Dynamic Token Seed Data Update via Photosensitive Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Dynamic tokens are limited to single application use and cannot update seed data post-manufacturing, restricting their versatility and user convenience.
Innovation Solution
A method for updating seed data in dynamic tokens through an interactive interface and application server, involving authentication, request packet generation, and certificate authority verification, allowing dynamic tokens to be used across multiple applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If seed data are built in dynamic tokens by token producers before the dynamic tokens leave factory, then the security and uniqueness of OTP generation is ensured, but the token cannot be updated by a user after activation and can only be used in single application
Solution Approach 1:
The patent introduces an application server as an intermediary between the user and the certificate authority. The application server receives user requests, communicates with the certificate authority to obtain new seed data, and facilitates the update process without requiring direct user access to the token's internal mechanisms. This intermediary approach enables secure seed data updates while maintaining system security architecture.
Solution Approach 2:
The patent enables users to self-update seed data in their dynamic tokens through an automated process. Users interact with the application server to request seed data updates, and the system automatically retrieves new seed data from the certificate authority and programs it into the token. This self-service mechanism eliminates the need for manual intervention by token producers while maintaining security.
2Adaptability or versatility
If the token cannot be updated by a user after activation, then the security architecture is simplified and manufacturing process is straightforward, but the token is restricted to single application use only
Solution Approach 1:
The patent implements a preliminary action by pre-establishing the communication infrastructure and authentication mechanisms between the application server and the certificate authority before the token needs to be updated. The system is pre-configured with the necessary security protocols and channels, allowing rapid seed data updates without requiring complex manufacturing processes or token redesign.
Solution Approach 2:
The patent makes the dynamic token universal by enabling it to serve multiple applications through updateable seed data. The same token hardware can be programmed with different seed data for different applications, transforming a single-function device into a multi-functional one without changing the physical token structure or manufacturing process.
3Ease of operation
If a method is implemented to allow user updating of seed data, then multi-application usage is enabled, but the authentication and verification process becomes more complex
Solution Approach 1:
The patent implements feedback mechanisms at multiple levels: the application server receives authentication results from the certificate authority and uses this feedback to determine whether to proceed with seed data updates; the system validates user credentials and provides feedback on authentication success or failure. This structured feedback approach manages complexity by breaking down the authentication process into manageable validation steps.
Data Source
AI summary
A method for updating seed data in a dynamic token comprises: an interaction interface sends user information to an application server for verification, receives a verification result returned by the application server, continuously receives dynamic token information when the verification result is valid, and sends same to the application server; the application server generates a request data packet containing the dynamic token information and application information and sends same to an authentication center; the authentication center acquires seed data corresponding to the dynamic token information and the application information and sends same to the application server; the application server converts the seed data into photosensitive data and displays same by means of the interaction interface; and the dynamic token obtains the seed data by acquiring the photosensitive data. The present invention can realize that the seed data in a dynamic token is automatically updated by a user, and meanwhile, a dynamic token can be applied to multiple applications.


