexibility in adapting to security requirements and key leakage scenarios without fundamentally redesigning the entire authentication system, thus balancing structural simplicity with operational flexibility
Solution Approach 2:
The patent implements preliminary key updating mechanisms that prepare the system for future security requirements. By establishing key updating protocols in advance, the system gains flexibility and adaptability for handling key leakage and security enhancements without requiring complex real-time reconfiguration
3Reliability
If the key is updated dynamically, then the security is improved by avoiding key leakage risks, but the system complexity increases
Solution Approach 1:
The patent employs feedback mechanisms where authentication results feed back into the key updating process. The system monitors authentication status and automatically triggers key updates based on feedback from authentication failures or periodic schedules, improving security through automated feedback-driven key rotation without requiring overly complex manual intervention
Solution Approach 2:
The key updating mechanism is designed to be self-service oriented, where the system automatically manages key updates based on predefined conditions and authentication results. This self-service approach improves security through automated key rotation while minimizing the complexity of manual key management and system configuration
Data Source
AI summary
A key updating method and system are provided. In the method, (1) a back-end authentication system receives a current dynamic password generated by a dynamic token and authenticates the current dynamic password, and if the authentication succeeds, generates key updating information and goes to (2); (2), the back-end authentication system generates a first updating key according to the key updating information and a first initial key stored therein and copies the first updating key to a buffer of the first initial key; the dynamic token obtains and authenticates the key updating information, and if the authentication succeeds, generates a second updating key according to the key updating information and a second initial key stored in the dynamic token and copies the second updating key to a buffer of the second initial key; or if authentication fails, quits the key updating. The solution avoids risk incurred by accidental key leakage.


