Dynamic Password Authentication With Expiring Login Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password generation and distribution systems require users to remember and manage multiple passwords, lacking mechanisms for seamless and secure dynamic password generation and authentication without direct user involvement.
Innovation Solution
A system generates unique, expiring passwords using dynamic secret parameters and algorithms, transmitted to both the user and the business, allowing secure authentication without requiring users to remember or manually input passwords, with additional security via NFC authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manually manage and remember multiple passwords, then authentication security is maintained, but user convenience and ease of operation deteriorate
Solution Approach 1:
The system enables automatic password generation and submission without user intervention. The password manager autonomously creates passwords using cryptographic algorithms, transmits them to the target system, and handles authentication automatically, freeing users from manual password management while maintaining security through algorithmic generation
Solution Approach 2:
A password manager service acts as an intermediary between the user and the target authentication system. It generates passwords on behalf of the user, transmits them securely to the target system, and receives authentication responses, thereby eliminating the need for users to directly handle or remember passwords while ensuring secure authentication
2Ease of operation
If static passwords are used for authentication, then ease of operation is improved, but security against replay attacks and unauthorized access deteriorates
Solution Approach 1:
The system transitions from static password authentication to dynamic password generation. Each password is generated on-demand using cryptographic algorithms that incorporate changing parameters such as timestamps or random values, ensuring that each authentication attempt uses a unique password that cannot be reused or replayed by attackers
Solution Approach 2:
The password generation process changes parameters dynamically by incorporating time-based factors, random seeds, or counter values into the cryptographic algorithm. This ensures that passwords evolve over time and are unique to each authentication event, preventing replay attacks while maintaining automated authentication simplicity
Data Source
AI summary
The disclosed embodiments contemplate consumers who wish to securely login to a business/vendor without the need to remember or even know the password. A business/vendor wishes to conduct business with a verified consumer without the business undertaking the burden to keep a database of their customer's usernames and passwords. A system operator or third party security service provides mechanisms of authentication to verify the purported identity of consumers and businesses. To open a channel of communication between a verified consumer and business, a system operator or verification service sends systematic parameters or other data structures such at a designated consumer and business will independently create the appropriate login information and temporary password to facilitate a transaction. Passwords and login information are never transmitted between the provider and business/vendor, hence preventing outside parties from accessing unauthorized login information.


