iOTP Authentication Mechanism for Password-Less Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current one-time password (OTP) systems are vulnerable to attacks due to the need for users to manage multiple username and password combinations, leading to security risks and logistical challenges, as well as exposure to phishing and SIM swap attacks, which compromise access control.
Innovation Solution
The improved One Time Password (iOTP) system uses a two-factor authentication mechanism that eliminates the need for passwords by generating a unique iOTP on the user's device, which is transmitted only once and requires biometric or PIN confirmation, using a modified Time-based One-Time Password (TOTP) algorithm with synchronized time windows to enhance security and prevent multiple access attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users manage multiple username and password combinations across systems, then access control to multiple systems is enabled, but security risk increases due to exposure to phishing and SIM swap attacks
Solution Approach 1:
The patent extracts the password function entirely from the authentication process. Instead of using traditional username-password combinations, the system uses a single OTP that is sent to the user's device. This eliminates passwords from the system, thereby removing the security risks associated with password management, phishing attacks, and SIM swap attacks while maintaining access control capability.
Solution Approach 2:
The patent introduces an intermediary OTP mechanism that mediates between the user and the system. The OTP is generated by the system, sent to the user's device through a communication channel, and then used for authentication. This intermediary process replaces direct password entry, adding a layer of security that protects against phishing and SIM swap attacks while enabling access to multiple systems.
2Ease of operation
If users use the same username and password across all systems, then user management is simplified, but security risk increases due to breach exposure
Solution Approach 1:
The patent removes passwords entirely from the authentication process, replacing them with a single OTP mechanism. Users no longer need to manage multiple username-password combinations or use the same credentials across systems. The OTP is generated and sent to the user's device, eliminating the need for users to remember or manage passwords while maintaining security against breach exposure.
3Reliability
If OTP is sent via secondary communication channel, then two-factor authentication is implemented, but user burden increases due to manual OTP entry
Solution Approach 1:
The patent enables the user's device to automatically handle the OTP process. The OTP is sent to the device through a communication channel, and the device can automatically process it without requiring manual user entry. This self-service approach maintains the security benefits of two-factor authentication while significantly reducing the operational burden on users.
Data Source
AI summary
An improved One Time Password (iOTP) is used in a two-factor authentication mechanism to decode a username, and the inherent security of the iOTP eliminates the need for a password. When the user is identified by the iOTP, a second challenge is sent. The second challenge may be confirmed by user biometrics or via a PIN code if the user's device does not support biometrics. Benefits of the subject invention include: (1) no username, which eliminates exposure to multiple domain attacks (i.e., attacks on other sites with the same username) that attempt to extract passwords from less secure sites (e.g., where a user used the same username and password across multiple sites); and (2) password-less access—the iOTP replaces both the username and password function, thereby eliminating the need for the user to manage multiple usernames and passwords.


