Dynamic Password Verification Using Diffie-Hellman Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional software-based dynamic password verification systems face security risks due to potential token seed exposure during download and require message exchanges between mobile devices and verification servers, leading to increased user and verification costs.
Innovation Solution
A method and device utilizing the Diffie-Hellman algorithm to generate and verify dynamic passwords, where an initial code is transmitted to a verification server through a web page, allowing the mobile device and server to share a secure key for generating and comparing dynamic passwords without direct message exchange, thus enhancing security and reducing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If token software is downloaded and token seed is shared between mobile device and verification server, then dynamic password verification can be implemented, but security is compromised because hacker can obtain token seed during download
Solution Approach 1:
The patent extracts the token seed from the download process entirely. Instead of downloading token seed to mobile device, the verification server generates dynamic password locally using its own token seed and only transmits the result to the user. This eliminates the security vulnerability of token seed exposure during download.
Solution Approach 2:
The patent introduces an intermediary mechanism where the verification server acts as a mediator between the token software and the user. The server generates dynamic passwords based on token seed and transmits them through web pages, avoiding direct exposure of token seed to mobile devices or users.
2Ease of operation
If mobile device exchanges real-time messages with verification server to obtain token seed, then token seed can be obtained, but user needs to pay for flux and verification costs increase
Solution Approach 1:
The patent applies preliminary action by pre-generating dynamic passwords on the verification server side before user requests. The server maintains token seed securely and pre-computes dynamic passwords, which are then transmitted to users via web pages without requiring real-time message exchange or additional flux payments.
Solution Approach 2:
The verification server provides self-service by autonomously generating and transmitting dynamic passwords to users through web pages. This eliminates the need for bidirectional real-time message exchange between mobile device and server, reducing communication costs and user burden.
3Adaptability or versatility
If mobile device does not support networking, then device can be used offline, but cannot exchange messages with verification server to obtain token seed
Solution Approach 1:
The patent extracts the dependency on real-time networking for token seed acquisition. By generating dynamic passwords directly on the server side and transmitting them through web pages, the system allows mobile devices to obtain dynamic passwords without requiring networking support or message exchange capability.
Solution Approach 2:
The patent uses copying by transmitting dynamic password values from the verification server to the mobile device through web pages. Instead of requiring the device to generate or exchange token seed, the server copies and transmits the ready-made dynamic password, which the user can then input for verification.
Data Source
AI summary
The examples of the present invention provide a method and device for verifying a dynamic password. In the method and device, some algorithm parameters can be exchanged in public by using a DH algorithm, and thus a same key is shared safely between two entities, so as to implement the verification of the dynamic password and further improve the security of identity verification. Moreover, the method and device can be easy to use. Further, by the above technical solution, no message exchange is needed between a mobile device and a verification server, and a user does not need to pay for additional flux, so as to decrease the burden of the user and verification costs.


