Multifactor Authentication via Image-Based Key Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing web service authentication systems are inefficient and prone to user error due to the manual input of authentication keys, which can lead to errors in reading and inputting key information.
Innovation Solution
A web services system provisions a device as an authentication device by displaying an image containing a key, allowing the device to capture and extract the key information, and then sends a seed to the device to generate one-time passcodes, thereby reducing user intervention and error.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual input of authentication keys is used, then user control is maintained, but user error increases and efficiency decreases
Solution Approach 1:
The authentication device automatically captures images, extracts keys, and generates one-time passcodes without requiring manual user input. The device serves itself by performing these operations autonomously, eliminating user errors associated with manual key entry while maintaining authentication security.
Solution Approach 2:
The patent replaces the manual mechanical process of reading and typing keys with an automated optical system. The device uses image capture and optical character recognition to automatically extract authentication keys, substituting the manual mechanical input process with an automated optical-digital system that eliminates human error.
2Reliability
If automated image capture and key extraction is implemented, then user error is reduced, but device complexity increases
Solution Approach 1:
The authentication device performs multiple functions including image capture, key extraction, seed storage, and one-time passcode generation within a single integrated system. By making the device multi-functional, the patent avoids requiring separate devices for each operation, thereby managing complexity while achieving high authentication accuracy.
Solution Approach 2:
The device captures visual images of authentication keys and creates digital copies for extraction and processing. This copying approach allows the system to work with visual information without requiring complex direct optical-to-digital conversion hardware, simplifying the overall system while maintaining accuracy.
3Speed
If one-time passcodes are generated automatically, then authentication speed increases, but security requirements increase
Solution Approach 1:
The authentication seed is pre-loaded into the device during provisioning before actual authentication occurs. This preliminary action allows the device to rapidly generate one-time passcodes during authentication without requiring real-time complex calculations, thus achieving high speed while maintaining security through pre-established cryptographic foundations.
Solution Approach 2:
The system generates one-time passcodes at periodic intervals or in response to periodic authentication requests. Each passcode is time-bound and single-use, creating a periodic authentication rhythm that enables fast repeated authentications while maintaining security through the evolving nature of each passcode based on the seed and time/counter values.
Data Source
AI summary
In certain embodiments, a system receives a request sent by a device to authorize an operation. The system initiates display of an image encoding a challenge code to allow the device to capture the image and extract the challenge code. The device calculates a response using the challenge code and a seed, and sends the response to the system. In certain examples, the device may send the request over a first channel and the response over a second channel distinct from the first channel. In other examples, the device displays the response and a user inputs the response into a computing system to send to the system.


