Dynamic Password Authentication via Device Identification Code
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional dynamic password authentication methods are vulnerable to cellular phone viruses, incur additional costs for ISPs due to malware-induced short message expenses, suffer from non-real-time and unreliable OTP transmission, are susceptible to phishing attacks, and can be tampered with through caller ID manipulation, leading to security breaches and increased fraudulent activities.
Innovation Solution
The method involves generating a dynamic password on the user's communication device and transmitting it via short message, with the user's identification code also being verified, eliminating reliance on traditional short message delivery and enhancing security by requiring matching of both the dynamic password and identification code, thus reducing ISP costs and improving authentication reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional dynamic password authentication is used via short message, then authentication functionality is provided, but security is compromised due to vulnerabilities to cellular phone viruses and phishing attacks
Solution Approach 1:
The authentication system is segmented into two independent verification components: device identification code verification and dynamic password verification. Both components must be satisfied simultaneously for authentication to succeed, thereby isolating the security risks of each component and preventing single-point failures due to viruses or phishing attacks
Solution Approach 2:
The authentication mechanism transitions from a single-dimensional password verification to a two-dimensional verification space by incorporating both device identification (hardware level) and dynamic password (software level). This dimensional expansion creates a more robust security surface that is harder to compromise through traditional vectors
2Reliability
If dynamic password is transmitted via short message from authentication server, then authentication is enabled, but additional costs are incurred for ISPs due to malware-induced short message expenses
Solution Approach 1:
The traditional authentication flow is inverted: instead of the server sending the dynamic password to the user for verification, the user's device generates the dynamic password locally and sends it back to the server for verification. This reversal eliminates the need for server-to-user message transmission, thereby eliminating ISP costs associated with authentication messages
3Reliability
If OTP transmission is performed through traditional short message system, then authentication can be conducted, but transmission is non-real-time and unreliable
Solution Approach 1:
The mechanical short message transmission system is replaced with an electronic data processing system where the user's communication device generates and transmits the dynamic password through data networks. This substitution enables real-time generation and transmission of authentication codes, eliminating the delays and reliability issues inherent in traditional SMS-based OTP systems
4Ease of operation
If only dynamic password matching is performed for authentication, then authentication process is simple, but security level is insufficient against sophisticated attacks
Solution Approach 1:
Two separate verification mechanisms—device identification code verification and dynamic password verification—are merged into a unified authentication process. The system combines hardware-based device identification with software-based dynamic password verification, creating a multi-layered security approach that maintains operational simplicity while significantly enhancing security against sophisticated attacks
Data Source
AI summary
A method of identity authentication and fraudulent phone call verification uses an identification code of a communication device and a dynamic password. The “dynamic password” is directly sent to an Internet user via a dynamic web-page of a specific website instead of by means of a traditional telephone short message. Thus, the “dynamic password” cannot be copied from the spyware infected communication device of the Internet user. Furthermore, even if the “dynamic password” is intercepted or otherwise discovered by a hacker or intruder, authentication is still secure because the dynamic password must be sent back to the specific website via a short message or the like from the same communication device having the corresponding identification code that was initially input by the Internet user in order to generate the dynamic password.


