Dynamic Password Authentication via Device Identification Code

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional dynamic password authentication methods are vulnerable to cellular phone viruses, incur additional costs for ISPs due to malware-induced short message expenses, suffer from non-real-time and unreliable OTP transmission, are susceptible to phishing attacks, and can be tampered with through caller ID manipulation, leading to security breaches and increased fraudulent activities.

Innovation Solution

The method involves generating a dynamic password on the user's communication device and transmitting it via short message, with the user's identification code also being verified, eliminating reliance on traditional short message delivery and enhancing security by requiring matching of both the dynamic password and identification code, thus reducing ISP costs and improving authentication reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional dynamic password authentication is used via short message, then authentication functionality is provided, but security is compromised due to vulnerabilities to cellular phone viruses and phishing attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to viruses and phishing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into two independent verification components: device identification code verification and dynamic password verification. Both components must be satisfied simultaneously for authentication to succeed, thereby isolating the security risks of each component and preventing single-point failures due to viruses or phishing attacks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication mechanism transitions from a single-dimensional password verification to a two-dimensional verification space by incorporating both device identification (hardware level) and dynamic password (software level). This dimensional expansion creates a more robust security surface that is harder to compromise through traditional vectors

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If dynamic password is transmitted via short message from authentication server, then authentication is enabled, but additional costs are incurred for ISPs due to malware-induced short message expenses

Engineering Contradiction:
Improveauthentication functionalityVSAvoidISP costs for short messages
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The traditional authentication flow is inverted: instead of the server sending the dynamic password to the user for verification, the user's device generates the dynamic password locally and sends it back to the server for verification. This reversal eliminates the need for server-to-user message transmission, thereby eliminating ISP costs associated with authentication messages

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If OTP transmission is performed through traditional short message system, then authentication can be conducted, but transmission is non-real-time and unreliable

Engineering Contradiction:
Improveauthentication capabilityVSAvoidtransmission real-time performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The mechanical short message transmission system is replaced with an electronic data processing system where the user's communication device generates and transmits the dynamic password through data networks. This substitution enables real-time generation and transmission of authentication codes, eliminating the delays and reliability issues inherent in traditional SMS-based OTP systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If only dynamic password matching is performed for authentication, then authentication process is simple, but security level is insufficient against sophisticated attacks

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Two separate verification mechanisms—device identification code verification and dynamic password verification—are merged into a unified authentication process. The system combines hardware-based device identification with software-based dynamic password verification, creating a multi-layered security approach that maintains operational simplicity while significantly enhancing security against sophisticated attacks

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8549594B2Method of identity authentication and fraudulent phone call verification that utilizes an identification code of a communication device and a dynamic password
Publication Date: 2013.10.01 LIN CHUNG YU
  • US8549594B2 patent drawing
  • US8549594B2 patent drawing
  • US8549594B2 patent drawing

AI summary

A method of identity authentication and fraudulent phone call verification uses an identification code of a communication device and a dynamic password. The “dynamic password” is directly sent to an Internet user via a dynamic web-page of a specific website instead of by means of a traditional telephone short message. Thus, the “dynamic password” cannot be copied from the spyware infected communication device of the Internet user. Furthermore, even if the “dynamic password” is intercepted or otherwise discovered by a hacker or intruder, authentication is still secure because the dynamic password must be sent back to the specific website via a short message or the like from the same communication device having the corresponding identification code that was initially input by the Internet user in order to generate the dynamic password.