Dynamic One-Time Authentication for Service Gate Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods using knowledge-based, possession-based, and bio-based information are inconvenient, vulnerable to security breaches, and expose personal information, as they require fixed and permanent identification details, making them susceptible to leakage and unauthorized access.

Innovation Solution

A method for determining access to a service gate through a network that uses dynamic and one-time identification information, where an authentication server transmits service gate information and an approval request to an authorizer terminal, allowing the authorizer to select approval without inputting a password, and performs authentication based on the selected approval information, ensuring secure and convenient access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods using fixed identification information (ID, password, bio-based info) are used, then authentication can be performed, but security vulnerability increases due to leakage and illegal stealing of identification information

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity vulnerability from identification leakage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transforming static, fixed identification information into dynamic, temporary identification information. The authentication system generates time-limited identification data that changes with each authentication session, preventing reuse by attackers. This dynamic approach resolves the contradiction by maintaining authentication reliability while eliminating security vulnerabilities associated with fixed identification leakage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs disposable, single-use identification information that becomes invalid after one authentication attempt. Each authentication session uses unique, temporary credentials that are discarded afterward, preventing attackers from exploiting leaked identification data. This disposable approach resolves the security vulnerability while maintaining reliable authentication.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If personal identification information is stored in server databases, then authentication can be performed, but risk of personal information leakage increases due to hacking and theft

Engineering Contradiction:
Improveauthentication functionVSAvoidpersonal information leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes personal identification information from server databases entirely. Instead of storing sensitive personal data, the system uses temporary, non-personal identification tokens that cannot be used to identify or track users. This extraction resolves the contradiction by maintaining authentication functionality while eliminating the target for hacking and information theft.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism where temporary identification tokens serve as mediators between users and services. These tokens replace direct personal information storage, allowing authentication to occur without exposing actual personal data. The intermediary tokens can be compromised without affecting user identity security, resolving the contradiction between authentication reliability and information leakage risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If static personal attributes are reflected in identification information, then user identification can be established, but tracking and protection of personal information becomes difficult

Engineering Contradiction:
Improveuser identificationVSAvoidpersonal information tracking vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by replacing static personal attributes with dynamic, session-specific identification data. User identification is maintained through temporary tokens that do not contain personal attributes, preventing tracking while enabling authentication. This resolves the contradiction by maintaining ease of user identification while eliminating tracking vulnerabilities.

Inventive Principle:
Principle #15Dynamics

4Reliability

If conventional authentication requires password input, then service access can be verified, but user convenience decreases due to frequent password input and memory requirements

Engineering Contradiction:
Improveservice access verificationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the system automatically manages identification tokens without requiring user input of passwords. The temporary identification information is generated and managed by the system, eliminating the need for users to remember or repeatedly enter passwords. This resolves the contradiction by maintaining secure verification while dramatically improving user convenience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10764049B2Method for determining approval for access to gate through network, and server and computer-readable recording media using the same
Publication Date: 2020.09.01 AIRCUVE INC
  • US10764049B2 patent drawing
  • US10764049B2 patent drawing
  • US10764049B2 patent drawing

AI summary

A method for determining approval for access to a gate through a network, a server, and computer readable recoding media using the same, and more particularly, to a method for determining approval for access to a gate through a network, a server, and computer readable recoding media using the same so as to determine access to a gate for using a service by allowing an authorizer (user) to determine an approval for a service access at the time of using the service without input of a password or the like. It is possible to use one-time and effective identification only when approval for the access to the corresponding gate is determined at the time of requiring the authority for the approval for the access to the service gate.