Dynamic Password Authentication With Expiring Login Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password generation and distribution systems require users to remember and manage multiple passwords, lacking mechanisms for seamless and secure dynamic password generation and authentication without direct user involvement.

Innovation Solution

A system generates unique, expiring passwords using dynamic secret parameters and algorithms, transmitted to both the user and the business, allowing secure authentication without requiring users to remember or manually input passwords, with additional security via NFC authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually manage and remember multiple passwords, then authentication security is maintained, but user convenience and ease of operation deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automatic password generation and submission without user intervention. The password manager autonomously creates passwords using cryptographic algorithms, transmits them to the target system, and handles authentication automatically, freeing users from manual password management while maintaining security through algorithmic generation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A password manager service acts as an intermediary between the user and the target authentication system. It generates passwords on behalf of the user, transmits them securely to the target system, and receives authentication responses, thereby eliminating the need for users to directly handle or remember passwords while ensuring secure authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If static passwords are used for authentication, then ease of operation is improved, but security against replay attacks and unauthorized access deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity against replay attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system transitions from static password authentication to dynamic password generation. Each password is generated on-demand using cryptographic algorithms that incorporate changing parameters such as timestamps or random values, ensuring that each authentication attempt uses a unique password that cannot be reused or replayed by attackers

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The password generation process changes parameters dynamically by incorporating time-based factors, random seeds, or counter values into the cryptographic algorithm. This ensures that passwords evolve over time and are unique to each authentication event, preventing replay attacks while maintaining automated authentication simplicity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12493683B1Means and methods of dynamically generating and authenticating passwords
Publication Date: 2025.12.09 LIGHTNING STRIKE INC
  • US12493683B1 patent drawing
  • US12493683B1 patent drawing
  • US12493683B1 patent drawing

AI summary

The disclosed embodiments contemplate consumers who wish to securely login to a business/vendor without the need to remember or even know the password. A business/vendor wishes to conduct business with a verified consumer without the business undertaking the burden to keep a database of their customer's usernames and passwords. A system operator or third party security service provides mechanisms of authentication to verify the purported identity of consumers and businesses. To open a channel of communication between a verified consumer and business, a system operator or verification service sends systematic parameters or other data structures such at a designated consumer and business will independently create the appropriate login information and temporary password to facilitate a transaction. Passwords and login information are never transmitted between the provider and business/vendor, hence preventing outside parties from accessing unauthorized login information.