Dynamic Permutation Passcode Generation for Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems are vulnerable because an attacker who intercepts a passcode generated by direct concatenation of a PIN and a token code can easily determine the PIN, which changes infrequently, allowing future unauthorized access.
Innovation Solution
Implementing a processing device that generates a passcode using a selected secret permutation type, which can change over time, to combine a PIN and a token code, increasing the number of passcodes an attacker must intercept before determining the PIN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If direct concatenation of PIN and tokencode is used to generate passcode, then the authentication process is simple and easy to implement, but the security is compromised because attackers can easily determine the PIN from intercepted passcodes
Solution Approach 1:
The patent applies dynamics by introducing a variable permutation type that changes over time based on a permutation update function. Instead of using a fixed concatenation method, the system dynamically adjusts the ordering of PIN and tokencode characters, making it impossible for attackers to reliably extract the PIN from intercepted passcodes, while still maintaining ease of implementation through automated permutation application
Solution Approach 2:
The patent changes the parameter of passcode generation from a static direct concatenation to a dynamic permutation-based approach. By varying the permutation type according to an update function, the system transforms the passcode structure into a non-repeating pattern that prevents secure analysis, thereby resolving the contradiction between simplicity and security
2Reliability
If the PIN changes frequently, then the security against unauthorized access is improved, but the user convenience and ease of use deteriorates due to frequent password changes
Solution Approach 1:
The patent segments the passcode into distinct components (PIN portion and tokencode portion) that can be independently manipulated. By applying different permutation types to these segments, the system creates variability in the passcode structure without requiring the user to change the PIN itself, thus maintaining security while preserving user convenience
Solution Approach 2:
The permutation type acts as an intermediary mechanism between the static PIN and the dynamic passcode. This intermediary transforms the fixed PIN into a variable passcode structure through character reordering, allowing security enhancement without forcing frequent PIN changes by the user
3Device complexity
If a fixed permutation type is used for passcode generation, then the implementation is simple and consistent, but the security is reduced because attackers can predict the passcode structure
Solution Approach 1:
The system transitions from a static to a dynamic permutation approach where the permutation type is updated over time according to a permutation update function. This dynamic behavior prevents attackers from predicting the passcode structure, while the implementation remains relatively simple by automating the permutation application process
Solution Approach 2:
The patent implements periodic action through the permutation update function that changes the permutation type at regular intervals. This periodic transformation of the passcode structure ensures that even if attackers intercept multiple passcodes, they cannot predict future permutations, thereby enhancing security while maintaining implementation simplicity
Data Source
AI summary
A processing device is configured to receive a personal identifier from a user, to obtain a tokencode generated by an authentication token, to determine a permutation type for the user, and to generate a passcode utilizing the personal identifier, the tokencode and the permutation type. The personal identifier may comprise a personal identification number (PIN) or other arrangement of characters, and the permutation type may specify a particular ordering of characters of the personal identifier and the tokencode in the passcode. For example, if the passcode is normally generated by direct concatenation of the personal identifier and the tokencode, the permutation type may specify a deviation from direct concatenation of the personal identifier and the tokencode in generating the passcode, such as at least one of reversal, interleaving and reordering of the characters of the personal identifier and the tokencode in generating the passcode.


