Dynamic Password Authentication Using Terminal Equipment Code and Counter

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional dynamic password authentication methods require additional costly hardware, are prone to manual input errors, and can fail due to software system time updates, necessitating a more effective and cost-efficient solution.

Innovation Solution

A method and system that generates a dynamic password based on a terminal's unique equipment code and a local counter, eliminating the need for manual input and additional hardware, while ensuring authentication through a server-generated verification process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional dynamic password authentication is used, then authentication security is improved, but additional costly hardware devices are required

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware device requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses software-based dynamic password generation that replicates the functionality of hardware tokens. The terminal device generates dynamic passwords locally using software algorithms, eliminating the need for physical hardware tokens while maintaining authentication security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical hardware devices with software-based authentication mechanisms. The dynamic password generation is implemented through software algorithms running on the terminal device, substituting the mechanical/hardware token system with a software-based system that achieves the same security function.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If manual entry of dynamic passwords is required, then authentication process is simple, but input errors occur frequently

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidinput accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements automatic password generation and transmission where the terminal device autonomously generates dynamic passwords and sends them to the server without requiring manual user input. This self-service mechanism eliminates human error in password entry while maintaining authentication functionality.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system automatically transmits the generated dynamic password from the terminal to the server, creating a feedback loop where the password generation and transmission are automated processes. This eliminates the need for manual entry and subsequent verification by the user, preventing input errors.

Inventive Principle:
Principle #23Feedback

3Device complexity

If software-based dynamic passwords are used, then hardware costs are reduced, but verification failures occur due to system time updates

Engineering Contradiction:
Improvehardware device requirementVSAvoidauthentication verification success
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent incorporates a counter mechanism that tracks the sequence number of dynamic password generations. This preliminary tracking action ensures that both the terminal and server are synchronized on which dynamic password should be used, preventing verification failures due to time updates or desynchronization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses dynamic counter values that automatically increment with each authentication attempt. This dynamic mechanism ensures that even if system time updates occur, the counter-based synchronization protocol maintains proper alignment between terminal and server, preventing verification failures.

Inventive Principle:
Principle #15Dynamics

4Reliability

If additional hardware devices are deployed, then authentication security is enhanced, but device loss risk increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice loss risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces physical hardware tokens with software-based authentication that runs on the terminal device. This copying approach maintains the security function without the physical object that can be lost, stolen, or damaged.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The terminal device performs self-generated authentication passwords using its own internal resources (processor, memory, software). This eliminates the need for separate hardware tokens that could be lost, as the authentication capability is embedded in the terminal itself.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3320523B1Method and device for authentication using dynamic passwords
Publication Date: 2021.09.01 ALIBABA GROUP HOLDING LTD
  • EP3320523B1 patent drawingFigure 1
  • EP3320523B1 patent drawingFigure 2
  • EP3320523B1 patent drawingFigure 3A

AI summary

Embodiments of the present application relate to a method and device for authentication processing. The method includes obtaining an equipment code that uniquely identifies a terminal, generating a dynamic password based at least in part on the equipment code and an output value of a counter, wherein the dynamic password is a basis for authentication of the terminal by a server, and sending the dynamic password to the server, wherein the server authenticates the dynamic password.