Dynamic One-Time Authentication for Service Gate Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods using knowledge-based, possession-based, and bio-based information are inconvenient, vulnerable to security breaches, and expose personal information, as they require fixed and permanent identification details, making them susceptible to leakage and unauthorized access.
Innovation Solution
A method for determining access to a service gate through a network that uses dynamic and one-time identification information, where an authentication server transmits service gate information and an approval request to an authorizer terminal, allowing the authorizer to select approval without inputting a password, and performs authentication based on the selected approval information, ensuring secure and convenient access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods using fixed identification information (ID, password, bio-based info) are used, then authentication can be performed, but security vulnerability increases due to leakage and illegal stealing of identification information
Solution Approach 1:
The patent applies dynamics by transforming static, fixed identification information into dynamic, temporary identification information. The authentication system generates time-limited identification data that changes with each authentication session, preventing reuse by attackers. This dynamic approach resolves the contradiction by maintaining authentication reliability while eliminating security vulnerabilities associated with fixed identification leakage.
Solution Approach 2:
The patent employs disposable, single-use identification information that becomes invalid after one authentication attempt. Each authentication session uses unique, temporary credentials that are discarded afterward, preventing attackers from exploiting leaked identification data. This disposable approach resolves the security vulnerability while maintaining reliable authentication.
2Reliability
If personal identification information is stored in server databases, then authentication can be performed, but risk of personal information leakage increases due to hacking and theft
Solution Approach 1:
The patent extracts and removes personal identification information from server databases entirely. Instead of storing sensitive personal data, the system uses temporary, non-personal identification tokens that cannot be used to identify or track users. This extraction resolves the contradiction by maintaining authentication functionality while eliminating the target for hacking and information theft.
Solution Approach 2:
The patent introduces an intermediary mechanism where temporary identification tokens serve as mediators between users and services. These tokens replace direct personal information storage, allowing authentication to occur without exposing actual personal data. The intermediary tokens can be compromised without affecting user identity security, resolving the contradiction between authentication reliability and information leakage risk.
3Ease of operation
If static personal attributes are reflected in identification information, then user identification can be established, but tracking and protection of personal information becomes difficult
Solution Approach 1:
The patent applies dynamics by replacing static personal attributes with dynamic, session-specific identification data. User identification is maintained through temporary tokens that do not contain personal attributes, preventing tracking while enabling authentication. This resolves the contradiction by maintaining ease of user identification while eliminating tracking vulnerabilities.
4Reliability
If conventional authentication requires password input, then service access can be verified, but user convenience decreases due to frequent password input and memory requirements
Solution Approach 1:
The patent implements self-service authentication where the system automatically manages identification tokens without requiring user input of passwords. The temporary identification information is generated and managed by the system, eliminating the need for users to remember or repeatedly enter passwords. This resolves the contradiction by maintaining secure verification while dramatically improving user convenience.
Data Source
AI summary
A method for determining approval for access to a gate through a network, a server, and computer readable recoding media using the same, and more particularly, to a method for determining approval for access to a gate through a network, a server, and computer readable recoding media using the same so as to determine access to a gate for using a service by allowing an authorizer (user) to determine an approval for a service access at the time of using the service without input of a password or the like. It is possible to use one-time and effective identification only when approval for the access to the corresponding gate is determined at the time of requiring the authority for the approval for the access to the service gate.


