Handheld Access Control System Using Dynamic OTP Seeds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control methods for advanced metering infrastructure (AMI) systems rely on fixed keys, which are vulnerable to unauthorized access and data breaches due to unstable network connections and limited data exchange capabilities between electricity meter devices and remote data management servers.

Innovation Solution

An access control system and method that generates a one-time password (OTP) seed set, transmitted to a handheld device for two-way identification certification with a terminal recording device, ensuring secure access without relying on fixed keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fixed keys are used for identification certification, then the access control system can operate with simple authentication, but the system becomes vulnerable to unauthorized access and security breaches

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication by replacing static fixed keys with one-time passwords (OTPs) that change with each authentication attempt. The OTP generation mechanism ensures that credentials are dynamic and time-sensitive, making unauthorized access significantly more difficult while maintaining operational simplicity through automated generation and verification processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from a fixed, unchanging key to a variable OTP that is generated based on multiple parameters including time, random values, and device-specific identifiers. This parameter transformation maintains ease of operation through automated generation while dramatically improving security reliability by ensuring each authentication credential is unique and time-limited.

Inventive Principle:
Principle #35Parameter changes

2Extent of automation

If remote data management servers maintain stable connections with electricity meter devices, then data exchange can be automated, but network instability and connection failures still occur in limited connection status

Engineering Contradiction:
Improvedata exchange automationVSAvoidconnection stability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-generating and storing multiple OTP seed values in both the handheld device and terminal recording device before actual authentication is needed. This preparation ensures that when connection stability issues occur, the devices can still perform authentication using pre-stored seeds without requiring real-time server intervention, thus maintaining automation despite connection unreliableness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service authentication by allowing handheld devices and terminal recording devices to independently generate and verify OTPs using their own pre-stored seed sets without requiring continuous server validation. This self-service capability ensures automated data exchange can proceed even when remote server connections are unstable or unavailable.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If manual access methods are used when remote servers fail to connect, then data access can be achieved at the near end, but fixed keys used for manual access are easy to be divulged, cracked or stolen

Engineering Contradiction:
Improvemanual access capabilityVSAvoidkey vulnerability to theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements the disposable principle by using one-time passwords that are valid for only a single authentication transaction. Each OTP is generated, used once for authentication, and then becomes invalid. This disposable credential approach maintains manual access capability while eliminating the vulnerability of fixed keys to theft, cracking, or unauthorized reuse, since each credential lives only for its intended single use.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8909937B2Access control system and access control method thereof
Publication Date: 2014.12.09 INSTITUTE FOR INFORMATION INDUSTRY
  • US8909937B2 patent drawing
  • US8909937B2 patent drawing
  • US8909937B2 patent drawing

AI summary

An access control system and an access control method thereof are provided. The access control system comprises a handheld device, an access control server and a terminal recording device. The handheld device has a user identification. The access control server is configured to store a user identification set, connect to the handheld device within a first time interval, determine that the user identification is included in the user identification set, generate a one-time password (OTP) seed set, and transmit the OTP seed set to the handheld device. The terminal recording device connects to the handhold device within a second time interval, and performs a two-way identification certification with the handheld device according to the OTP seed set so that the handheld device performs a data access to the terminal recording device after achieving the two-way identification certification.