Hardware OTP Module for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face security risks due to the vulnerability of One-Time Passwords (OTPs) when generated through the operating system or application layer, making them susceptible to exploitation by malicious programs.

Innovation Solution

An OTP module is implemented at the hardware or firmware layer of an information handling system, generating OTPs independently of the operating system and application layers, using a predetermined input trigger such as a key combination, and presenting the OTP through a hardware or firmware-controlled display to limit access by the operating system or applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OTP is generated through the operating system or application layer, then the system is easier to implement and operate, but the security is compromised due to vulnerability to exploitation by malicious programs

Engineering Contradiction:
Improveease of OTP implementationVSAvoidsecurity of OTP
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the OTP generation functionality from the operating system and application layers into a separate hardware module. This modular approach allows the OTP generation to occur in an isolated security domain, preventing malicious programs from accessing or manipulating the OTP generation process while maintaining ease of implementation through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware-based OTP module acts as an intermediary between the user and the authentication system. This intermediary component generates OTPs in a secure hardware environment and provides them through controlled interfaces, mediating between the need for secure OTP generation and the requirement for ease of operation by end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated hardware devices are used for OTP generation, then the security is improved, but the expense and complexity of implementing the OTP verification system increases

Engineering Contradiction:
Improvesecurity of OTPVSAvoidcomplexity of OTP verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The OTP module is designed to perform multiple functions within a single hardware component, including OTP generation, secure key storage, and controlled output. This multi-functionality reduces the need for separate dedicated hardware devices for each function, thereby improving security while reducing overall system complexity and expense.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The hardware OTP module is designed to be self-contained and self-service, generating OTPs autonomously based on internal cryptographic operations. This eliminates the need for complex external hardware devices or continuous external intervention, reducing system complexity while maintaining high security through hardware-based cryptographic operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8321929B2System and method for implementing a one time password at an information handling system
Publication Date: 2012.11.27 DELL PROD LP
  • US8321929B2 patent drawing
  • US8321929B2 patent drawing
  • US8321929B2 patent drawing

AI summary

A system and method are provided which substantially reduce the disadvantages and problems associated with previous methods and systems for generating an OTP at an information handling system. An OTP is generated at an information handling system hardware or firmware layer upon detection of a predetermined input trigger, such as a key combination. The OTP is provided for authentication independent of an operating system or applications running on the information handling system.