Gesture-Based One-Time Password Authentication for Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods, such as traditional passwords and time-based one-time passwords (OTPs), lack context-awareness and security adaptability, particularly in transactions where varying levels of security are required based on transaction specifics like location and amount.

Innovation Solution

Implementing gesture-based one-time password (OTP) authentication, where contextual information associated with a transaction is used to generate and display specific gestures on an extended reality (XR) device, requiring users to perform validated motions to authorize transactions, enhancing security based on transaction context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional passwords or time-based OTPs are used for authentication, then the authentication process is simple to implement, but the security level is insufficient and lacks context-awareness

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication by adjusting the complexity and type of gestures required based on contextual risk assessment. The system transitions from static password/OTP authentication to dynamic gesture-based authentication, where the authentication requirements change dynamically according to transaction context such as location, amount, and device risk profile

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (gesture complexity, number of gestures, verification strictness) based on contextual parameters like transaction amount, location, and device trust level. This allows the same authentication system to adapt its security level by modifying operational parameters rather than requiring different authentication mechanisms

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If gesture-based OTP authentication with contextual awareness is implemented, then the security and adaptability are enhanced, but the device complexity and operational requirements increase

Engineering Contradiction:
Improvecontext-awarenessVSAvoiduser operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system requires only partial authentication actions (simple gestures) for low-risk transactions, and excessive actions (complex multi-gesture sequences) for high-risk transactions. This partial/excessive approach allows the system to maintain ease of operation for routine tasks while providing enhanced security when needed, rather than requiring full authentication complexity for all operations

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If contextual information is used to dynamically generate OTPs, then the security adaptability improves, but the processing time and system complexity increase

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary contextual assessment and risk classification before the actual authentication gesture. By pre-evaluating transaction context (location, amount, device profile) and determining the appropriate authentication level in advance, the system avoids time-consuming real-time complex processing during the authentication moment itself

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12056696B2Gesture based one-time password generation for transactions
Publication Date: 2024.08.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12056696B2 patent drawing
  • US12056696B2 patent drawing
  • US12056696B2 patent drawing

AI summary

Aspects of the present disclosure relate to gesture-based one-time password (OTP) authentication for transactions. Initiation of a transaction can be detected. Contextual information associated with the transaction can be received. In response to detecting the initiation of the transaction and based on the contextual information associated with the transaction, a one-time password (OTP) comprising one or more gestures to be performed by a user can be generated. A command can be transmitted to display the one or more gestures to be performed on an extended reality (XR) device worn by the user. In response to validating user performance of the one or more gestures displayed via the XR device, the transaction can be authorized.